﻿Level	Date and Time	Source	Event ID	Task Category
Information	4/9/2019 10:49:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎04‎-‎09T05:19:33.466048600Z.
Information	4/9/2019 10:49:56 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Information	4/9/2019 10:49:56 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight2. Product Version: 1.4.0.12710. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	4/9/2019 10:49:56 AM	MsiInstaller	11724	None	Product: 4Sight2 -- Removal completed successfully.
Information	4/9/2019 10:49:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎04‎-‎09T05:19:33.466048600Z.
Information	4/9/2019 10:49:29 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Information	4/9/2019 10:49:10 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/9/2019 10:48:50 AM	PostgreSQL	0	None	"2019-04-09 10:48:50 IST LOG:  redirecting log output to logging collector process
2019-04-09 10:48:50 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/9/2019 10:48:50 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:47:10 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:47:09 AM	PostgreSQL	0	None	"2019-04-09 10:47:09 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:47:09 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:47:09 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:45:58 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.12710. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	4/9/2019 10:45:58 AM	MsiInstaller	11707	None	Product: 4Sight2 -- Installation operation completed successfully.
Information	4/9/2019 10:45:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎04‎-‎09T05:01:26.385401900Z.
Information	4/9/2019 10:45:57 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{55D60130-D133-410A-835A-753DA71BBE43}\4Sight™ 2.msi. Client Process Id: 15824.
Error	4/9/2019 10:45:53 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:45:52 AM	PostgreSQL	0	None	"2019-04-09 10:45:52 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:45:52 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:45:52 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:45:48 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:45:48 AM	PostgreSQL	0	None	"2019-04-09 10:45:48 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:45:48 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:45:47 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:45:43 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:45:43 AM	PostgreSQL	0	None	"2019-04-09 10:45:43 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:45:43 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:45:42 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:45:39 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:45:38 AM	PostgreSQL	0	None	"2019-04-09 10:45:38 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:45:38 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:45:38 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:35:19 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:35:19 AM	PostgreSQL	0	None	"2019-04-09 10:35:19 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:35:19 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:35:18 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:35:15 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:35:14 AM	PostgreSQL	0	None	"2019-04-09 10:35:14 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:35:14 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:35:13 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:35:10 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:35:09 AM	PostgreSQL	0	None	"2019-04-09 10:35:09 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:35:09 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:35:09 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:35:05 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:35:04 AM	PostgreSQL	0	None	"2019-04-09 10:35:04 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:35:04 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:35:04 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:31:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎04‎-‎09T05:01:26.385401900Z.
Information	4/9/2019 10:31:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{55D60130-D133-410A-835A-753DA71BBE43}\4Sight™ 2.msi. Client Process Id: 15824.
Error	4/9/2019 10:30:21 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:30:20 AM	PostgreSQL	0	None	"2019-04-09 10:30:20 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:30:20 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:30:20 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:27:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎04‎-‎09T04:57:36.904365300Z.
Information	4/9/2019 10:27:58 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Information	4/9/2019 10:27:57 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight2. Product Version: 1.4.0.12710. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	4/9/2019 10:27:57 AM	MsiInstaller	11724	None	Product: 4Sight2 -- Removal completed successfully.
Information	4/9/2019 10:27:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎04‎-‎09T04:57:36.904365300Z.
Information	4/9/2019 10:27:34 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Error	4/9/2019 10:25:03 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:25:02 AM	PostgreSQL	0	None	"2019-04-09 10:25:02 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:25:02 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:25:02 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:24:37 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:24:36 AM	PostgreSQL	0	None	"2019-04-09 10:24:36 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:24:36 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:24:36 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:23:44 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.12710. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	4/9/2019 10:23:44 AM	MsiInstaller	11707	None	Product: 4Sight2 -- Installation operation completed successfully.
Information	4/9/2019 10:23:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎04‎-‎09T04:43:03.368605700Z.
Information	4/9/2019 10:23:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{99561077-0F6C-4B54-8B9C-19DA016F46C8}\4Sight™ 2.msi. Client Process Id: 12768.
Error	4/9/2019 10:23:33 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:23:33 AM	PostgreSQL	0	None	"2019-04-09 10:23:33 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:23:33 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:23:32 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:23:28 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:23:28 AM	PostgreSQL	0	None	"2019-04-09 10:23:28 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:23:28 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:23:27 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:23:24 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:23:23 AM	PostgreSQL	0	None	"2019-04-09 10:23:23 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:23:23 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:23:23 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:23:19 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:23:18 AM	PostgreSQL	0	None	"2019-04-09 10:23:18 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:23:18 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:23:18 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:17:54 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:17:53 AM	PostgreSQL	0	None	"2019-04-09 10:17:53 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:17:53 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:17:53 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:17:49 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:17:49 AM	PostgreSQL	0	None	"2019-04-09 10:17:49 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:17:49 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:17:48 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:17:45 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:17:44 AM	PostgreSQL	0	None	"2019-04-09 10:17:44 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:17:44 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:17:44 AM	PostgreSQL	0	None	Waiting for server startup...

Error	4/9/2019 10:17:40 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:17:39 AM	PostgreSQL	0	None	"2019-04-09 10:17:39 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:17:39 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:17:39 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:17:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2019 10:13:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎04‎-‎09T04:43:03.368605700Z.
Information	4/9/2019 10:13:02 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{99561077-0F6C-4B54-8B9C-19DA016F46C8}\4Sight™ 2.msi. Client Process Id: 12768.
Error	4/9/2019 10:12:14 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/9/2019 10:12:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56622)(?)])(1 )(2 )]

"
Information	4/9/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56622)(?)])(1 )(2 )]

"
Information	4/9/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56622)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2019 10:12:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2019 10:12:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2019 10:12:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/9/2019 10:12:07 AM	PostgreSQL	0	None	Timed out waiting for server startup

Error	4/9/2019 10:12:06 AM	PostgreSQL	0	None	"2019-04-09 10:12:06 IST FATAL:  lock file ""postmaster.pid"" already exists
2019-04-09 10:12:06 IST HINT:  Is another postmaster (PID 5512) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	4/9/2019 10:12:06 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/9/2019 10:05:13 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎04‎-‎09T04:34:34.675592700Z.
Information	4/9/2019 10:05:13 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Information	4/9/2019 10:05:13 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight2. Product Version: 1.4.0.12607. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	4/9/2019 10:05:13 AM	MsiInstaller	11724	None	Product: 4Sight2 -- Removal completed successfully.
Information	4/9/2019 10:04:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎04‎-‎09T04:34:34.675592700Z.
Information	4/9/2019 10:04:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7948.
Information	4/9/2019 9:28:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2019 9:23:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2019 9:23:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2019 9:23:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2019 9:22:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7f1ec49-5a7a-11e9-b0a2-80000bd6758f
Report Status: 0"
Warning	4/9/2019 9:14:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2019 9:13:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/9/2019 9:13:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2019 9:13:20 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/9/2019 9:13:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/9/2019 9:13:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/9/2019 9:12:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	4/9/2019 9:12:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/9/2019 9:12:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 8:21:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 8:21:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/8/2019 6:35:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02127a0a-59ff-11e9-b0a2-80000bd6758f
Report Status: 0"
Warning	4/8/2019 6:27:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/8/2019 6:25:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/8/2019 6:25:50 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/8/2019 6:25:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	4/8/2019 6:25:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 6:25:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 6:25:24 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 6:25:24 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 5:20:17 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 5:20:17 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	4/8/2019 3:57:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/8/2019 3:38:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 3:38:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-15T10:02:08Z. Reason: GVLK.
Information	4/8/2019 3:33:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 3:33:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 3:33:08 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/04/08 10:02"
Information	4/8/2019 3:33:06 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/04/08 10:02, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/8/2019 3:27:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/8/2019 3:27:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 3:27:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 3:27:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 2:26:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 2:21:30 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 889

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1966

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 530

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 32

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 468

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 405

Warning	4/8/2019 2:21:30 PM	Outlook	59	None	Outlook disabled the following add-in(s):



ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
Load Behavior: 3
HKLM: 1
Location: c:\program files (x86)\phishme\phishme reporter\adxloader.phishmeoutlookreporter.dll
Threshold Time (Milliseconds): 1000
Time Taken (Milliseconds): 1061
Disable Reason: This add-in caused Outlook to start slowly.
Policy Exception (Allow List): 0 
Information	4/8/2019 2:21:29 PM	Outlook	52	None	An Outlook add-in took longer than expected (500 milliseconds) to disconnect.
Add-in: PhishMe Reporter
Duration: 593 milliseconds
Information	4/8/2019 2:21:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/8/2019 2:20:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57814)(?)])(1 )(2 )]

"
Information	4/8/2019 2:20:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 2:20:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57814)(?)])(1 )(2 )]

"
Information	4/8/2019 2:20:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57814)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 2:20:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/8/2019 2:20:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 2:20:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/8/2019 2:08:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/8/2019 2:03:53 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/8/2019 2:03:51 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	4/8/2019 2:03:27 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 2:03:27 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 1:39:02 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 1:39:02 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/8/2019 1:21:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 16127201-59d3-11e9-b0a2-80000bd6758f
Report Status: 0"
Information	4/8/2019 12:28:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/8/2019 12:25:23 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/8/2019 12:10:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/8/2019 11:39:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 5, Deleted: 0, Modified: 1, Compared: 32210, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/8/2019 11:37:22 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/8/2019 11:35:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 11:30:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57984)(?)])(1 )(2 )]

"
Information	4/8/2019 11:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 11:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57984)(?)])(1 )(2 )]

"
Information	4/8/2019 11:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57984)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 11:30:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/8/2019 11:30:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 11:30:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 10:17:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/8/2019 10:12:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/8/2019 10:12:16 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/8/2019 10:12:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58062)(?)])(1 )(2 )]

"
Information	4/8/2019 10:12:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58062)(?)])(1 )(2 )]

"
Information	4/8/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58062)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 10:12:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/8/2019 10:12:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 10:12:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 10:01:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 10:01:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:37Z. Reason: GVLK.
Information	4/8/2019 9:56:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/8/2019 9:56:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 9:56:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 9:56:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 8:54:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 8:54:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:52Z. Reason: GVLK.
Information	4/8/2019 8:49:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/8/2019 8:49:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 8:49:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 8:49:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 8:41:31 AM	McLogEvent	257	None	The scan of C:\Users\212558710\Desktop\Share\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9216.0000.
Information	4/8/2019 8:40:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/8/2019 8:35:17 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/8/2019 8:35:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58159)(?)])(1 )(2 )]

"
Information	4/8/2019 8:35:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 8:35:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58159)(?)])(1 )(2 )]

"
Information	4/8/2019 8:35:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58159)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 8:35:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/8/2019 8:35:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 8:35:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 8:34:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 8:34:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:19Z. Reason: GVLK.
Information	4/8/2019 8:33:42 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 8:29:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/8/2019 8:29:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 8:29:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 8:29:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 8:29:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/8/2019 8:29:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:10Z. Reason: GVLK.
Information	4/8/2019 8:29:09 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/8/2019 8:28:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/8/2019 8:28:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/8/2019 8:28:43 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 218

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1529

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 686

Information	4/8/2019 8:28:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/8/2019 8:26:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	4/8/2019 8:25:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58169)(?)])(1 )(2 )]

"
Information	4/8/2019 8:25:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 8:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58169)(?)])(1 )(2 )]

"
Information	4/8/2019 8:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58169)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	4/8/2019 8:23:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, March 15, 2019 11:46:53 PM.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AddTrust External CA Root, OU=AddTrust External TTP Network, O=AddTrust AB, C=SE> Sha1 thumbprint: <02FAF3E291435468607857694DF5E45B68851868>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1 thumbprint: <0483ED3399AC3608058722EDBC5E4600E3BEF9D7>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=NetLock Arany (Class Gold) Főtanúsítvány, OU=Tanúsítványkiadók (Certification Services), O=NetLock Kft., L=Budapest, C=HU> Sha1 thumbprint: <06083F593F15A104A069A46BA903D006B7970991>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=USERTrust RSA Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US> Sha1 thumbprint: <2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=COMODO ECC Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB> Sha1 thumbprint: <9F744E9F2B4DBAEC0F312C50B6563B8E2D93C311>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB> Sha1 thumbprint: <AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UTN-USERFirst-Client Authentication and Email, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1 thumbprint: <B172B1A56D95F91FE50287E14D37EA6A4463768A>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=USERTrust ECC Certification Authority, O=The USERTRUST Network, L=Jersey City, S=New Jersey, C=US> Sha1 thumbprint: <D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, S=Greater Manchester, C=GB> Sha1 thumbprint: <D1EB23A46D17D68FD92564C2F1F1601764D8E349>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1 thumbprint: <E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46>.
Information	4/8/2019 8:21:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=COMODO Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB> Sha1 thumbprint: <EE869387FFFD8349AB5AD14322588789A457B012>.
Error	4/8/2019 8:20:58 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {F8823946-1E97-402D-B3A0-B148B087E7E6}
Error	4/8/2019 8:20:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/8/2019 8:20:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58174)(?)])(1 )(2 )]

"
Information	4/8/2019 8:20:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/8/2019 8:20:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58174)(?)])(1 )(2 )]

"
Information	4/8/2019 8:20:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58174)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 8:20:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/8/2019 8:20:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 8:20:14 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/8/2019 8:20:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/8/2019 8:19:56 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/8/2019 8:19:55 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/8/2019 8:19:53 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/8/2019 8:19:52 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/8/2019 8:19:02 AM	ESENT	302	Logging/Recovery	Windows (1800) Windows: The database engine has successfully completed recovery steps.
Information	4/8/2019 8:18:53 AM	ESENT	301	Logging/Recovery	Windows (1800) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/8/2019 8:18:53 AM	ESENT	300	Logging/Recovery	Windows (1800) Windows: The database engine is initiating recovery steps.
Information	4/8/2019 8:18:53 AM	ESENT	102	General	Windows (1800) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/8/2019 8:18:51 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	4/8/2019 8:18:51 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	4/8/2019 8:18:37 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/8/2019 8:18:37 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/8/2019 8:17:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/8/2019 8:17:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/8/2019 8:17:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/8/2019 8:17:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/8/2019 8:17:49 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	4/8/2019 8:17:21 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9216.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	4/8/2019 8:17:04 AM	Service1	0	None	Service started successfully.
Error	4/8/2019 8:16:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/8/2019 8:16:41 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/8/2019 8:16:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/8/2019 8:16:40 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	4/8/2019 8:16:40 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/8/2019 8:16:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/8/2019 8:16:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/8/2019 8:16:31 AM	PostgreSQL	0	None	"2019-04-08 08:16:31 IST LOG:  redirecting log output to logging collector process
2019-04-08 08:16:31 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/8/2019 8:16:24 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	4/8/2019 8:16:24 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/8/2019 8:16:19 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/8/2019 8:15:45 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/8/2019 8:15:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/8/2019 8:15:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:38 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/8/2019 8:15:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/8/2019 8:15:37 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/8/2019 8:15:36 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4552 at 4/5/2019 11:49:23 AM (local) 4/5/2019 6:19:23 AM (UTC). This is an informational message only; no user action is required.
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/8/2019 8:15:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/8/2019 8:15:33 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/8/2019 8:15:33 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/8/2019 8:15:33 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/8/2019 8:15:33 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4740.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/8/2019 8:15:25 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/8/2019 8:13:27 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/8/2019 8:13:22 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	4/8/2019 8:13:21 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/8/2019 8:12:37 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/8/2019 8:12:35 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/8/2019 8:12:34 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/7/2019 12:45:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/7/2019 12:45:05 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/7/2019 12:44:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	4/7/2019 12:44:43 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/7/2019 12:44:43 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 10:06:15 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 10:06:15 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/5/2019 9:56:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 92dd88dd-57bf-11e9-9818-80000bd6758f
Report Status: 0"
Information	4/5/2019 9:34:27 PM	MTAService.OnSessionChange	0	None	9:34:27 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/5/2019 8:42:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 8:04:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 7:36:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎04‎-‎05T14:06:21.499516400Z.
Information	4/5/2019 7:36:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎04‎-‎05T14:06:21.499516400Z.
Information	4/5/2019 7:24:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎04‎-‎05T13:54:39.966984000Z.
Information	4/5/2019 7:24:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎04‎-‎05T13:54:39.966984000Z.
Information	4/5/2019 7:12:59 PM	MTAService.OnSessionChange	0	None	7:12:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2019 7:12:41 PM	MTAService.OnSessionChange	0	None	7:12:41 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2019 6:53:37 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/5/2019 6:53:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 6:48:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61866)(?)])(1 )(2 )]

"
Information	4/5/2019 6:48:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 6:48:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61866)(?)])(1 )(2 )]

"
Information	4/5/2019 6:48:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61866)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 6:48:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 6:48:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 6:48:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 5:55:38 PM	MTAService.OnSessionChange	0	None	5:55:38 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/5/2019 4:57:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 4:56:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a929e2cc-5795-11e9-9818-80000bd6758f
Report Status: 0"
Information	4/5/2019 4:55:27 PM	MTAService.OnSessionChange	0	None	4:55:27 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2019 4:50:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 4:45:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 4:45:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 4:45:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 4:04:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 4:04:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/5/2019 4:04:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/5/2019 3:12:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 2:36:23 PM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Saturday, March 16, 2019 2:30:23 AM.
Information	4/5/2019 2:24:02 PM	MTAService.OnSessionChange	0	None	2:24:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2019 1:57:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/5/2019 1:57:52 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	4/5/2019 1:57:42 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 1:57:42 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 1:47:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 1:47:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	4/5/2019 1:36:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 1:14:15 PM	MTAService.OnSessionChange	0	None	1:14:15 PM - Session change notice received: SessionLock Session ID: 1
Error	4/5/2019 12:56:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 12:56:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 12:55:09 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 12:55:09 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/5/2019 12:12:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 12:08:13 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 1, Deleted: 0, Modified: 2, Compared: 31856, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/5/2019 12:07:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62267)(?)])(1 )(2 )]

"
Information	4/5/2019 12:07:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 12:07:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62267)(?)])(1 )(2 )]

"
Information	4/5/2019 12:07:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 12:04:33 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 202

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 203

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 110

Information	4/5/2019 12:04:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 12:03:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62270)(?)])(1 )(2 )]

"
Information	4/5/2019 12:03:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 12:03:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62270)(?)])(1 )(2 )]

"
Information	4/5/2019 12:03:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62270)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 12:03:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 12:03:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 12:03:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 11:59:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 11:59:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 11:59:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:15Z. Reason: GVLK.
Information	4/5/2019 11:56:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: be994220-576b-11e9-9818-80000bd6758f
Report Status: 0"
Warning	4/5/2019 11:56:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/5/2019 11:54:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/5/2019 11:53:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/5/2019 11:53:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62281)(?)])(1 )(2 )]

"
Information	4/5/2019 11:53:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 11:53:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62281)(?)])(1 )(2 )]

"
Information	4/5/2019 11:53:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 11:53:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 11:53:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 11:53:42 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 11:53:26 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/5/2019 11:53:18 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/5/2019 11:53:17 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/5/2019 11:53:14 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/5/2019 11:53:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/5/2019 11:52:47 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	4/5/2019 11:52:47 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	4/5/2019 11:52:37 AM	ESENT	302	Logging/Recovery	Windows (9828) Windows: The database engine has successfully completed recovery steps.
Information	4/5/2019 11:52:24 AM	ESENT	301	Logging/Recovery	Windows (9828) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/5/2019 11:52:24 AM	ESENT	300	Logging/Recovery	Windows (9828) Windows: The database engine is initiating recovery steps.
Information	4/5/2019 11:52:24 AM	ESENT	102	General	Windows (9828) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	4/5/2019 11:52:10 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/5/2019 11:52:10 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/5/2019 11:52:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/5/2019 11:52:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 11:52:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 11:51:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/5/2019 11:51:12 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	4/5/2019 11:50:58 AM	MTAService.OnSessionChange	0	None	11:50:58 AM - Logon : 212558710
Information	4/5/2019 11:50:54 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/5/2019 11:50:54 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	4/5/2019 11:50:54 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/5/2019 11:50:53 AM	MTAService.OnSessionChange	0	None	11:50:53 AM - Session change notice received: SessionLogon Session ID: 1
Information	4/5/2019 11:50:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/5/2019 11:50:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/5/2019 11:50:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9216.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	4/5/2019 11:50:23 AM	Service1	0	None	Service started successfully.
Error	4/5/2019 11:50:10 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/5/2019 11:50:07 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/5/2019 11:49:58 AM	PostgreSQL	0	None	"2019-04-05 11:49:58 IST LOG:  redirecting log output to logging collector process
2019-04-05 11:49:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/5/2019 11:49:50 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	4/5/2019 11:49:49 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/5/2019 11:49:47 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/5/2019 11:49:44 AM	MTAService	0	None	Service started successfully.
Information	4/5/2019 11:49:44 AM	MTAService.OnStart	0	None	11:49:44 AM - Waiting for user to Logon
Information	4/5/2019 11:49:33 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/5/2019 11:49:28 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:28 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/5/2019 11:49:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/5/2019 11:49:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/5/2019 11:49:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/5/2019 11:49:27 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/5/2019 11:49:27 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:26 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/5/2019 11:49:25 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/5/2019 11:49:25 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/5/2019 11:49:25 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4408 at 3/29/2019 8:19:16 AM (local) 3/29/2019 2:49:16 AM (UTC). This is an informational message only; no user action is required.
Information	4/5/2019 11:49:23 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/5/2019 11:49:22 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/5/2019 11:49:22 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/5/2019 11:49:22 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/5/2019 11:49:22 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/5/2019 11:49:22 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4552.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/5/2019 11:49:13 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/5/2019 11:47:38 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/5/2019 11:47:17 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	4/5/2019 11:47:15 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/5/2019 11:46:25 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/5/2019 11:46:25 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/5/2019 11:46:25 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Warning	4/5/2019 10:48:54 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 16772 did not respond and is being forcibly terminated {filter host process 7188}. 

Information	4/5/2019 10:40:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 10:38:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e8c4b0bc-5760-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/5/2019 10:35:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 10:35:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/5/2019 10:35:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/5/2019 10:35:05 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 406

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 764

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 125

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 343

Information	4/5/2019 10:34:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 10:34:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/5/2019 10:34:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62360)(?)])(1 )(2 )]

"
Information	4/5/2019 10:34:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 10:34:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62360)(?)])(1 )(2 )]

"
Information	4/5/2019 10:33:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62360)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 10:33:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 10:33:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 10:33:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 10:30:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2019 10:30:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/5/2019 10:29:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	4/5/2019 10:29:48 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x8034081f). If this error continues, contact Microsoft Support.
Information	4/5/2019 10:21:32 AM	MTAService.OnSessionChange	0	None	10:21:32 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2019 10:17:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/5/2019 10:12:16 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/5/2019 10:12:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62382)(?)])(1 )(2 )]

"
Information	4/5/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62382)(?)])(1 )(2 )]

"
Information	4/5/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62382)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 10:12:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2019 10:12:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 10:12:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/5/2019 10:03:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 9:45:23 AM	MTAService.OnSessionChange	0	None	9:45:23 AM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2019 8:53:38 AM	MTAService.OnSessionChange	0	None	8:53:38 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2019 8:28:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 8:28:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:19Z. Reason: GVLK.
Information	4/5/2019 8:23:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/5/2019 8:23:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 8:23:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 8:23:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/5/2019 8:16:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 6:29:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/5/2019 6:24:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 5:38:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff0e5b83-5736-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/5/2019 4:34:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 4:02:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 4:02:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:15Z. Reason: GVLK.
Information	4/5/2019 3:57:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/5/2019 3:57:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 3:57:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 3:57:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 3:40:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 3:40:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:38Z. Reason: GVLK.
Information	4/5/2019 3:32:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/5/2019 3:32:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 3:32:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 3:32:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/5/2019 3:07:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/5/2019 3:07:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:00Z. Reason: GVLK.
Information	4/5/2019 3:02:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/5/2019 3:02:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2019 3:01:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2019 3:01:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/5/2019 2:58:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 2:29:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/5/2019 1:24:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2019 12:38:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 155d77df-570d-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/5/2019 12:08:43 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 8760 did not respond and is being forcibly terminated {filter host process 19920}. 

Information	4/5/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/4/2019 11:48:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 10:29:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/4/2019 10:09:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 9:01:05 PM	MTAService.OnSessionChange	0	None	9:01:05 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/4/2019 8:23:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/4/2019 7:41:45 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 18948 did not respond and is being forcibly terminated {filter host process 17160}. 

Information	4/4/2019 7:38:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2bb6ec6d-56e3-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/4/2019 7:11:57 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 20060 did not respond and is being forcibly terminated {filter host process 17268}. 

Information	4/4/2019 6:40:17 PM	MTAService.OnSessionChange	0	None	6:40:17 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/4/2019 6:37:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 6:29:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 6:29:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/4/2019 6:29:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 5:23:43 PM	MTAService.OnSessionChange	0	None	5:23:43 PM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2019 5:23:08 PM	MTAService.OnSessionChange	0	None	5:23:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2019 5:09:44 PM	MTAService.OnSessionChange	0	None	5:09:44 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/4/2019 4:49:06 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 14164 did not respond and is being forcibly terminated {filter host process 0}. 

Warning	4/4/2019 4:44:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/4/2019 4:26:10 PM	Application Error	1000	(100)	"Faulting application name: cscript.exe, version: 5.8.7601.24288, time stamp: 0x5bd3d5b9
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x46ec
Faulting application start time: 0x01d4ead5001d5589
Faulting application path: C:\Windows\SysWOW64\cscript.exe
Faulting module path: unknown
Report Id: 40b81367-56c8-11e9-96b9-80000bd6758f"
Information	4/4/2019 4:10:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 4:05:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2019 4:05:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2019 4:05:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2019 2:53:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/4/2019 2:41:17 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/4/2019 2:41:17 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/4/2019 2:38:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4135401c-56b9-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/4/2019 2:29:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 2:28:48 PM	MTAService.OnSessionChange	0	None	2:28:48 PM - Session change notice received: SessionUnlock Session ID: 1
Error	4/4/2019 2:28:35 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/4/2019 2:28:35 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/4/2019 1:33:40 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/4/2019 1:33:40 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/4/2019 1:24:25 PM	MTAService.OnSessionChange	0	None	1:24:25 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/4/2019 1:18:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/4/2019 1:03:25 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\Documents\Outlook Files\archive.pst (error=0x81940885). If this error continues, contact Microsoft Support.
Warning	4/4/2019 1:00:56 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 18124 did not respond and is being forcibly terminated {filter host process 13968}. 

Information	4/4/2019 12:05:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9216.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	4/4/2019 11:21:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 11:19:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	4/4/2019 10:21:39 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 19208 did not respond and is being forcibly terminated {filter host process 6644}. 

Information	4/4/2019 10:19:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 10:14:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/4/2019 10:14:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/4/2019 10:14:28 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 546

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1061

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 46

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 531

Information	4/4/2019 10:14:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 10:13:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63821)(?)])(1 )(2 )]

"
Information	4/4/2019 10:13:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2019 10:13:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63821)(?)])(1 )(2 )]

"
Information	4/4/2019 10:13:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63821)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	4/4/2019 10:12:15 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/4/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63822)(?)])(1 )(2 )]

"
Information	4/4/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63822)(?)])(1 )(2 )]

"
Information	4/4/2019 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63822)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2019 10:12:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2019 10:12:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2019 10:12:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2019 9:43:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 9:38:11 AM	MTAService.OnSessionChange	0	None	9:38:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2019 9:24:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 9:09:21 AM	MTAService.OnSessionChange	0	None	9:09:21 AM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2019 9:03:55 AM	MTAService.OnSessionChange	0	None	9:03:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2019 8:54:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2652f2bd-5689-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/4/2019 8:31:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/4/2019 8:31:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/4/2019 8:31:44 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 32151, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/4/2019 8:30:00 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	4/4/2019 7:49:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 7:47:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 7:47:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/4/2019 7:46:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/4/2019 6:11:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/4/2019 4:25:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 3:54:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3c9e5790-565f-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/4/2019 3:48:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 3:48:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:19Z. Reason: GVLK.
Information	4/4/2019 3:46:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2019 3:39:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2019 3:39:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2019 3:39:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2019 3:39:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2019 2:49:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 2:49:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:54Z. Reason: GVLK.
Information	4/4/2019 2:44:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2019 2:44:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2019 2:44:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2019 2:44:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2019 2:37:52 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Warning	4/4/2019 2:31:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 2:29:50 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/4/2019 12:57:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2019 12:57:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:00Z. Reason: GVLK.
Information	4/4/2019 12:51:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2019 12:51:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2019 12:51:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2019 12:51:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/4/2019 12:46:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2019 12:03:11 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/3/2019 11:46:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/3/2019 11:05:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 10:54:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 52efa5e3-5635-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/3/2019 9:19:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/3/2019 7:47:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 7:46:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2019 7:46:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/3/2019 7:46:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2019 7:03:52 PM	MTAService.OnSessionChange	0	None	7:03:52 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/3/2019 6:01:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 5:54:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6909b829-560b-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/3/2019 4:42:14 PM	MTAService.OnSessionChange	0	None	4:42:14 PM - Session change notice received: SessionUnlock Session ID: 1
Error	4/3/2019 4:41:53 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/3/2019 4:41:53 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/3/2019 4:41:04 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/3/2019 4:41:04 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	4/3/2019 4:07:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 3:49:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2019 3:49:22 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/3/2019 3:46:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2019 3:41:54 PM	MTAService.OnSessionChange	0	None	3:41:54 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2019 3:34:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64940)(?)])(1 )(2 )]

"
Information	4/3/2019 3:34:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/3/2019 3:34:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64940)(?)])(1 )(2 )]

"
Information	4/3/2019 3:34:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64940)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 2:35:34 PM	MTAService.OnSessionChange	0	None	2:35:34 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/3/2019 2:22:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 1:28:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 1:28:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/3/2019 1:27:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 1:27:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/3/2019 1:21:32 PM	MTAService.OnSessionChange	0	None	1:21:32 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2019 1:03:44 PM	MTAService.OnSessionChange	0	None	1:03:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2019 1:02:39 PM	MTAService.OnSessionChange	0	None	1:02:39 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2019 12:59:35 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9215.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	4/3/2019 12:54:45 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 13416 did not respond and is being forcibly terminated {filter host process 17980}. 

Information	4/3/2019 12:54:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f1e44ae-55e1-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/3/2019 12:53:10 PM	MTAService.OnSessionChange	0	None	12:53:10 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/3/2019 12:47:45 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 14332 did not respond and is being forcibly terminated {filter host process 11036}. 

Information	4/3/2019 12:36:54 PM	MTAService.OnSessionChange	0	None	12:36:54 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/3/2019 12:35:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 12:31:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 12:31:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/3/2019 11:45:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/3/2019 11:40:02 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 15364 did not respond and is being forcibly terminated {filter host process 16520}. 

Warning	4/3/2019 11:33:02 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 16800 did not respond and is being forcibly terminated {filter host process 13444}. 

Information	4/3/2019 11:24:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 11:23:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/3/2019 11:21:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 11:21:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/3/2019 11:19:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/3/2019 11:19:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	4/3/2019 10:37:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 10:19:24 AM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	4/3/2019 10:16:07 AM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	4/3/2019 10:15:58 AM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Error	4/3/2019 10:12:13 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/3/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65262)(?)])(1 )(2 )]

"
Information	4/3/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/3/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65262)(?)])(1 )(2 )]

"
Information	4/3/2019 10:12:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65262)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 10:06:11 AM	MTAService.OnSessionChange	0	None	10:06:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2019 9:31:22 AM	MTAService.OnSessionChange	0	None	9:31:22 AM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2019 9:28:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/3/2019 9:20:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/3/2019 9:20:25 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/3/2019 9:19:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2019 9:19:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:58Z. Reason: GVLK.
Information	4/3/2019 9:16:27 AM	MTAService.OnSessionChange	0	None	9:16:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2019 9:14:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2019 9:14:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 9:14:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2019 9:14:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/3/2019 8:49:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 7:54:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95432166-55b7-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/3/2019 7:45:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2019 7:45:56 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/3/2019 7:45:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/3/2019 6:53:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/3/2019 5:15:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 4:52:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2019 4:52:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:14Z. Reason: GVLK.
Information	4/3/2019 4:47:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2019 4:47:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 4:47:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2019 4:47:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/3/2019 4:06:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2019 4:06:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:33Z. Reason: GVLK.
Information	4/3/2019 4:01:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2019 4:01:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 4:01:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2019 4:01:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/3/2019 4:00:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2019 4:00:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:39Z. Reason: GVLK.
Information	4/3/2019 3:55:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2019 3:55:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2019 3:55:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2019 3:55:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/3/2019 3:45:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/3/2019 3:28:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 2:54:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ab8bf319-558d-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/3/2019 2:08:30 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/3/2019 1:54:34 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	4/3/2019 1:41:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 12:26:19 AM	MTAService	0	None	Service started successfully.
Information	4/3/2019 12:26:12 AM	MTAService.OnStart	0	None	12:26:12 AM - User is already logged in : 212558710
Information	4/3/2019 12:24:51 AM	MTAService	0	None	Service stopped successfully.
Information	4/3/2019 12:24:51 AM	MTAService	0	None	MTAService.OnStop: --> Stop
Warning	4/3/2019 12:08:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2019 12:03:11 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/2/2019 11:45:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 11:45:40 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/2/2019 11:45:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 10:52:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2019 10:52:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:56Z. Reason: GVLK.
Information	4/2/2019 10:47:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2019 10:47:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 10:47:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 10:47:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/2/2019 10:35:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 9:54:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1c7e82b-5563-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/2/2019 9:00:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 7:47:42 PM	MTAService.OnSessionChange	0	None	7:47:42 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 7:46:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 7:46:05 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/2/2019 7:46:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2019 7:46:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 66128)(?)])(1 )(2 )]

"
Information	4/2/2019 7:46:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 66128)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 7:46:00 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	4/2/2019 7:45:59 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 203

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 109

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 47

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 452

Information	4/2/2019 7:45:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 66128)(?)])(1 )(2 )]

"
Information	4/2/2019 7:45:57 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/2/2019 7:45:57 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109328  Grace type=8.
Information	4/2/2019 7:45:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=87480eed-36a9-45a3-a1ce-25b389472580"
Information	4/2/2019 7:45:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=40da08f4-01a6-4108-a7dc-ace32d907cc6"
Information	4/2/2019 7:45:56 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/2/2019 7:45:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 7:44:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20050)(?)])(1 )(2 )]

"
Information	4/2/2019 7:44:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2019 7:44:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20050)(?)])(1 )(2 )]

"
Information	4/2/2019 7:44:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20050)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 7:44:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2019 7:44:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 7:44:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/2/2019 7:18:50 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/2/2019 7:18:50 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	4/2/2019 7:14:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 5:53:42 PM	MTAService.OnSessionChange	0	None	5:53:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 5:24:23 PM	MTAService.OnSessionChange	0	None	5:24:23 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/2/2019 5:15:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 4:54:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8027d69-5539-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/2/2019 3:41:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 3:01:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 3:01:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 2:58:22 PM	MTAService.OnSessionChange	0	None	2:58:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 2:41:21 PM	MTAService.OnSessionChange	0	None	2:41:21 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 2:29:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 2:29:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 2:26:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 2:26:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 2:21:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 2:20:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 2:20:38 PM	MTAService.OnSessionChange	0	None	2:20:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 2:11:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/2/2019 2:04:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 2:03:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 2:02:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 2:02:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	4/2/2019 1:59:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 1:53:46 PM	MTAService.OnSessionChange	0	None	1:53:46 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 1:51:37 PM	MTAService.OnSessionChange	0	None	1:51:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 1:50:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:50:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:43:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:42:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:42:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:42:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:40:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:39:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:35:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:35:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:32:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:32:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:27:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:27:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:20:43 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/2/2019 1:20:39 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/2/2019 1:13:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:12:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 1:11:08 PM	MTAService.OnSessionChange	0	None	1:11:08 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 1:10:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 1:10:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 12:57:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9214.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	4/2/2019 12:37:57 PM	MTAService.OnSessionChange	0	None	12:37:57 PM - Session change notice received: SessionUnlock Session ID: 1
Error	4/2/2019 12:37:40 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/2/2019 12:33:44 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/2/2019 12:14:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 12:14:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	4/2/2019 12:12:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/2/2019 12:10:01 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/2/2019 12:10:01 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/2/2019 12:09:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	4/2/2019 12:09:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	4/2/2019 11:57:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 11:56:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 11:54:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed7902a9-550f-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/2/2019 11:45:06 AM	MTAService.OnSessionChange	0	None	11:45:06 AM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 11:25:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 11:24:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 11:03:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/2/2019 11:03:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/2/2019 10:46:53 AM	MTAService.OnSessionChange	0	None	10:46:53 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 10:43:22 AM	MTAService.OnSessionChange	0	None	10:43:22 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/2/2019 10:17:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 10:12:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 10:12:14 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/2/2019 10:11:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 10:06:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2019 10:04:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/2/2019 10:04:09 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/2/2019 10:04:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/2/2019 10:01:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2019 10:01:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 10:01:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2019 9:52:58 AM	MTAService.OnSessionChange	0	None	9:52:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2019 9:24:56 AM	MTAService.OnSessionChange	0	None	9:24:56 AM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/2/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20687)(?)])(1 )(2 )]

"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20687)(?)])(1 )(2 )]

"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20687)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2019 9:06:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 9:06:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2019 8:59:54 AM	MTAService.OnSessionChange	0	None	8:59:54 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/2/2019 8:42:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 7:47:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2019 7:47:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:26Z. Reason: GVLK.
Information	4/2/2019 7:42:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2019 7:42:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 7:42:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 7:42:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/2/2019 7:09:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 6:54:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03c2f394-54e6-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/2/2019 6:11:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/2/2019 5:25:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 4:49:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2019 4:49:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:58:09Z. Reason: GVLK.
Information	4/2/2019 4:44:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2019 4:44:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 4:44:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 4:44:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2019 4:43:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2019 4:43:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:51Z. Reason: GVLK.
Information	4/2/2019 4:38:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2019 4:38:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2019 4:38:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2019 4:38:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/2/2019 3:36:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 2:11:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2019 1:54:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 19f6092a-54bc-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/2/2019 1:46:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/2/2019 12:12:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2019 12:03:12 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/1/2019 10:20:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 10:11:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 10:11:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/1/2019 10:11:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 9:20:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 9:20:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:47Z. Reason: GVLK.
Information	4/1/2019 9:15:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 9:15:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 9:15:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 9:15:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/1/2019 8:54:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 303606ec-5492-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	4/1/2019 8:38:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 7:53:55 PM	MTAService.OnSessionChange	0	None	7:53:55 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 7:50:25 PM	MTAService.OnSessionChange	0	None	7:50:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 7:34:58 PM	MTAService.OnSessionChange	0	None	7:34:58 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/1/2019 6:59:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 6:12:21 PM	MTAService.OnSessionChange	0	None	6:12:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 6:11:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 5:26:51 PM	MTAService.OnSessionChange	0	None	5:26:51 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/1/2019 5:02:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 4:41:25 PM	MTAService.OnSessionChange	0	None	4:41:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 4:37:55 PM	MTAService.OnSessionChange	0	None	4:37:55 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 4:10:30 PM	MTAService.OnSessionChange	0	None	4:10:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 4:02:51 PM	MTAService.OnSessionChange	0	None	4:02:51 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 3:54:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4589df5c-5468-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/1/2019 3:44:26 PM	MTAService.OnSessionChange	0	None	3:44:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 3:33:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 3:33:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-08T09:57:35Z. Reason: GVLK.
Information	4/1/2019 3:28:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 3:28:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 3:28:34 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/04/01 09:58"
Information	4/1/2019 3:28:33 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/04/01 09:58, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/1/2019 3:24:37 PM	MTAService.OnSessionChange	0	None	3:24:37 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 3:23:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 3:23:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 3:23:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 3:23:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/1/2019 3:01:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 2:33:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 2:33:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 2:23:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 2:23:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 2:23:36 PM	MTAService.OnSessionChange	0	None	2:23:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 2:11:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 2:11:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 2:10:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/1/2019 1:51:10 PM	MTAService.OnSessionChange	0	None	1:51:10 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 1:50:54 PM	MTAService.OnSessionChange	0	None	1:50:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 1:31:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 1:30:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	4/1/2019 1:28:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 1:26:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 1:25:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 1:12:56 PM	MTAService.OnSessionChange	0	None	1:12:56 PM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 1:09:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 1:08:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:42:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:41:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:40:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:40:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:38:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:37:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:36:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:35:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:33:36 PM	MTAService.OnSessionChange	0	None	12:33:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/1/2019 12:31:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:30:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:26:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9213.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	4/1/2019 12:09:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:09:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 12:06:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 12:06:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 11:43:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 11:42:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 11:38:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 11:37:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	4/1/2019 11:35:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 11:16:05 AM	MTAService.OnSessionChange	0	None	11:16:05 AM - Session change notice received: SessionLock Session ID: 1
Information	4/1/2019 11:02:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 11:02:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 11:00:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/1/2019 10:59:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/1/2019 10:53:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a2e5c0e-543e-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/1/2019 10:11:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 10:11:09 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/1/2019 10:10:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 10:04:25 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/1/2019 10:03:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/1/2019 10:03:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/1/2019 10:02:55 AM	MTAService.OnSessionChange	0	None	10:02:55 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/1/2019 9:38:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 9:11:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/1/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	4/1/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22127)(?)])(1 )(2 )]

"
Information	4/1/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/1/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22128)(?)])(1 )(2 )]

"
Information	4/1/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22128)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/1/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/1/2019 9:00:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 8:55:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/1/2019 8:55:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 8:55:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/1/2019 8:31:52 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/1/2019 8:31:52 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/1/2019 8:31:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 31943, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	4/1/2019 8:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/1/2019 8:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/1/2019 8:26:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 8:26:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:25Z. Reason: GVLK.
Information	4/1/2019 8:21:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 8:21:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 8:21:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 8:21:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/1/2019 8:04:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 7:40:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 7:40:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:45Z. Reason: GVLK.
Information	4/1/2019 7:35:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 7:35:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 7:35:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 7:35:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/1/2019 6:12:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 6:10:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/1/2019 5:53:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7056be96-5414-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/1/2019 5:49:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/1/2019 5:29:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 5:29:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:15Z. Reason: GVLK.
Information	4/1/2019 5:24:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 5:24:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 5:24:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 5:24:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/1/2019 4:25:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 3:56:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 3:56:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:57Z. Reason: GVLK.
Information	4/1/2019 3:51:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 3:51:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 3:51:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 3:51:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/1/2019 3:51:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/1/2019 3:51:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:51Z. Reason: GVLK.
Information	4/1/2019 3:46:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/1/2019 3:46:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/1/2019 3:46:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/1/2019 3:46:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/1/2019 2:48:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 2:10:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/1/2019 1:16:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/1/2019 12:53:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 869369ee-53ea-11e9-96b9-80000bd6758f
Report Status: 0"
Information	4/1/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/31/2019 11:22:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 10:11:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/31/2019 10:11:00 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/31/2019 10:10:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/31/2019 9:40:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 7:53:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cce48ac-53c0-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/31/2019 7:48:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 7:45:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2019 7:45:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:08Z. Reason: GVLK.
Information	3/31/2019 7:40:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2019 7:40:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2019 7:40:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2019 7:40:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2019 7:38:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2019 7:38:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:14Z. Reason: GVLK.
Information	3/31/2019 7:33:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2019 7:33:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2019 7:33:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2019 7:33:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2019 6:10:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/31/2019 5:49:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/31/2019 4:02:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 2:53:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b2a0182a-5396-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/31/2019 2:29:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 2:10:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/31/2019 2:10:26 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/31/2019 2:09:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/31/2019 12:43:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 12:27:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9212.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	3/31/2019 10:52:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 10:10:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/31/2019 10:10:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/31/2019 10:09:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/31/2019 9:53:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c89e02a5-536c-11e9-96b9-80000bd6758f
Report Status: 0"
Information	3/31/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/31/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/31/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23567)(?)])(1 )(2 )]

"
Information	3/31/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/31/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23567)(?)])(1 )(2 )]

"
Information	3/31/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23567)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/31/2019 9:04:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/31/2019 7:34:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 6:09:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/31/2019 5:41:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 4:53:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dd0ff107-5342-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/31/2019 4:03:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 2:09:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/31/2019 2:02:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/31/2019 1:16:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2019 1:16:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:42Z. Reason: GVLK.
Information	3/31/2019 1:11:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2019 1:11:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2019 1:11:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2019 1:11:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/31/2019 12:14:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 11:53:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f0dbcc9d-5318-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/30/2019 10:16:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 10:09:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/30/2019 10:09:57 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/30/2019 10:09:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/30/2019 8:19:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 6:53:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0719c10e-52ef-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/30/2019 6:45:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 6:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/30/2019 5:30:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/30/2019 5:30:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:30Z. Reason: GVLK.
Information	3/30/2019 5:25:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/30/2019 5:25:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/30/2019 5:25:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/30/2019 5:25:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/30/2019 5:07:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/30/2019 3:24:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 2:53:24 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/30/2019 2:09:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/30/2019 1:53:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bc0f0a7-52c5-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/30/2019 1:45:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 1:32:37 PM	MTAService.OnSessionChange	0	None	1:32:37 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/30/2019 12:10:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 11:31:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	3/30/2019 11:31:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/30/2019 10:47:03 AM	MTAService.OnSessionChange	0	None	10:47:03 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/30/2019 10:31:44 AM	MTAService.OnSessionChange	0	None	10:31:44 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/30/2019 10:31:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 10:14:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/30/2019 10:12:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/30/2019 10:09:52 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/30/2019 10:09:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/30/2019 10:09:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/30/2019 10:09:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/30/2019 10:09:46 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 156

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1810

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	3/30/2019 10:09:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/30/2019 10:08:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24945)(?)])(1 )(2 )]

"
Information	3/30/2019 10:08:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/30/2019 10:08:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24945)(?)])(1 )(2 )]

"
Information	3/30/2019 10:08:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/30/2019 10:08:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/30/2019 10:08:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/30/2019 10:08:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/30/2019 9:14:15 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9211.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/30/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/30/2019 9:06:51 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25007)(?)])(1 )(2 )]

"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25008)(?)])(1 )(2 )]

"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25008)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/30/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/30/2019 9:06:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/30/2019 8:59:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/30/2019 8:54:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/30/2019 8:54:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/30/2019 8:54:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/30/2019 8:53:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31fcce85-529b-11e9-96b9-80000bd6758f
Report Status: 0"
Warning	3/30/2019 8:45:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/30/2019 8:44:53 AM	MTAService.OnSessionChange	0	None	8:44:53 AM - Session change notice received: SessionUnlock Session ID: 1
Error	3/29/2019 5:40:00 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/29/2019 5:40:00 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	3/29/2019 5:00:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/29/2019 4:58:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/29/2019 4:58:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/29/2019 4:28:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 4:28:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:10Z. Reason: GVLK.
Information	3/29/2019 4:23:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2019 4:23:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 4:23:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 4:23:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 4:05:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9210.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/29/2019 3:56:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 181f57d9-520d-11e9-96b9-80000bd6758f
Report Status: 0"
Information	3/29/2019 3:54:06 PM	MTAService.OnSessionChange	0	None	3:54:06 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/29/2019 3:26:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 3:09:31 PM	MTAService.OnSessionChange	0	None	3:09:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2019 3:00:20 PM	MTAService.OnSessionChange	0	None	3:00:20 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2019 2:27:55 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/29/2019 2:26:54 PM	MTAService.OnSessionChange	0	None	2:26:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2019 1:55:07 PM	MTAService.OnSessionChange	0	None	1:55:07 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2019 1:49:22 PM	MTAService.OnSessionChange	0	None	1:49:22 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/29/2019 1:46:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 1:33:48 PM	MTAService.OnSessionChange	0	None	1:33:48 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2019 12:41:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/29/2019 12:08:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎03‎-‎29T06:38:20.164489300Z.
Information	3/29/2019 12:08:20 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	3/29/2019 12:08:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎29T06:38:20.164489300Z.
Information	3/29/2019 12:08:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎03‎-‎29T06:38:19.457489300Z.
Information	3/29/2019 12:08:19 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	3/29/2019 12:08:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎29T06:38:19.457489300Z.
Information	3/29/2019 12:08:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎03‎-‎29T06:38:17.365489300Z.
Information	3/29/2019 12:08:17 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	3/29/2019 12:08:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎29T06:38:17.365489300Z.
Warning	3/29/2019 12:05:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 12:03:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9209.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/29/2019 11:54:25 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.222. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/29/2019 11:54:25 AM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	3/29/2019 11:54:21 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T06:23:57.383774900Z.
Information	3/29/2019 11:54:21 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{A3FAFEA3-A321-4146-9491-BA038FE60657}\DeviceManager.msi. Client Process Id: 10272.
Information	3/29/2019 11:53:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T06:23:57.383774900Z.
Information	3/29/2019 11:53:55 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{A3FAFEA3-A321-4146-9491-BA038FE60657}\DeviceManager.msi. Client Process Id: 10272.
Information	3/29/2019 11:53:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T06:23:31.754338100Z.
Information	3/29/2019 11:53:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0507E688-C1EE-411F-826F-7620B541772F}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 7324.
Information	3/29/2019 11:53:51 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.3.0.222. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/29/2019 11:53:51 AM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	3/29/2019 11:53:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T06:23:31.754338100Z.
Information	3/29/2019 11:53:30 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0507E688-C1EE-411F-826F-7620B541772F}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 7324.
Information	3/29/2019 11:40:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T06:09:53.722836700Z.
Information	3/29/2019 11:40:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 5876.
Information	3/29/2019 11:40:08 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.222. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/29/2019 11:40:08 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	3/29/2019 11:39:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T06:09:53.722836700Z.
Information	3/29/2019 11:24:08 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 5876.
Error	3/29/2019 11:16:05 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 0F6C6FA4 (0F550000) with exit code c0000005.

Error	3/29/2019 11:11:35 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 0F976FA4 (0F800000) with exit code c0000005.

Error	3/29/2019 11:07:35 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 0F676FA4 (0F500000) with exit code c0000005.

Error	3/29/2019 11:05:17 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 0FFB6FA4 (0FE40000) with exit code c0000005.

Error	3/29/2019 11:02:03 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 0FFF6FA4 (0FE80000) with exit code c0000005.

Information	3/29/2019 10:56:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e402d03-51e3-11e9-96b9-80000bd6758f
Report Status: 0"
Error	3/29/2019 10:49:45 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 10096FA4 (0FF20000) with exit code c0000005.

Information	3/29/2019 10:34:58 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.12607. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/29/2019 10:34:58 AM	MsiInstaller	11707	None	Product: 4Sight2 -- Installation operation completed successfully.
Information	3/29/2019 10:34:36 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T04:55:19.835052000Z.
Information	3/29/2019 10:34:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{98488850-047A-4B02-AA0A-2839BC742FF3}\4Sight™ 2.msi. Client Process Id: 14812.
Information	3/29/2019 10:25:19 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T04:55:19.835052000Z.
Information	3/29/2019 10:24:47 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{98488850-047A-4B02-AA0A-2839BC742FF3}\4Sight™ 2.msi. Client Process Id: 14812.
Warning	3/29/2019 10:23:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/29/2019 10:20:23 AM	.NET Runtime	1023	None	Application: dotnet.exe
CoreCLR Version: 4.6.27317.3
Description: The process was terminated due to an internal error in the .NET Runtime at IP 01986FA4 (01810000) with exit code c0000005.

Information	3/29/2019 10:11:08 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.222. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/29/2019 10:11:08 AM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	3/29/2019 10:11:06 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T04:40:29.503449800Z.
Information	3/29/2019 10:11:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{83C0D622-9D6F-40A1-B0CE-C7EF70CBD0A1}\DeviceManager.msi. Client Process Id: 14928.
Information	3/29/2019 10:10:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T04:40:29.503449800Z.
Information	3/29/2019 10:10:27 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{83C0D622-9D6F-40A1-B0CE-C7EF70CBD0A1}\DeviceManager.msi. Client Process Id: 14928.
Information	3/29/2019 9:47:58 AM	MTAService.OnSessionChange	0	None	9:47:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2019 9:19:38 AM	MTAService.OnSessionChange	0	None	9:19:38 AM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2019 9:12:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T03:42:17.713291600Z.
Information	3/29/2019 9:12:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 11860.
Information	3/29/2019 9:12:20 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 0.
Information	3/29/2019 9:12:20 AM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	3/29/2019 9:12:17 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T03:42:17.713291600Z.
Information	3/29/2019 9:12:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 11860.
Information	3/29/2019 9:12:17 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 11860.
Information	3/29/2019 9:12:17 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 1638.
Information	3/29/2019 9:12:17 AM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	3/29/2019 9:12:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 11860.
Information	3/29/2019 9:11:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/29/2019 9:06:54 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/29/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26447)(?)])(1 )(2 )]

"
Information	3/29/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26447)(?)])(1 )(2 )]

"
Information	3/29/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26447)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/29/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 9:03:54 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎29T03:33:52.448770200Z.
Information	3/29/2019 9:03:54 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 12864.
Information	3/29/2019 9:03:54 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	3/29/2019 9:03:54 AM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	3/29/2019 9:03:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎29T03:33:52.448770200Z.
Information	3/29/2019 9:03:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 12864.
Information	3/29/2019 9:03:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 12864.
Information	3/29/2019 9:03:51 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 1638.
Information	3/29/2019 9:03:51 AM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	3/29/2019 9:03:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 12864.
Information	3/29/2019 8:59:29 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	3/29/2019 8:59:28 AM	GE Software	0	(1)	++No Reboot requested by Google_Chrome_67_V01
Information	3/29/2019 8:59:23 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	3/29/2019 8:59:23 AM	GE Software	0	(1)	Updating Pactrack registry keys with google_chrome_67_v01
Information	3/29/2019 8:59:23 AM	GE Software	0	(1)	++This wrapper has been run 2 time(s) on this PC
Information	3/29/2019 8:59:19 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Error	3/29/2019 8:59:02 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/29/2019 8:58:34 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	3/29/2019 8:58:34 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: 212558710.
Information	3/29/2019 8:58:31 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Google_Chrome_67_V01\google_chrome_67_v01.exe with the following commandline: /P /IC /NOCHECK
Information	3/29/2019 8:58:23 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Google_Chrome_67_V01
Information	3/29/2019 8:58:23 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	3/29/2019 8:58:23 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	3/29/2019 8:58:23 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	3/29/2019 8:58:21 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	3/29/2019 8:58:21 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/29/2019 8:58:21 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/29/2019 8:58:21 AM	GE Software	0	(1)	++No Install Check was performed.
Information	3/29/2019 8:58:21 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/29/2019 8:58:19 AM	GE Software	0	(1)	++ Google_Chrome_67_V01 was launched using the following Command line: /P /IC
Information	3/29/2019 8:58:18 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: 212558710.
Information	3/29/2019 8:58:18 AM	GE Software	0	(1)	++ The installation of google_chrome_67_v01.exe was launched with the following Command Line Switches: /P /IC
Information	3/29/2019 8:52:36 AM	Outlook	27	None	An unexpected error has occurred.
Information	3/29/2019 8:47:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 8:46:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 35, Deleted: 78, Modified: 116, Compared: 32022, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	3/29/2019 8:46:10 AM	Outlook	27	None	An unexpected error has occurred.
Information	3/29/2019 8:42:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20304.
Information	3/29/2019 8:42:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/29/2019 8:42:31 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 390

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 796

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 390

Information	3/29/2019 8:42:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/29/2019 8:41:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/29/2019 8:36:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26478)(?)])(1 )(2 )]

"
Information	3/29/2019 8:36:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2019 8:36:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26478)(?)])(1 )(2 )]

"
Information	3/29/2019 8:36:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26478)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 8:36:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/29/2019 8:36:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 8:36:45 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 8:35:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/29/2019 8:34:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 8:34:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:18Z. Reason: GVLK.
Information	3/29/2019 8:29:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/29/2019 8:28:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/29/2019 8:27:16 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/29/2019 8:27:15 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Warning	3/29/2019 8:26:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/29/2019 8:24:05 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {38DF5AC3-AE36-45AD-B248-46E7022917CE}
Error	3/29/2019 8:23:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/29/2019 8:23:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26491)(?)])(1 )(2 )]

"
Information	3/29/2019 8:23:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2019 8:23:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26491)(?)])(1 )(2 )]

"
Information	3/29/2019 8:23:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26491)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 8:23:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/29/2019 8:23:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 8:23:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 8:23:28 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	3/29/2019 8:23:10 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/29/2019 8:23:07 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/29/2019 8:23:05 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/29/2019 8:23:03 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/29/2019 8:22:18 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	3/29/2019 8:22:18 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	3/29/2019 8:22:17 AM	ESENT	302	Logging/Recovery	Windows (9896) Windows: The database engine has successfully completed recovery steps.
Information	3/29/2019 8:22:02 AM	ESENT	301	Logging/Recovery	Windows (9896) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/29/2019 8:22:02 AM	ESENT	300	Logging/Recovery	Windows (9896) Windows: The database engine is initiating recovery steps.
Information	3/29/2019 8:22:02 AM	ESENT	102	General	Windows (9896) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	3/29/2019 8:21:40 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/29/2019 8:21:40 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/29/2019 8:21:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2019 8:21:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 8:21:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 8:21:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 8:21:11 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9208.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/29/2019 8:20:39 AM	Service1	0	None	Service started successfully.
Error	3/29/2019 8:20:20 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/29/2019 8:20:20 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/29/2019 8:20:05 AM	MTAService.OnSessionChange	0	None	8:20:05 AM - Logon : 212558710
Information	3/29/2019 8:20:00 AM	MTAService.OnSessionChange	0	None	8:20:00 AM - Session change notice received: SessionLogon Session ID: 1
Information	3/29/2019 8:19:59 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/29/2019 8:19:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/29/2019 8:19:59 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/29/2019 8:19:59 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/29/2019 8:19:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/29/2019 8:19:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/29/2019 8:19:51 AM	PostgreSQL	0	None	Server started and accepting connections

Information	3/29/2019 8:19:50 AM	PostgreSQL	0	None	"2019-03-29 08:19:50 IST LOG:  redirecting log output to logging collector process
2019-03-29 08:19:50 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/29/2019 8:19:48 AM	PostgreSQL	0	None	Waiting for server startup...

Information	3/29/2019 8:19:36 AM	MTAService	0	None	Service started successfully.
Information	3/29/2019 8:19:36 AM	MTAService.OnStart	0	None	8:19:36 AM - Waiting for user to Logon
Information	3/29/2019 8:19:26 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/29/2019 8:19:21 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:21 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/29/2019 8:19:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/29/2019 8:19:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/29/2019 8:19:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/29/2019 8:19:20 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/29/2019 8:19:19 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:18 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/29/2019 8:19:18 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/29/2019 8:19:18 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/29/2019 8:19:18 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4964 at 3/29/2019 8:12:39 AM (local) 3/29/2019 2:42:39 AM (UTC). This is an informational message only; no user action is required.
Information	3/29/2019 8:19:16 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/29/2019 8:19:15 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/29/2019 8:19:15 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/29/2019 8:19:15 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/29/2019 8:19:15 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/29/2019 8:19:15 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4408.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/29/2019 8:19:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/29/2019 8:17:29 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/29/2019 8:17:04 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	3/29/2019 8:17:03 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/29/2019 8:16:32 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/29/2019 8:16:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/29/2019 8:16:32 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/29/2019 8:12:49 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	3/29/2019 8:12:39 AM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	3/29/2019 8:12:39 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	3/29/2019 8:12:37 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/29/2019 8:12:37 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	3/29/2019 8:12:34 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 30 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 340 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5076 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 8484 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/29/2019 8:12:34 AM	MTAService.OnSessionChange	0	None	8:12:34 AM - Logoff
Information	3/29/2019 8:12:34 AM	MTAService.OnSessionChange	0	None	8:12:34 AM - Session change notice received: SessionLogoff Session ID: 1
Information	3/29/2019 8:12:33 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/29/2019 8:12:33 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/29/2019 8:12:33 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	3/29/2019 8:04:03 AM	MTAService.OnSessionChange	0	None	8:04:03 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/29/2019 6:39:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 5:56:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44d28e59-51b9-11e9-8b6d-80000bd6758f
Report Status: 0"
Warning	3/29/2019 4:49:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 4:31:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 4:31:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:26Z. Reason: GVLK.
Information	3/29/2019 4:26:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2019 4:26:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 4:26:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 4:26:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 3:43:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 3:43:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:19Z. Reason: GVLK.
Information	3/29/2019 3:38:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2019 3:38:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 3:38:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 3:38:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/29/2019 3:34:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2019 3:34:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:38Z. Reason: GVLK.
Information	3/29/2019 3:29:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2019 3:29:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2019 3:29:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2019 3:29:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/29/2019 3:06:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/29/2019 1:33:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2019 12:56:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b296646-518f-11e9-8b6d-80000bd6758f
Report Status: 0"
Information	3/29/2019 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/28/2019 11:49:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/28/2019 9:52:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 9:31:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T15:59:07.759224600Z.
Information	3/28/2019 9:31:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T15:59:08.757631000Z.
Information	3/28/2019 9:31:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T15:59:06.012013400Z.
Information	3/28/2019 9:31:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{EB0F4690-91BD-4C98-A4C8-0611E67648E9}v4.23.8603.0\CsAgent.msi. Client Process Id: 13924.
Information	3/28/2019 9:31:01 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.23.8603.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	3/28/2019 9:31:01 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	3/28/2019 9:29:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T15:59:08.757631000Z.
Information	3/28/2019 9:29:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T15:59:07.759224600Z.
Information	3/28/2019 9:29:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T15:59:06.012013400Z.
Information	3/28/2019 9:29:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{EB0F4690-91BD-4C98-A4C8-0611E67648E9}v4.23.8603.0\CsAgent.msi. Client Process Id: 13924.
Information	3/28/2019 9:12:22 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/28/2019 8:08:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T14:38:44.738104900Z.
Information	3/28/2019 8:08:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T14:38:44.738104900Z.
Information	3/28/2019 8:08:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 14460.
Information	3/28/2019 8:08:46 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 0.
Information	3/28/2019 8:08:46 PM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	3/28/2019 8:08:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 14460.
Information	3/28/2019 8:08:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 14460.
Information	3/28/2019 8:08:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 1638.
Information	3/28/2019 8:08:44 PM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	3/28/2019 8:08:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 14460.
Information	3/28/2019 8:07:33 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\Microsoft.SqlServer.SQLTaskConnectionsWrap.dll has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9208.0000.
Warning	3/28/2019 8:04:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 8:02:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T14:32:16.298627100Z.
Information	3/28/2019 8:02:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 10908.
Information	3/28/2019 8:02:26 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	3/28/2019 8:02:26 PM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	3/28/2019 8:02:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T14:32:16.298627100Z.
Information	3/28/2019 8:01:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 10908.
Information	3/28/2019 8:01:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 10908.
Information	3/28/2019 8:01:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 1638.
Information	3/28/2019 8:01:53 PM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	3/28/2019 8:01:47 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 10908.
Information	3/28/2019 7:57:37 PM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	3/28/2019 7:57:36 PM	GE Software	0	(1)	++No Reboot requested by Google_Chrome_67_V01
Information	3/28/2019 7:57:30 PM	GE Software	0	(1)	Package Tracker MIF file created.
Information	3/28/2019 7:57:30 PM	GE Software	0	(1)	Updating Pactrack registry keys with google_chrome_67_v01
Information	3/28/2019 7:57:30 PM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	3/28/2019 7:57:26 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	3/28/2019 7:56:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 709eeb6f-5165-11e9-8b6d-80000bd6758f
Report Status: 0"
Information	3/28/2019 7:56:11 PM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	3/28/2019 7:56:11 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: 212558710.
Information	3/28/2019 7:56:07 PM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Google_Chrome_67_V01\google_chrome_67_v01.exe with the following commandline: /P /IC /NOCHECK
Information	3/28/2019 7:55:49 PM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Google_Chrome_67_V01
Information	3/28/2019 7:55:49 PM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	3/28/2019 7:55:49 PM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	3/28/2019 7:55:49 PM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	3/28/2019 7:55:47 PM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	3/28/2019 7:55:47 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/28/2019 7:55:47 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/28/2019 7:55:47 PM	GE Software	0	(1)	++No Install Check was performed.
Information	3/28/2019 7:55:47 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/28/2019 7:55:45 PM	GE Software	0	(1)	++ Google_Chrome_67_V01 was launched using the following Command line: /P /IC
Information	3/28/2019 7:55:45 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: 212558710.
Information	3/28/2019 7:55:45 PM	GE Software	0	(1)	++ The installation of google_chrome_67_v01.exe was launched with the following Command Line Switches: /P /IC
Information	3/28/2019 7:53:05 PM	MTAService.OnSessionChange	0	None	7:53:05 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2019 7:41:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 7:36:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	3/28/2019 7:35:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27259)(?)])(1 )(2 )]

"
Information	3/28/2019 7:35:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2019 7:35:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27259)(?)])(1 )(2 )]

"
Information	3/28/2019 7:35:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27259)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 7:35:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/28/2019 7:35:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 7:35:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/28/2019 7:07:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 7:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27291)(?)])(1 )(2 )]

"
Information	3/28/2019 7:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2019 7:02:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27291)(?)])(1 )(2 )]

"
Information	3/28/2019 7:02:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27291)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 7:02:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/28/2019 7:02:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 7:02:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/28/2019 6:31:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 5:29:50 PM	MTAService.OnSessionChange	0	None	5:29:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/28/2019 5:14:39 PM	MTAService.OnSessionChange	0	None	5:14:39 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2019 4:45:02 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:40:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9544.
Information	3/28/2019 4:40:05 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.10730.20304. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:40:05 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	3/28/2019 4:40:04 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/28/2019 4:40:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27434)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 4:40:02 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/28/2019 4:40:02 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/28/2019 4:40:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:40:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/28/2019 4:40:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:39:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/28/2019 4:39:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:39:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:40 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.10730.20304. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:39:40 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	3/28/2019 4:39:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20304. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:39:37 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	3/28/2019 4:39:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20304. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:39:34 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	3/28/2019 4:39:25 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:39:24 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20304. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:39:24 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	3/28/2019 4:39:14 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/28/2019 4:39:13 PM	ESENT	102	General	Windows (12940) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/28/2019 4:38:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:38:51 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	3/28/2019 4:38:51 PM	ESENT	103	General	Windows (8296) Windows: The database engine stopped the instance (0).
Information	3/28/2019 4:38:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:38:46 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20304. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/28/2019 4:38:46 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Error	3/28/2019 4:38:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/28/2019 4:36:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 4:36:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:36:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:13Z. Reason: GVLK.
Information	3/28/2019 4:35:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9544.
Information	3/28/2019 4:34:50 PM	McLogEvent	257	None	The scan of C:\Users\212558710\Downloads\ZAP_2_6_0_windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9208.0000.
Information	3/28/2019 4:34:20 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/28/2019 4:34:20 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/28/2019 4:34:19 PM	ESENT	102	General	Windows (8296) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/28/2019 4:34:18 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	3/28/2019 4:34:18 PM	ESENT	103	General	Windows (3016) Windows: The database engine stopped the instance (0).
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:13 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/28/2019 4:34:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/28/2019 4:34:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	3/28/2019 4:34:00 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2019 4:33:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27440)(?)])(1 )(2 )]

"
Information	3/28/2019 4:33:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2019 4:33:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27440)(?)])(1 )(2 )]

"
Information	3/28/2019 4:33:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27440)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 4:33:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/28/2019 4:33:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Error	3/28/2019 4:32:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2019 4:32:30 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/28/2019 4:32:29 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/28/2019 4:32:21 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	3/28/2019 4:32:21 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	3/28/2019 4:31:01 PM	MTAService.OnSessionChange	0	None	4:31:01 PM - Logon : 212558710
Information	3/28/2019 4:30:56 PM	MTAService.OnSessionChange	0	None	4:30:56 PM - Session change notice received: SessionLogon Session ID: 1
Information	3/28/2019 4:30:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/28/2019 4:30:55 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/28/2019 4:30:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/28/2019 4:30:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/28/2019 4:30:01 PM	MTAService.OnSessionChange	0	None	4:30:01 PM - Session change notice received: ConsoleConnect Session ID: 1
Warning	3/28/2019 4:29:59 PM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 126 second(s) to handle the notification event (CreateSession).
Information	3/28/2019 4:29:09 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/28/2019 4:29:07 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	3/28/2019 4:29:07 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e633ae97-1bc1-4fdb-873e-55456b30489a"
Information	3/28/2019 4:29:07 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60bf7784-81ca-4556-a959-9c152e15669d"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=544d2e70-aa48-4e2b-a43d-52ec83aa0427"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=cf84484a-44a0-4b67-b1e9-4186929240ca"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3acae882-52ce-42dd-a708-eca29d35bb09"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=56421083-4260-4bf5-8bb8-2a9aed708066"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c6341c8-6dda-4a94-810d-45c3ba3108cf"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5a9f936e-3aee-409b-ada6-cd0169049418"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d6a534c8-cdf3-442d-850f-925004c6ed8f"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9d16bfa3-a0aa-4659-8555-04360305c600"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=576982b1-f73d-442b-8f34-4e9c8245f728"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4958405-6251-473b-b4e9-649f61239091"
Information	3/28/2019 4:29:06 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=cb1acfd5-4ad6-46f7-a508-95096e7e53cb"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60c6b5ae-abeb-405a-ae22-b1a179b9a0b8"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f46cd2ab-a792-4421-a25b-10a2c2b6065e"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3fcfa8df-de4c-4ae9-a6eb-ce92f6000012"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=70abdf70-5bb0-46f5-bade-1e7fb728eb96"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=84904722-dfb7-4e90-b656-eac912151df3"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=380aa12a-eeb0-4851-8915-e97ff3c99037"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4e1412c-eafa-4c01-bf17-96f00ec2e8c0"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ba2baae7-dc04-4afe-82d9-abff518374c0"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=55e45973-1275-415b-84ea-5dd31d2bf5b6"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=59f44fbc-2ce4-4025-900a-219030f1d5f1"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=8c6aed11-5d85-47a7-98cd-91e8dd441d09"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=33ae5639-431e-4d01-a725-10b55fbf19fa"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b6238cce-6111-4dd8-8e3a-2131345b41f4"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c2a811a-4066-41d9-b01e-6ce41951b612"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=96180128-4419-4223-81d5-455dd1f0b8cc"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f327bfa6-fbf6-4ed0-a4a9-bd4bfad744a4"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32d48179-769f-42a7-8318-85183032750f"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=1967969c-5f25-4bbb-b0b6-9b2a85956b82"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bf09d53d-e057-4345-8573-3258cbcdcef0"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f108a725-53a3-46f8-8638-671f21618af5"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=df86036a-2bdd-40fb-95e5-7758a40888a0"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8ad24e6d-710c-41c0-8442-09360563915a"
Information	3/28/2019 4:29:05 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=528bab55-7786-4356-b2ad-88fe1b8fcac8"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=36c02486-b646-42e2-9d99-3f004cdf9417"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=63ac7ebe-fee9-4a32-837b-e3d4eb8aab69"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8c2ef592-c12b-4876-8763-5b9b86e92d9d"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43734373-179d-47a1-b21b-115629169450"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1d9e42c5-325e-442c-98af-fd1302c4df68"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=958bc5e1-123f-4165-bb7b-8e858e8e919e"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cbf0d3b-d091-4f6c-8e5d-4efbaec5b4e3"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=95f0af3a-edc0-44f3-b03c-b3bdf67435ca"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=48f8ef71-4394-4531-a9de-2ec4c93ec39a"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=22628221-fa6f-46db-a6d9-67311a301511"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f7934e94-8990-4c80-b27a-5cf7eece2fa5"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5ad7f835-c1e8-44f5-baba-8bf994ae4d24"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4526aedc-292b-409a-bc96-f9d1d2381942"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c133fb56-f2de-4574-898a-41d104a45835"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2602ff5c-19a2-4669-b1cc-ab7fd12dfc65"
Information	3/28/2019 4:29:04 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=450354ce-2bb6-4774-a3b6-f7a0a9b987d4"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2c74a701-ffb9-4c86-9f1e-73bf1fd37556"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=76be9fd9-fea4-4be2-ba66-936c33de5275"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9b5f2cc3-88de-453f-869e-57da5482fb25"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb57abfe-5d2d-4c1f-ba4a-61a7115e0583"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7b206866-c2d5-4e3e-9653-cd48d22d876e"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1664fd49-b86a-42c8-aac6-dee2ca9fd24a"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=4b14f23e-05d8-4f50-84c1-50bc046e8af4"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=707c0c99-18c9-4857-b121-a2294a144fdd"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	3/28/2019 4:29:03 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	3/28/2019 4:29:02 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	3/28/2019 4:29:02 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	3/28/2019 4:29:02 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	3/28/2019 4:29:02 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	3/28/2019 4:29:02 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	3/28/2019 4:28:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/28/2019 4:28:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:28:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/28/2019 4:28:53 PM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	3/28/2019 4:28:48 PM	ESENT	302	Logging/Recovery	Windows (3016) Windows: The database engine has successfully completed recovery steps.
Information	3/28/2019 4:28:43 PM	ESENT	301	Logging/Recovery	Windows (3016) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/28/2019 4:28:43 PM	ESENT	300	Logging/Recovery	Windows (3016) Windows: The database engine is initiating recovery steps.
Information	3/28/2019 4:28:43 PM	ESENT	102	General	Windows (3016) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/28/2019 4:28:42 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	3/28/2019 4:28:33 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/28/2019 4:28:32 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/28/2019 4:28:31 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/28/2019 4:27:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 4:27:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 4:27:36 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	3/28/2019 4:27:35 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (WMPPlayer)
License Id=7d141cc8-75a1-5d14-1583-53c8065e7556"
Information	3/28/2019 4:27:34 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (SMBServer)
License Id=72265f61-2ae6-0dcf-a15e-3495ea6c5663"
Information	3/28/2019 4:27:34 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (Microsoft-Windows-NetworkBridge)
License Id=8e782466-c8cd-72f2-d954-38c2921ec3a9"
Information	3/28/2019 4:27:34 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	3/28/2019 4:27:34 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	3/28/2019 4:27:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:27:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/28/2019 4:26:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 4:26:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/28/2019 4:26:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T10:56:49.290375400Z.
Information	3/28/2019 4:26:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9208.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/28/2019 4:25:20 PM	Service1	0	None	Service started successfully.
Error	3/28/2019 4:25:06 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/28/2019 4:25:05 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/28/2019 4:25:02 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/28/2019 4:25:01 PM	PostgreSQL	0	None	Server started and accepting connections

Information	3/28/2019 4:24:58 PM	PostgreSQL	0	None	"2019-03-28 16:24:58 IST LOG:  redirecting log output to logging collector process
2019-03-28 16:24:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/28/2019 4:24:51 PM	PostgreSQL	0	None	Waiting for server startup...

Information	3/28/2019 4:24:41 PM	MTAService	0	None	Service started successfully.
Information	3/28/2019 4:24:41 PM	MTAService.OnStart	0	None	4:24:41 PM - Waiting for user to Logon
Information	3/28/2019 4:24:37 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:37 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/28/2019 4:24:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/28/2019 4:24:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/28/2019 4:24:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/28/2019 4:24:36 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/28/2019 4:24:35 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:35 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/28/2019 4:24:33 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:32 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/28/2019 4:24:32 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/28/2019 4:24:32 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/28/2019 4:24:32 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/28/2019 4:24:32 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/28/2019 4:24:29 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:29 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4644 at 3/28/2019 4:15:42 PM (local) 3/28/2019 10:45:42 AM (UTC). This is an informational message only; no user action is required.
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/28/2019 4:24:28 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/28/2019 4:24:26 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/28/2019 4:24:26 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/28/2019 4:24:26 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/28/2019 4:24:26 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4964.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/28/2019 4:24:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/28/2019 4:22:42 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/28/2019 4:21:52 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	3/28/2019 4:21:51 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/28/2019 4:20:47 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/28/2019 4:20:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/28/2019 4:20:47 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/28/2019 4:15:48 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	3/28/2019 4:15:48 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	3/28/2019 4:15:41 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	3/28/2019 4:12:37 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 4:12:37 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/28/2019 4:12:36 PM	MTAService.OnSessionChange	0	None	4:12:35 PM - Logoff
Warning	3/28/2019 4:12:35 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 36 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 340 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 596 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 596 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2668 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4984 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 596 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 596 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 596 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2184 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/28/2019 4:12:35 PM	MTAService.OnSessionChange	0	None	4:12:35 PM - Session change notice received: SessionLogoff Session ID: 1
Information	3/28/2019 4:12:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/28/2019 4:12:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/28/2019 4:12:33 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	3/28/2019 4:11:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/28/2019 4:09:32 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2019 4:03:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:03:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:41Z. Reason: GVLK.
Error	3/28/2019 4:01:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2019 3:58:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 3:58:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 3:58:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 3:58:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/28/2019 3:52:09 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/28/2019 3:52:09 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2019 3:50:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A7A76FD6-91B5-3C7F-B37D-DFDA03F5FBAE}. Client Process Id: 14040.
Information	3/28/2019 3:50:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A7A76FD6-91B5-3C7F-B37D-DFDA03F5FBAE}. Client Process Id: 14040.
Information	3/28/2019 3:50:54 PM	GE Software	0	(1)	Manual Uninstall - User chose to uninstall
Information	3/28/2019 3:50:51 PM	GE Software	0	(1)	Running uninstall for google_chrome_34_v01 - Mode=FULL
Information	3/28/2019 3:20:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T09:50:20.422305000Z.
Information	3/28/2019 3:20:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 17392.
Information	3/28/2019 3:20:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 0.
Information	3/28/2019 3:20:20 PM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	3/28/2019 3:20:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T09:50:20.422305000Z.
Information	3/28/2019 3:20:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 17392.
Information	3/28/2019 3:20:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 17392.
Information	3/28/2019 3:20:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.34.7. Product Language: 1033. Manufacturer: Google LLC. Reconfiguration success or error status: 1638.
Information	3/28/2019 3:20:19 PM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	3/28/2019 3:20:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleUpdateHelper.msi. Client Process Id: 17392.
Information	3/28/2019 2:56:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 83bb0302-513b-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/28/2019 2:40:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 2:23:49 PM	MTAService.OnSessionChange	0	None	2:23:49 PM - Session change notice received: SessionUnlock Session ID: 1
Error	3/28/2019 2:23:36 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:36 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:31 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:31 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:26 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:26 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:22 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/28/2019 2:23:21 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/28/2019 1:46:46 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 19584) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/28/2019 1:46:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T08:16:45.472281000Z.
Information	3/28/2019 1:46:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎28T08:16:42.164950300Z.
Information	3/28/2019 1:28:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2019 1:28:32 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/28/2019 1:28:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2019 1:19:53 PM	MTAService.OnSessionChange	0	None	1:19:53 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2019 1:02:20 PM	MTAService.OnSessionChange	0	None	1:02:20 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/28/2019 12:59:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 12:54:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9208.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/28/2019 12:47:55 PM	MTAService.OnSessionChange	0	None	12:47:55 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2019 12:40:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/28/2019 12:40:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/28/2019 12:39:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T07:09:04.276285900Z.
Information	3/28/2019 12:39:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 9264.
Information	3/28/2019 12:39:17 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.221. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/28/2019 12:39:17 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	3/28/2019 12:39:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T07:09:04.276285900Z.
Information	3/28/2019 12:39:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 9264.
Information	3/28/2019 12:38:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎28T07:08:12.805285900Z.
Information	3/28/2019 12:38:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9264.
Information	3/28/2019 12:38:35 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight2. Product Version: 1.4.0.6041. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/28/2019 12:38:35 PM	MsiInstaller	11724	None	Product: 4Sight2 -- Removal completed successfully.
Information	3/28/2019 12:38:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T07:08:12.805285900Z.
Information	3/28/2019 12:38:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9264.
Information	3/28/2019 12:31:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎03‎-‎28T07:01:25.535254400Z.
Information	3/28/2019 12:31:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎28T07:01:25.535254400Z.
Information	3/28/2019 11:25:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/28/2019 11:24:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/28/2019 11:17:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 11:17:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:03Z. Reason: GVLK.
Warning	3/28/2019 11:13:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 11:12:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 11:12:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 11:12:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 11:12:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/28/2019 10:43:00 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/28/2019 10:42:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎28T05:12:59.433674600Z.
Information	3/28/2019 10:42:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎28T05:12:57.259457200Z.
Information	3/28/2019 10:28:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/28/2019 10:28:05 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/28/2019 9:58:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/28/2019 9:56:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 998d83a1-5111-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/28/2019 9:38:22 AM	MTAService.OnSessionChange	0	None	9:38:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/28/2019 9:28:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/28/2019 9:15:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 9:11:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 9:11:24 AM	MTAService.OnSessionChange	0	None	9:11:24 AM - Session change notice received: SessionLock Session ID: 1
Error	3/28/2019 9:06:55 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/28/2019 9:06:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27887)(?)])(1 )(2 )]

"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27887)(?)])(1 )(2 )]

"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27887)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 9:06:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/28/2019 9:04:52 AM	MTAService.OnSessionChange	0	None	9:04:52 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/28/2019 7:26:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 7:02:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 7:02:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:39Z. Reason: GVLK.
Information	3/28/2019 6:57:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 6:57:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 6:57:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 6:57:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/28/2019 5:33:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 5:28:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2019 4:56:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: afeac6b7-50e7-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/28/2019 4:31:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:31:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:41Z. Reason: GVLK.
Information	3/28/2019 4:26:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 4:26:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 4:26:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:26:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/28/2019 4:24:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2019 4:24:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:40Z. Reason: GVLK.
Information	3/28/2019 4:19:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2019 4:19:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2019 4:19:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2019 4:19:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/28/2019 3:37:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 2:32:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/28/2019 2:20:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/28/2019 1:50:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 1:28:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2019 1:28:00 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/28/2019 1:27:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/28/2019 12:04:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/27/2019 11:56:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c64cf237-50bd-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/27/2019 10:22:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 9:27:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 9:27:46 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/27/2019 9:27:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/27/2019 8:36:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 8:34:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 8:30:24 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 23172) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/27/2019 8:30:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎27T15:00:23.573429700Z.
Information	3/27/2019 8:30:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎27T15:00:15.010573500Z.
Information	3/27/2019 8:29:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2019 8:29:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 8:29:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 8:11:27 PM	MTAService.OnSessionChange	0	None	8:11:27 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2019 6:59:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 6:56:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dc6c05e1-5093-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/27/2019 6:07:24 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/27/2019 6:07:23 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/27/2019 6:00:15 PM	MTAService.OnSessionChange	0	None	6:00:15 PM - Session change notice received: SessionUnlock Session ID: 1
Error	3/27/2019 5:58:17 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/27/2019 5:58:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/27/2019 5:27:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 5:10:52 PM	MTAService.OnSessionChange	0	None	5:10:52 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2019 5:09:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 4:37:47 PM	MTAService.OnSessionChange	0	None	4:37:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 4:29:34 PM	MTAService.OnSessionChange	0	None	4:29:34 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2019 3:49:17 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 24792 did not respond and is being forcibly terminated {filter host process 24044}. 

Warning	3/27/2019 3:13:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 2:52:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎03‎-‎27T09:22:31.220696500Z.
Information	3/27/2019 2:52:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎27T09:22:31.220696500Z.
Information	3/27/2019 2:37:26 PM	MTAService.OnSessionChange	0	None	2:37:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 2:31:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 2:31:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:51Z. Reason: GVLK.
Information	3/27/2019 2:26:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2019 2:26:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 2:26:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 2:26:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 2:14:33 PM	MTAService.OnSessionChange	0	None	2:14:33 PM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2019 2:09:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/27/2019 2:08:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/27/2019 1:55:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f25ec123-5069-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/27/2019 1:49:56 PM	MTAService.OnSessionChange	0	None	1:49:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 1:28:27 PM	MTAService.OnSessionChange	0	None	1:28:27 PM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2019 1:27:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 1:27:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/27/2019 1:27:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/27/2019 1:19:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 1:01:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9207.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/27/2019 12:38:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/27/2019 12:38:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/27/2019 12:17:38 PM	MTAService.OnSessionChange	0	None	12:17:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 12:09:44 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/27/2019 12:09:44 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/27/2019 12:09:18 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/27/2019 12:09:16 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/27/2019 12:09:16 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/27/2019 12:08:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 31894, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/27/2019 12:05:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/27/2019 12:05:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/27/2019 11:56:08 AM	MTAService.OnSessionChange	0	None	11:56:08 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2019 11:36:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 11:02:45 AM	MTAService.OnSessionChange	0	None	11:02:45 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 11:02:36 AM	MTAService.OnSessionChange	0	None	11:02:36 AM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\SearchProtocolHost.exe' (pid 23252) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/27/2019 11:02:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎27T05:32:26.138269900Z.
Information	3/27/2019 11:02:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎27T05:32:24.158071900Z.
Information	3/27/2019 10:16:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 10:16:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:45Z. Reason: GVLK.
Information	3/27/2019 10:11:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2019 10:11:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 10:11:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 10:11:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 10:09:44 AM	MTAService.OnSessionChange	0	None	10:09:44 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2019 10:06:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/27/2019 10:05:49 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/27/2019 10:05:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎27T04:35:48.467708600Z.
Information	3/27/2019 10:05:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎27T04:35:46.445708600Z.
Information	3/27/2019 9:48:31 AM	MTAService.OnSessionChange	0	None	9:48:31 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2019 9:45:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 9:26:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 9:11:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/27/2019 9:06:57 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/27/2019 9:06:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29327)(?)])(1 )(2 )]

"
Information	3/27/2019 9:06:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2019 9:06:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29327)(?)])(1 )(2 )]

"
Information	3/27/2019 9:06:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29327)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 9:06:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2019 9:06:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 9:06:55 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 8:55:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0876189e-5040-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/27/2019 8:53:47 AM	MTAService.OnSessionChange	0	None	8:53:47 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/27/2019 7:52:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 7:31:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 7:31:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:11Z. Reason: GVLK.
Information	3/27/2019 7:26:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2019 7:26:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 7:26:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 7:26:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/27/2019 6:21:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/27/2019 6:00:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎27T00:30:59.038895100Z.
Information	3/27/2019 6:00:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎27T00:30:57.122703500Z.
Information	3/27/2019 5:26:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 4:52:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 4:52:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:44Z. Reason: GVLK.
Information	3/27/2019 4:47:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2019 4:47:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 4:47:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 4:47:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 4:47:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2019 4:47:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:32Z. Reason: GVLK.
Warning	3/27/2019 4:42:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 4:42:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2019 4:42:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2019 4:42:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2019 4:42:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/27/2019 3:55:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ec05a1f-5016-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/27/2019 2:47:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 1:27:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2019 1:27:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/27/2019 1:26:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/27/2019 12:56:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/26/2019 11:10:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 10:55:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 34fc1e45-4fec-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/26/2019 9:35:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 9:26:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\SearchProtocolHost.exe' (pid 17888) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 9:19:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T15:49:03.084387200Z.
Information	3/26/2019 9:19:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T15:49:01.269205700Z.
Information	3/26/2019 8:35:27 PM	MTAService.OnSessionChange	0	None	8:35:27 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/26/2019 7:46:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 6:49:30 PM	MTAService.OnSessionChange	0	None	6:49:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 6:06:32 PM	MTAService.OnSessionChange	0	None	6:06:32 PM - Session change notice received: SessionLock Session ID: 1
Error	3/26/2019 5:59:08 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 5:59:08 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/26/2019 5:55:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b4b9626-4fc2-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/26/2019 5:52:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 5:45:34 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.221. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/26/2019 5:45:34 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	3/26/2019 5:45:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T12:14:34.707665300Z.
Information	3/26/2019 5:45:32 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{044F3D0C-3D8D-4D79-BE24-A0EF70876ED2}\DeviceManager.msi. Client Process Id: 18424.
Information	3/26/2019 5:44:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T12:14:34.707665300Z.
Information	3/26/2019 5:44:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{044F3D0C-3D8D-4D79-BE24-A0EF70876ED2}\DeviceManager.msi. Client Process Id: 18424.
Information	3/26/2019 5:44:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T12:14:21.897665300Z.
Information	3/26/2019 5:44:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{8C5D81EE-85B3-3031-8074-6F3E5BE8AF19}v2.1.8.0\aspnetcore-runtime-2.1.8-win-x86.msi. Client Process Id: 14496.
Information	3/26/2019 5:44:28 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft ASP.NET Core 2.1.8 Shared Framework (x86). Product Version: 2.1.8.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	3/26/2019 5:44:28 PM	MsiInstaller	11707	None	Product: Microsoft ASP.NET Core 2.1.8 Shared Framework (x86) -- Installation completed successfully.
Information	3/26/2019 5:44:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T12:14:21.897665300Z.
Information	3/26/2019 5:44:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{8C5D81EE-85B3-3031-8074-6F3E5BE8AF19}v2.1.8.0\aspnetcore-runtime-2.1.8-win-x86.msi. Client Process Id: 14496.
Information	3/26/2019 5:44:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T12:14:05.176665300Z.
Information	3/26/2019 5:44:15 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{286353C1-45CA-4BC2-813A-CD66DC77C1C9}v16.96.27317\dotnet-host-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:44:15 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Host - 2.1.8 (x86). Product Version: 16.96.27317. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	3/26/2019 5:44:15 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Host - 2.1.8 (x86) -- Installation completed successfully.
Information	3/26/2019 5:44:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T12:14:05.176665300Z.
Information	3/26/2019 5:44:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T12:14:03.044665300Z.
Information	3/26/2019 5:44:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{286353C1-45CA-4BC2-813A-CD66DC77C1C9}v16.96.27317\dotnet-host-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:44:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{8A11A99E-6B06-4255-B59F-A6F596851DCA}v16.96.27317\dotnet-hostfxr-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:44:05 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Host FX Resolver - 2.1.8 (x86). Product Version: 16.96.27317. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	3/26/2019 5:44:05 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Host FX Resolver - 2.1.8 (x86) -- Installation completed successfully.
Information	3/26/2019 5:44:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T12:14:03.044665300Z.
Information	3/26/2019 5:44:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T12:13:55.168665300Z.
Information	3/26/2019 5:44:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{8A11A99E-6B06-4255-B59F-A6F596851DCA}v16.96.27317\dotnet-hostfxr-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:44:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{7139E572-2928-4622-BE04-14D02BE5C874}v16.96.27317\dotnet-runtime-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:44:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Runtime - 2.1.8 (x86). Product Version: 16.96.27317. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	3/26/2019 5:44:02 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Runtime - 2.1.8 (x86) -- Installation completed successfully.
Information	3/26/2019 5:43:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T12:13:55.168665300Z.
Information	3/26/2019 5:43:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{7139E572-2928-4622-BE04-14D02BE5C874}v16.96.27317\dotnet-runtime-2.1.8-win-x86.msi. Client Process Id: 20680.
Information	3/26/2019 5:34:11 PM	MTAService.OnSessionChange	0	None	5:34:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 5:26:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 5:25:57 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 5:25:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T11:55:56.287930100Z.
Information	3/26/2019 5:25:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T11:55:54.586930100Z.
Information	3/26/2019 4:57:10 PM	MTAService.OnSessionChange	0	None	4:57:10 PM - Session change notice received: SessionLock Session ID: 1
Information	3/26/2019 4:47:18 PM	MTAService.OnSessionChange	0	None	4:47:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 4:44:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 4:39:46 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 4:39:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T11:09:45.478997000Z.
Information	3/26/2019 4:39:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T11:09:43.784827600Z.
Information	3/26/2019 4:39:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/26/2019 4:39:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 4:39:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/26/2019 4:10:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 4:00:32 PM	MTAService.OnSessionChange	0	None	4:00:32 PM - Session change notice received: SessionLock Session ID: 1
Information	3/26/2019 3:29:02 PM	MTAService.OnSessionChange	0	None	3:29:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 3:19:12 PM	MTAService.OnSessionChange	0	None	3:19:12 PM - Session change notice received: SessionLock Session ID: 1
Error	3/26/2019 2:54:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:54:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/26/2019 2:54:33 PM	MTAService.OnSessionChange	0	None	2:54:33 PM - Session change notice received: SessionUnlock Session ID: 1
Error	3/26/2019 2:54:09 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:54:09 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:54:03 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:54:03 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:53:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:53:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:53:46 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:53:46 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 2:48:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T09:18:17.027604600Z.
Information	3/26/2019 2:48:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T09:18:15.411604600Z.
Error	3/26/2019 2:32:33 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/26/2019 2:32:33 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	3/26/2019 2:24:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 2:00:45 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 2:00:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T08:30:44.576604600Z.
Information	3/26/2019 2:00:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T08:30:40.073604600Z.
Information	3/26/2019 1:30:27 PM	MTAService.OnSessionChange	0	None	1:30:27 PM - Session change notice received: SessionLock Session ID: 1
Information	3/26/2019 1:26:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 1:26:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/26/2019 1:26:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 1:00:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/26/2019 1:00:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/26/2019 12:55:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61718e5e-4f98-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/26/2019 12:54:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9206.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/26/2019 12:49:29 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.6041. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/26/2019 12:49:29 PM	MsiInstaller	11707	None	Product: 4Sight2 -- Installation operation completed successfully.
Information	3/26/2019 12:48:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎26T07:04:18.242604600Z.
Information	3/26/2019 12:48:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1A7ED342-C5ED-4F21-B575-7F569874CF3A}\4Sight™ 2.msi. Client Process Id: 9208.
Warning	3/26/2019 12:42:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 12:34:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T07:04:18.242604600Z.
Information	3/26/2019 12:32:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/26/2019 12:32:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/26/2019 12:32:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1A7ED342-C5ED-4F21-B575-7F569874CF3A}\4Sight™ 2.msi. Client Process Id: 9208.
Information	3/26/2019 12:24:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 12:24:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:43Z. Reason: GVLK.
Information	3/26/2019 12:19:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 12:19:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 12:19:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 12:19:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2019 12:18:11 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/26/2019 12:14:19 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/26/2019 12:08:41 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/26/2019 11:54:42 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.6041. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	3/26/2019 11:54:42 AM	MsiInstaller	11708	None	Product: 4Sight2 -- Installation operation failed.
Information	3/26/2019 11:51:17 AM	MTAService.OnSessionChange	0	None	11:51:17 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 11:37:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 11:37:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:40Z. Reason: GVLK.
Information	3/26/2019 11:32:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 11:32:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 11:32:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 11:32:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2019 11:32:26 AM	MTAService.OnSessionChange	0	None	11:32:26 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/26/2019 10:56:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 9:56:23 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/26/2019 9:56:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/26/2019 9:56:03 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/26/2019 9:55:28 AM	MTAService.OnSessionChange	0	None	9:55:28 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 9:47:43 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T04:17:43.073937300Z.
Information	3/26/2019 9:47:41 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T04:17:41.416937300Z.
Information	3/26/2019 9:30:54 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 9:30:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T04:00:53.439937300Z.
Information	3/26/2019 9:30:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T04:00:51.802937300Z.
Information	3/26/2019 9:29:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 9:29:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:31Z. Reason: GVLK.
Information	3/26/2019 9:26:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 9:24:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 9:24:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 9:24:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 9:24:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/26/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30767)(?)])(1 )(2 )]

"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30767)(?)])(1 )(2 )]

"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30767)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/26/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/26/2019 9:02:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/26/2019 9:02:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎26T03:32:15.883937300Z.
Information	3/26/2019 9:02:13 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎26T03:32:13.939937300Z.
Warning	3/26/2019 9:02:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 7:55:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74784f7d-4f6e-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/26/2019 7:31:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 7:31:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:21Z. Reason: GVLK.
Information	3/26/2019 7:26:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 7:26:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 7:26:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 7:26:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/26/2019 7:02:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 5:26:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2019 5:03:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 4:11:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 4:11:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:30Z. Reason: GVLK.
Information	3/26/2019 4:06:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 4:06:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 4:06:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 4:06:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2019 4:05:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2019 4:05:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:30Z. Reason: GVLK.
Information	3/26/2019 4:00:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2019 4:00:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2019 4:00:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2019 4:00:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/26/2019 3:25:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 2:55:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8a9ac69a-4f44-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/26/2019 1:47:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2019 1:26:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 1:26:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/26/2019 1:25:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/25/2019 11:56:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/25/2019 10:23:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 9:55:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0f9f661-4f1a-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/25/2019 9:54:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 9:54:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:53:09Z. Reason: GVLK.
Information	3/25/2019 9:49:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2019 9:49:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 9:49:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 9:48:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2019 9:25:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 8:30:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T15:00:42.343273500Z.
Information	3/25/2019 8:30:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T15:00:39.805019700Z.
Warning	3/25/2019 8:27:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 7:58:42 PM	MTAService.OnSessionChange	0	None	7:58:42 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/25/2019 6:32:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 5:40:01 PM	MTAService.OnSessionChange	0	None	5:40:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/25/2019 5:25:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2019 5:00:39 PM	MTAService.OnSessionChange	0	None	5:00:39 PM - Session change notice received: SessionLock Session ID: 1
Information	3/25/2019 4:55:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a54f0b98-4ef0-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/25/2019 4:34:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 3:28:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 3:28:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T09:52:41Z. Reason: GVLK.
Information	3/25/2019 3:23:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 3:23:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 3:23:40 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/03/25 09:52"
Information	3/25/2019 3:23:39 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/03/25 09:52, 0, 1, 248880, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/25/2019 3:17:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2019 3:17:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 3:17:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 3:17:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/25/2019 2:58:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 2:55:39 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 2:55:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T09:25:38.362897900Z.
Information	3/25/2019 2:55:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T09:25:23.338395600Z.
Information	3/25/2019 2:23:45 PM	MTAService.OnSessionChange	0	None	2:23:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 22160) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 2:15:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T08:45:59.278013200Z.
Information	3/25/2019 2:15:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T08:45:57.134798900Z.
Information	3/25/2019 1:25:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2019 1:25:46 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/25/2019 1:25:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/25/2019 1:25:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 1:23:04 PM	MTAService.OnSessionChange	0	None	1:23:04 PM - Session change notice received: SessionLock Session ID: 1
Information	3/25/2019 1:01:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 12:56:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31978)(?)])(1 )(2 )]

"
Information	3/25/2019 12:56:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/25/2019 12:56:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31978)(?)])(1 )(2 )]

"
Information	3/25/2019 12:56:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31978)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 12:55:59 PM	McLogEvent	257	None	The Scan was unable to scan password protected file C:\Users\212558710\Downloads\JobManagement Detailed design.docx.crdownload\word/document.xml. Scan engine version used is 6000.8403 DAT version 9204.0000.
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31979)(?)])(1 )(2 )]

"
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31979)(?)])(1 )(2 )]

"
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31979)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/25/2019 12:55:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 12:55:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/25/2019 12:24:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/25/2019 12:23:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/25/2019 12:14:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9204.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/25/2019 12:03:28 PM	MTAService.OnSessionChange	0	None	12:03:28 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/25/2019 11:55:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb73a1df-4ec6-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/25/2019 11:53:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 11:52:52 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 12156) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 11:52:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T06:22:51.578329100Z.
Information	3/25/2019 11:52:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T06:22:49.724143700Z.
Information	3/25/2019 11:39:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/25/2019 11:38:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/25/2019 11:34:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 11:32:55 AM	MTAService.OnSessionChange	0	None	11:32:55 AM - Session change notice received: SessionLock Session ID: 1
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32065)(?)])(1 )(2 )]

"
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32065)(?)])(1 )(2 )]

"
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/25/2019 11:29:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 11:29:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/25/2019 11:18:56 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (16) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190321_235249.log
"
Error	3/25/2019 11:18:56 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190321_235249.log
"
Information	3/25/2019 11:13:21 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.12543. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	3/25/2019 11:13:21 AM	MsiInstaller	11708	None	Product: 4Sight2 -- Installation operation failed.
Information	3/25/2019 10:54:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 10:54:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-04-01T05:18:57Z. Reason: GVLK.
Information	3/25/2019 10:49:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 10:49:57 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	3/25/2019 10:49:57 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020018, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/03/25 05:19, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/25/2019 10:47:47 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎25T05:17:25.042390900Z.
Information	3/25/2019 10:47:47 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 20632.
Information	3/25/2019 10:47:47 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight2. Product Version: 1.4.0.12511. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/25/2019 10:47:47 AM	MsiInstaller	11724	None	Product: 4Sight2 -- Removal completed successfully.
Information	3/25/2019 10:47:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T05:17:25.042390900Z.
Information	3/25/2019 10:46:09 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 20632.
Information	3/25/2019 10:44:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2019 10:44:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 10:44:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 10:44:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\SearchProtocolHost.exe' (pid 5808) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 10:35:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T05:05:23.276117900Z.
Information	3/25/2019 10:35:21 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T05:05:21.479477300Z.
Warning	3/25/2019 10:18:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2019 10:17:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Error	3/25/2019 10:17:01 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:17:01 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/25/2019 10:14:43 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/25/2019 10:14:43 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	3/25/2019 10:05:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:05:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:05:05 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:05:05 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:03:30 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:03:30 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:03:03 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 10:03:03 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/25/2019 9:54:37 AM	MTAService.OnSessionChange	0	None	9:54:37 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/25/2019 9:53:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/25/2019 9:48:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/25/2019 9:48:54 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎25T04:18:54.974850600Z.
Information	3/25/2019 9:48:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎25T04:18:53.127744900Z.
Information	3/25/2019 9:48:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/25/2019 9:48:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 9:48:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/25/2019 9:32:56 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:32:56 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:32:29 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:32:29 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/25/2019 9:25:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	3/25/2019 9:25:08 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:25:08 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:24:41 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:24:41 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:23:36 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:23:36 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:23:08 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:23:08 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:21:50 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:21:50 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:21:24 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:21:24 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:20:21 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:20:21 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:19:54 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 9:19:54 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/25/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 9:07:47 AM	MTAService.OnSessionChange	0	None	9:07:47 AM - Session change notice received: SessionLock Session ID: 1
Error	3/25/2019 9:06:51 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32207)(?)])(1 )(2 )]

"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32208)(?)])(1 )(2 )]

"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32208)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/25/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 9:06:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/25/2019 8:57:15 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 19256 did not respond and is being forcibly terminated {filter host process 20192}. 

Information	3/25/2019 8:53:07 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/25/2019 8:53:07 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	3/25/2019 8:50:09 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 8:50:09 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 8:49:49 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 8:49:49 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 8:49:46 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/25/2019 8:49:46 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/25/2019 8:43:14 AM	MTAService.OnSessionChange	0	None	8:43:14 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/25/2019 5:25:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/25/2019 3:43:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2019 3:43:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:54Z. Reason: GVLK.
Information	3/25/2019 3:36:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2019 3:36:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2019 3:36:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2019 3:36:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2019 1:25:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/25/2019 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Error	3/24/2019 10:32:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/24/2019 10:32:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/24/2019 10:32:12 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/24/2019 10:32:12 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/24/2019 9:25:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/24/2019 9:10:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2019 9:10:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:47Z. Reason: GVLK.
Information	3/24/2019 9:05:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2019 9:05:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2019 9:05:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2019 9:05:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2019 5:25:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	3/24/2019 1:50:27 PM	Application Error	1000	(100)	"Faulting application name: AdobeARM.exe, version: 1.824.31.1644, time stamp: 0x5c1716d5
Faulting module name: WININET.dll, version: 11.0.9600.19267, time stamp: 0x5c4b977a
Exception code: 0xc0000005
Fault offset: 0x000d06af
Faulting process id: 0x4fc0
Faulting application start time: 0x01d4e213effec0a8
Faulting application path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Faulting module path: C:\Windows\syswow64\WININET.dll
Report Id: adc1a01e-4e0d-11e9-9ecd-204747d02364"
Information	3/24/2019 1:25:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/24/2019 12:23:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/24/2019 12:23:54 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2019 12:23:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2019 12:23:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2019 12:23:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2019 12:23:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/24/2019 12:23:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎24T06:53:53.750912800Z.
Information	3/24/2019 12:23:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎24T06:53:52.246826800Z.
Information	3/24/2019 11:31:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/24/2019 11:31:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/24/2019 11:31:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/24/2019 11:31:23 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/24/2019 11:31:23 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/24/2019 11:30:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 31759, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/24/2019 11:30:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/24/2019 11:30:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/24/2019 11:30:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/24/2019 9:25:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/24/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/24/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/24/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33647)(?)])(1 )(2 )]

"
Information	3/24/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/24/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33648)(?)])(1 )(2 )]

"
Information	3/24/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33648)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/24/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/24/2019 5:25:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/24/2019 4:36:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2019 4:36:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:58Z. Reason: GVLK.
Information	3/24/2019 4:29:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2019 4:29:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2019 4:29:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2019 4:29:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2019 1:24:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/24/2019 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/23/2019 9:24:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 7:19:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2019 7:19:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:01Z. Reason: GVLK.
Information	3/23/2019 7:14:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2019 7:14:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2019 7:14:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2019 7:13:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2019 5:24:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2019 3:25:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎23T09:55:13.123380000Z.
Information	3/23/2019 3:25:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎23T09:55:11.580291700Z.
Information	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2019 2:14:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎23T08:44:49.496802400Z.
Information	3/23/2019 2:14:48 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎23T08:44:48.074721000Z.
Information	3/23/2019 2:13:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/23/2019 2:08:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/23/2019 2:08:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2019 2:08:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/23/2019 1:24:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 9:24:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/23/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/23/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35087)(?)])(1 )(2 )]

"
Information	3/23/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/23/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35087)(?)])(1 )(2 )]

"
Information	3/23/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35088)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/23/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/23/2019 5:24:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 4:22:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2019 4:22:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:05Z. Reason: GVLK.
Information	3/23/2019 4:12:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2019 4:12:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2019 4:12:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2019 4:12:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2019 1:24:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/23/2019 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/22/2019 9:24:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2019 7:43:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎22T14:13:01.075723300Z.
Information	3/22/2019 7:42:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎22T14:12:59.603576100Z.
Error	3/22/2019 7:28:38 PM	Group Policy Registry	8194	(2)	The client-side extension could not apply computer policy settings for 'GE000000000_Network_Security_Protocols {BA9949F3-E905-406E-B5FE-CB5A053B510B}' because it failed with error code '0x80070040 The specified network name is no longer available.' See trace file for more details.
Error	3/22/2019 7:28:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/22/2019 7:28:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	3/22/2019 7:28:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 6:55:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e6f414db-4ca5-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/22/2019 5:30:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 5:29:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2019 5:29:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:08Z. Reason: GVLK.
Information	3/22/2019 5:24:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2019 5:24:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2019 5:24:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2019 5:24:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 5:24:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/22/2019 3:45:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2019 1:55:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎22T08:25:19.108735200Z.
Information	3/22/2019 1:55:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎22T08:25:16.391463500Z.
Information	3/22/2019 1:55:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fd39ef9c-4c7b-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/22/2019 1:53:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 1:24:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2019 1:01:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9202.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Warning	3/22/2019 12:13:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 11:13:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2019 11:13:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:35Z. Reason: GVLK.
Information	3/22/2019 11:08:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2019 11:08:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2019 11:08:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 11:08:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/22/2019 11:04:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/22/2019 10:30:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 9:24:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2019 9:24:01 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/22/2019 9:23:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2019 9:11:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/22/2019 9:06:51 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36527)(?)])(1 )(2 )]

"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36528)(?)])(1 )(2 )]

"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36528)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 9:06:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/22/2019 8:55:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 8:55:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1381720e-4c52-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/22/2019 8:17:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/22/2019 8:12:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2019 8:12:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎22T02:42:55.605047800Z.
Information	3/22/2019 8:12:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎22T02:42:53.940047800Z.
Information	3/22/2019 8:12:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2019 8:12:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 8:12:42 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/22/2019 7:04:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 5:23:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/22/2019 5:18:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 4:32:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2019 4:32:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:44Z. Reason: GVLK.
Information	3/22/2019 4:27:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2019 4:27:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2019 4:27:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 4:27:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/22/2019 4:26:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2019 4:26:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:44Z. Reason: GVLK.
Information	3/22/2019 4:21:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2019 4:21:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2019 4:21:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2019 4:21:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/22/2019 3:55:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2a70aafe-4c28-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/22/2019 3:37:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/22/2019 3:37:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/22/2019 3:28:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/22/2019 1:40:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2019 1:23:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/21/2019 11:53:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 11:53:07 PM	GE Software	0	(1)	++Installation complete
Information	3/21/2019 11:53:07 PM	GE Software	0	(1)	++Installation complete with an exit code of: 51638
Warning	3/21/2019 11:53:06 PM	GE Software	0	(1)	++Application Already Installed, exiting Installation Code 51638
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Warning	3/21/2019 11:53:06 PM	GE Software	0	(1)	++Installation Check - TAG file exists
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++ GE_InstallMFPSecureTrayApp_1005_V01 was launched using the following Command line: /Q
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/21/2019 11:53:06 PM	GE Software	0	(1)	++ The installation of ge_installmfpsecuretrayapp_1005_v01.exe was launched with the following Command Line Switches: /Q
Information	3/21/2019 11:53:00 PM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	3/21/2019 11:52:56 PM	GE Software	0	(1)	++No Reboot requested by LRS_VPSX_Printer_1.07_V03
Information	3/21/2019 11:52:53 PM	GE Software	0	(1)	Package Tracker MIF file created.
Information	3/21/2019 11:52:53 PM	GE Software	0	(1)	Updating Pactrack registry keys with lrs_vpsx_printer_1.07_v03
Information	3/21/2019 11:52:53 PM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	3/21/2019 11:52:53 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	3/21/2019 11:52:52 PM	GE Software	0	(1)	++Installing GEPRINT printer with exitcode 0
Information	3/21/2019 11:52:52 PM	GE Software	0	(1)	++Executing command C:\Program Files\LRS\VPSX Printer Driver Management\ndrvu.exe  connect http://vpsx.cloud.ge.com:631/GEPRINT -s
Information	3/21/2019 11:52:49 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T18:22:35.495174200Z.
Information	3/21/2019 11:52:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\{D6B511C1-8F8D-4787-98E2-2090EC3B5602}\drvinst64.msi. Client Process Id: 14136.
Information	3/21/2019 11:52:49 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: VPSX Printer Driver Management. Product Version: 1.075.101. Product Language: 1033. Manufacturer: Levi, Ray & Shoup, Inc. Installation success or error status: 0.
Information	3/21/2019 11:52:49 PM	MsiInstaller	11707	None	Product: VPSX Printer Driver Management -- Installation operation completed successfully.
Information	3/21/2019 11:52:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T18:22:35.495174200Z.
Information	3/21/2019 11:52:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\{D6B511C1-8F8D-4787-98E2-2090EC3B5602}\drvinst64.msi. Client Process Id: 14136.
Information	3/21/2019 11:52:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T18:22:07.318356800Z.
Information	3/21/2019 11:52:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T18:22:06.689293900Z.
Error	3/21/2019 11:52:28 PM	Microsoft-Windows-RestartManager	10007	None	Application or service 'VPSX Printer Driver Management Service' could not be restarted.
Error	3/21/2019 11:52:28 PM	Microsoft-Windows-RestartManager	10007	None	Application or service 'VPSX Pull Print Service' could not be restarted.
Information	3/21/2019 11:52:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {8F7E0DF1-0683-418A-9B0E-8F5D1F0224EB}. Client Process Id: 6520.
Information	3/21/2019 11:52:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: VPSX Printer Driver Management. Product Version: 1.072.300. Product Language: 1033. Manufacturer: Levi, Ray & Shoup, Inc. Removal success or error status: 0.
Information	3/21/2019 11:52:28 PM	MsiInstaller	11724	None	Product: VPSX Printer Driver Management -- Removal completed successfully.
Information	3/21/2019 11:52:13 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'VPSX Printer Driver Management Service'.
Information	3/21/2019 11:52:10 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'VPSX Pull Print Service'.
Error	3/21/2019 11:52:10 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8318E <$MAIN$  > SERVICE CONTROL FUNCTION ControlService FAILED RC(0) The service has not been started.  
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190318_094957.log
"
Information	3/21/2019 11:52:07 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 11:52:07 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\LRS\VPSX Printer Driver Management\ndrvs.exe' (pid 8872) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 11:52:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T18:22:07.318356800Z.
Information	3/21/2019 11:52:07 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 11:52:07 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\LRS\VPSX Printer Driver Management\ndrvs.exe' (pid 8872) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 11:52:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T18:22:06.689293900Z.
Information	3/21/2019 11:52:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {8F7E0DF1-0683-418A-9B0E-8F5D1F0224EB}. Client Process Id: 6520.
Information	3/21/2019 11:52:05 PM	GE Software	0	(1)	Running uninstall for LRS_VPSX_Printer_1.07_V02 - Mode=QUIET
Information	3/21/2019 11:52:01 PM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	3/21/2019 11:52:01 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/21/2019 11:52:01 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/21/2019 11:51:56 PM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\LRS_VPSX_Printer_1.07_V03\lrs_vpsx_printer_1.07_v03.exe with the following commandline: /Q /NOCHECK
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\LRS_VPSX_Printer_1.07_V03
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++ LRS_VPSX_Printer_1.07_V03 was launched using the following Command line: /Q
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/21/2019 11:51:52 PM	GE Software	0	(1)	++ The installation of lrs_vpsx_printer_1.07_v03.exe was launched with the following Command Line Switches: /Q
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++No Install Check was performed.
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++Started the installation of GE Print as a Service 2.0 V01 with the following commandline: /Q
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/21/2019 11:51:43 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/21/2019 10:55:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 40ca9a87-4bfe-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/21/2019 10:25:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 10:19:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 10:19:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:26Z. Reason: GVLK.
Information	3/21/2019 10:14:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 10:14:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 10:14:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 10:14:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2019 9:23:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 9:23:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/21/2019 9:23:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/21/2019 8:37:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/21/2019 7:03:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 5:54:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 571b1bab-4bd4-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/21/2019 5:31:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 5:23:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 4:17:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 4:17:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:05Z. Reason: GVLK.
Information	3/21/2019 4:12:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 4:12:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 4:12:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 4:12:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2019 4:04:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 4:04:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:53Z. Reason: GVLK.
Information	3/21/2019 3:59:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 3:59:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 3:59:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 3:59:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/21/2019 3:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/21/2019 1:32:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 1:23:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 1:23:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/21/2019 1:22:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 12:54:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d86f5f5-4baa-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/21/2019 12:34:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9201.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Warning	3/21/2019 11:41:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 11:32:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/21/2019 11:32:51 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/21/2019 11:32:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/21/2019 11:32:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/21/2019 11:32:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/21/2019 11:31:55 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 8, Compared: 31774, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/21/2019 11:30:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/21/2019 11:30:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/21/2019 11:30:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	3/21/2019 10:07:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 9:23:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 9:23:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/21/2019 9:22:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/21/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/21/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37967)(?)])(1 )(2 )]

"
Information	3/21/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37967)(?)])(1 )(2 )]

"
Information	3/21/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37968)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/21/2019 8:29:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 8:16:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 8:16:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:33Z. Reason: GVLK.
Information	3/21/2019 8:11:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 8:11:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 8:11:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 8:11:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2019 7:54:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 83d61780-4b80-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/21/2019 7:35:05 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T02:05:02.335021700Z.
Information	3/21/2019 7:35:05 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T02:05:01.300918300Z.
Information	3/21/2019 7:35:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57250\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18752.
Information	3/21/2019 7:35:04 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎21T02:05:00.868875100Z.
Information	3/21/2019 7:35:04 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/21/2019 7:35:04 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/21/2019 7:35:04 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T02:05:02.335021700Z.
Information	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 7:35:02 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 7:35:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T02:05:01.300918300Z.
Information	3/21/2019 7:35:00 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T02:05:00.868875100Z.
Information	3/21/2019 7:34:59 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57250\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18752.
Warning	3/21/2019 6:36:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 6:03:17 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎21T00:33:17.240567300Z.
Information	3/21/2019 6:03:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎21T00:33:15.119355200Z.
Information	3/21/2019 5:22:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2019 4:55:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T23:25:13.809265000Z.
Information	3/21/2019 4:55:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T23:25:12.591143200Z.
Information	3/21/2019 4:55:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57146\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11768.
Information	3/21/2019 4:55:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T23:25:11.357019800Z.
Information	3/21/2019 4:55:16 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/21/2019 4:55:16 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/21/2019 4:55:15 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T23:25:13.809265000Z.
Information	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 4:55:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 4:55:12 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T23:25:12.591143200Z.
Information	3/21/2019 4:55:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T23:25:11.357019800Z.
Information	3/21/2019 4:55:10 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57146\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11768.
Warning	3/21/2019 4:50:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 3:42:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 3:42:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:11Z. Reason: GVLK.
Information	3/21/2019 3:37:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 3:37:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 3:37:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 3:37:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2019 3:33:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 3:33:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:40Z. Reason: GVLK.
Information	3/21/2019 3:28:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 3:28:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 3:28:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 3:28:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2019 3:23:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/21/2019 3:09:15 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/21/2019 2:56:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 2:54:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9a26a0e7-4b56-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/21/2019 2:25:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T20:55:06.115585700Z.
Information	3/21/2019 2:25:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T20:55:04.996473800Z.
Information	3/21/2019 2:25:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T20:55:03.428317000Z.
Information	3/21/2019 2:25:09 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57043\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8464.
Information	3/21/2019 2:25:08 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/21/2019 2:25:08 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/21/2019 2:25:07 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T20:55:06.115585700Z.
Information	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/21/2019 2:25:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/21/2019 2:25:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T20:55:04.996473800Z.
Information	3/21/2019 2:25:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T20:55:03.428317000Z.
Information	3/21/2019 2:25:02 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_57043\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8464.
Information	3/21/2019 1:22:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/21/2019 1:00:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2019 12:07:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2019 12:07:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:10Z. Reason: GVLK.
Information	3/21/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/21/2019 12:02:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2019 12:02:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2019 12:02:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2019 12:02:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 11:55:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T18:25:00.006324200Z.
Information	3/20/2019 11:55:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T18:24:58.630909600Z.
Information	3/20/2019 11:55:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56941\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10668.
Information	3/20/2019 11:55:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T18:24:57.541748800Z.
Information	3/20/2019 11:55:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 11:55:02 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 11:55:01 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 11:55:00 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 11:55:00 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 11:55:00 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 11:55:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T18:25:00.006324200Z.
Information	3/20/2019 11:54:59 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 11:54:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 11:54:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 11:54:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T18:24:58.630909600Z.
Information	3/20/2019 11:54:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T18:24:57.541748800Z.
Information	3/20/2019 11:54:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56941\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10668.
Warning	3/20/2019 11:18:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 9:54:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b074ff1d-4b2c-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/20/2019 9:44:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 9:25:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T15:55:23.271269600Z.
Information	3/20/2019 9:25:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T15:55:22.043146800Z.
Information	3/20/2019 9:25:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56833\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16796.
Information	3/20/2019 9:25:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T15:55:20.879030400Z.
Information	3/20/2019 9:25:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 9:25:25 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 9:25:25 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T15:55:23.271269600Z.
Information	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:25:23 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 9:25:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T15:55:22.043146800Z.
Information	3/20/2019 9:25:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T15:55:20.879030400Z.
Information	3/20/2019 9:25:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56833\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16796.
Information	3/20/2019 9:22:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 9:22:23 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/20/2019 9:21:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/20/2019 7:48:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 6:55:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T13:25:26.493681800Z.
Information	3/20/2019 6:55:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T13:25:25.370569500Z.
Information	3/20/2019 6:55:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T13:25:24.000432500Z.
Information	3/20/2019 6:55:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56720\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5824.
Information	3/20/2019 6:55:28 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 6:55:28 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 6:55:28 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T13:25:26.493681800Z.
Information	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 6:55:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 6:55:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T13:25:25.370569500Z.
Information	3/20/2019 6:55:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T13:25:24.000432500Z.
Information	3/20/2019 6:55:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56720\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5824.
Information	3/20/2019 6:39:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 6:39:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:26Z. Reason: GVLK.
Information	3/20/2019 6:34:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2019 6:34:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 6:34:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 6:34:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/20/2019 6:06:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 5:21:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 4:54:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c6bd9910-4b02-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/20/2019 4:27:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T10:57:24.404561700Z.
Information	3/20/2019 4:27:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T10:57:23.254446700Z.
Information	3/20/2019 4:27:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56606\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 20316.
Information	3/20/2019 4:27:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T10:57:21.925313800Z.
Information	3/20/2019 4:27:26 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 4:27:26 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 4:27:26 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T10:57:24.404561700Z.
Information	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:27:24 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 4:27:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T10:57:23.254446700Z.
Information	3/20/2019 4:27:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T10:57:21.925313800Z.
Information	3/20/2019 4:27:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56606\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 20316.
Warning	3/20/2019 4:13:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 4:09:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 4:04:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T10:34:45.224657300Z.
Information	3/20/2019 4:04:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎20T10:34:42.071342000Z.
Information	3/20/2019 4:04:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2019 4:04:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 4:04:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 3:44:23 PM	MTAService.OnSessionChange	0	None	3:44:23 PM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 2:47:43 PM	McLogEvent	257	None	The scan of C:\Users\212558710\Downloads\ZAP_2_6_0_windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9200.0000.
Information	3/20/2019 2:43:29 PM	McLogEvent	257	None	The scan of C:\Users\212558710\Downloads\AtomSetup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9200.0000.
Information	3/20/2019 2:41:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 2:41:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:22Z. Reason: GVLK.
Error	3/20/2019 2:41:09 PM	Outlook	27	None	MAPISendMail: Failed to submit message. Attachments to the message exceeded the size limit set by your Administrator.
Information	3/20/2019 2:38:45 PM	McLogEvent	257	None	The scan of D:\NetFlex_R1_4\CMS-Installation\pre-reqs\postgres\postgresql-9.5.3-1-windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9200.0000.
Information	3/20/2019 2:36:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2019 2:36:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 2:36:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 2:36:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 2:35:39 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9200.0000.
Information	3/20/2019 2:33:53 PM	McLogEvent	257	None	The scan of D:\NetFlex_R1_4\CMS-Installation\pre-reqs\chrome\64bit\55.0.2883.75_chrome_installer.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9200.0000.
Warning	3/20/2019 2:24:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 2:21:08 PM	MTAService.OnSessionChange	0	None	2:21:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 1:57:48 PM	MTAService.OnSessionChange	0	None	1:57:48 PM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 1:55:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T08:25:31.096780000Z.
Information	3/20/2019 1:55:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T08:25:27.535423900Z.
Information	3/20/2019 1:55:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56503\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5820.
Information	3/20/2019 1:55:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T08:25:23.101980600Z.
Information	3/20/2019 1:55:36 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 1:55:36 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 1:55:35 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T08:25:31.096780000Z.
Information	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 1:55:31 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 1:55:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T08:25:27.535423900Z.
Information	3/20/2019 1:55:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T08:25:23.101980600Z.
Information	3/20/2019 1:55:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56503\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5820.
Information	3/20/2019 1:50:44 PM	MTAService.OnSessionChange	0	None	1:50:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 1:24:19 PM	MTAService.OnSessionChange	0	None	1:24:19 PM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 1:24:08 PM	MTAService.OnSessionChange	0	None	1:24:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 1:23:53 PM	MTAService.OnSessionChange	0	None	1:23:53 PM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 1:21:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 12:52:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/20/2019 12:52:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/20/2019 12:42:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 12:39:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/20/2019 12:39:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/20/2019 12:04:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9200.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/20/2019 11:54:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dca9a3f1-4ad8-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/20/2019 11:46:14 AM	MTAService.OnSessionChange	0	None	11:46:14 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 11:31:58 AM	MTAService.OnSessionChange	0	None	11:31:58 AM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 11:25:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T05:55:50.424811500Z.
Information	3/20/2019 11:25:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T05:55:48.528621900Z.
Information	3/20/2019 11:25:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T05:55:46.703439400Z.
Information	3/20/2019 11:25:57 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56392\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5824.
Information	3/20/2019 11:25:57 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 11:25:57 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 11:25:55 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T05:55:50.424811500Z.
Information	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 11:25:50 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 11:25:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T05:55:48.528621900Z.
Information	3/20/2019 11:25:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T05:55:46.703439400Z.
Information	3/20/2019 11:25:45 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56392\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5824.
Information	3/20/2019 11:24:12 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight2. Product Version: 1.4.0.12511. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/20/2019 11:24:12 AM	MsiInstaller	11707	None	Product: 4Sight2 -- Installation operation completed successfully.
Information	3/20/2019 11:23:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T05:46:40.759850500Z.
Information	3/20/2019 11:23:34 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{56D185FB-2EF9-456F-B0A8-0EC4F2A61EF4}\4Sight™ 2.msi. Client Process Id: 11776.
Information	3/20/2019 11:22:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/20/2019 11:21:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/20/2019 11:16:40 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T05:46:40.759850500Z.
Information	3/20/2019 11:16:39 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{56D185FB-2EF9-456F-B0A8-0EC4F2A61EF4}\4Sight™ 2.msi. Client Process Id: 11776.
Warning	3/20/2019 11:05:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 11:03:42 AM	McLogEvent	257	None	The scan of D:\LatestInstall\DISK1\4Sight2.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9199.0000.
Information	3/20/2019 10:09:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/20/2019 10:09:11 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/20/2019 10:03:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/20/2019 10:03:26 AM	MTAService.OnSessionChange	0	None	10:03:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11140) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 9:56:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T04:26:30.416092100Z.
Information	3/20/2019 9:56:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎20T04:26:28.614912000Z.
Warning	3/20/2019 9:31:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 9:26:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 9:24:40 AM	MTAService.OnSessionChange	0	None	9:24:40 AM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 9:23:18 AM	MTAService.OnSessionChange	0	None	9:23:18 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 9:22:34 AM	MTAService.OnSessionChange	0	None	9:22:34 AM - Session change notice received: SessionLock Session ID: 1
Information	3/20/2019 9:21:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 9:21:45 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/20/2019 9:21:45 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 515

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 281

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 203

Information	3/20/2019 9:21:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 9:21:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39393)(?)])(1 )(2 )]

"
Information	3/20/2019 9:21:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2019 9:21:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39393)(?)])(1 )(2 )]

"
Information	3/20/2019 9:21:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39393)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 9:20:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2019 9:20:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 9:20:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/20/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39407)(?)])(1 )(2 )]

"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39407)(?)])(1 )(2 )]

"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39407)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 8:54:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T03:24:53.355423000Z.
Information	3/20/2019 8:54:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T03:24:52.037291200Z.
Information	3/20/2019 8:54:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T03:24:51.406228100Z.
Information	3/20/2019 8:54:56 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56286\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8780.
Information	3/20/2019 8:54:56 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 8:54:56 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 8:54:55 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T03:24:53.355423000Z.
Information	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 8:54:53 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 8:54:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T03:24:52.037291200Z.
Information	3/20/2019 8:54:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T03:24:51.406228100Z.
Information	3/20/2019 8:54:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56286\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8780.
Warning	3/20/2019 7:43:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 7:34:12 AM	MTAService.OnSessionChange	0	None	7:34:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/20/2019 7:27:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2019 6:54:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f2c0fc58-4aae-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/20/2019 6:25:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T00:55:29.618391300Z.
Information	3/20/2019 6:25:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T00:55:28.331906100Z.
Information	3/20/2019 6:25:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56178\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16844.
Information	3/20/2019 6:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎20T00:55:26.995440900Z.
Information	3/20/2019 6:25:32 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 6:25:32 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 6:25:31 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T00:55:29.618391300Z.
Information	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 6:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 6:25:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T00:55:28.331906100Z.
Information	3/20/2019 6:25:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎20T00:55:26.995440900Z.
Information	3/20/2019 6:25:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56178\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16844.
Warning	3/20/2019 6:07:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 5:42:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 5:42:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:25Z. Reason: GVLK.
Information	3/20/2019 5:37:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2019 5:37:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 5:37:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 5:37:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 5:19:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T23:49:25.285637200Z.
Information	3/20/2019 5:19:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T23:49:23.331441800Z.
Information	3/20/2019 4:47:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 4:47:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:19Z. Reason: GVLK.
Information	3/20/2019 4:42:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2019 4:42:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 4:42:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 4:42:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2019 4:41:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2019 4:41:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:29Z. Reason: GVLK.
Information	3/20/2019 4:36:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2019 4:36:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2019 4:36:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2019 4:36:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/20/2019 4:20:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 3:55:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T22:25:08.542013400Z.
Information	3/20/2019 3:55:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T22:25:07.402899500Z.
Information	3/20/2019 3:55:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T22:25:06.255784800Z.
Information	3/20/2019 3:55:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56070\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17096.
Information	3/20/2019 3:55:11 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 3:55:11 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 3:55:10 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T22:25:08.542013400Z.
Information	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 3:55:08 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 3:55:07 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T22:25:07.402899500Z.
Information	3/20/2019 3:55:06 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T22:25:06.255784800Z.
Information	3/20/2019 3:55:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_56070\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17096.
Information	3/20/2019 3:27:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/20/2019 2:46:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/20/2019 2:42:35 AM	VPSX Printer Driver Management	2	None	"VPSX Printer Driver Management Utility error: 
PrintUIEntry() failed; error (87) (0x00000057) The parameter is incorrect.  

 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\\drvutmp\20190320_024213x\drvu.log
"
Warning	3/20/2019 2:42:15 AM	VPSX Printer Driver Management	5	None	"VPSX Printer Driver Management Utility information:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          
Printer (GEPRINT on vpsx) deleted
"
Information	3/20/2019 2:01:14 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/20/2019 1:54:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0903a7a5-4a85-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/20/2019 1:51:39 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/20/2019 1:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T19:55:29.563807600Z.
Information	3/20/2019 1:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T19:55:28.433807600Z.
Information	3/20/2019 1:25:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55961\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 13656.
Information	3/20/2019 1:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T19:55:27.884807600Z.
Information	3/20/2019 1:25:32 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/20/2019 1:25:32 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/20/2019 1:25:31 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T19:55:29.563807600Z.
Information	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/20/2019 1:25:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/20/2019 1:25:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T19:55:28.433807600Z.
Information	3/20/2019 1:25:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T19:55:27.884807600Z.
Information	3/20/2019 1:25:26 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55961\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 13656.
Warning	3/20/2019 12:47:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/19/2019 11:27:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 11:27:35 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/19/2019 11:27:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 10:55:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T17:25:08.399807600Z.
Information	3/19/2019 10:55:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T17:25:07.276807600Z.
Information	3/19/2019 10:55:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55855\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18164.
Information	3/19/2019 10:55:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T17:25:06.722807600Z.
Information	3/19/2019 10:55:10 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 10:55:10 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 10:55:10 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T17:25:08.399807600Z.
Information	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:55:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 10:55:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T17:25:07.276807600Z.
Information	3/19/2019 10:55:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T17:25:06.722807600Z.
Information	3/19/2019 10:55:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55855\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18164.
Warning	3/19/2019 10:51:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/19/2019 9:09:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 8:54:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f03df78-4a5b-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/19/2019 8:25:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T14:55:26.782018000Z.
Information	3/19/2019 8:25:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T14:55:25.371877000Z.
Information	3/19/2019 8:25:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T14:55:23.665706400Z.
Information	3/19/2019 8:25:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55740\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12808.
Information	3/19/2019 8:25:29 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 8:25:29 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 8:25:28 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T14:55:26.782018000Z.
Information	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 8:25:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 8:25:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T14:55:25.371877000Z.
Information	3/19/2019 8:25:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T14:55:23.665706400Z.
Information	3/19/2019 8:25:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55740\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12808.
Warning	3/19/2019 7:38:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 7:27:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 7:18:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T13:48:16.333013400Z.
Information	3/19/2019 7:18:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T13:48:14.485828700Z.
Information	3/19/2019 6:39:21 PM	MTAService.OnSessionChange	0	None	6:39:21 PM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 5:55:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T12:25:01.926622700Z.
Information	3/19/2019 5:55:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T12:25:00.644494500Z.
Information	3/19/2019 5:55:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T12:24:59.850415100Z.
Information	3/19/2019 5:55:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55630\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12728.
Information	3/19/2019 5:55:05 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 5:55:05 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 5:55:04 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T12:25:01.926622700Z.
Information	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:55:01 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 5:55:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T12:25:00.644494500Z.
Information	3/19/2019 5:54:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T12:24:59.850415100Z.
Information	3/19/2019 5:54:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55630\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12728.
Warning	3/19/2019 5:49:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 5:40:45 PM	MTAService.OnSessionChange	0	None	5:40:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 5:39:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T12:09:29.128352200Z.
Information	3/19/2019 5:39:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T12:09:27.339173300Z.
Information	3/19/2019 5:08:33 PM	MTAService.OnSessionChange	0	None	5:08:33 PM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 4:12:27 PM	MTAService.OnSessionChange	0	None	4:12:27 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/19/2019 4:12:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 3:58:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T10:28:28.287300500Z.
Information	3/19/2019 3:58:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T10:28:26.569128700Z.
Information	3/19/2019 3:54:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3543ec99-4a31-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/19/2019 3:39:55 PM	MTAService.OnSessionChange	0	None	3:39:55 PM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 3:31:05 PM	MTAService.OnSessionChange	0	None	3:31:05 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 3:29:45 PM	MTAService.OnSessionChange	0	None	3:29:45 PM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 3:29:29 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 3:29:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T09:59:28.591021300Z.
Information	3/19/2019 3:29:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T09:59:26.899645300Z.
Information	3/19/2019 3:27:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 3:25:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T09:55:20.685227300Z.
Information	3/19/2019 3:25:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T09:55:19.575227300Z.
Information	3/19/2019 3:25:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55520\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15704.
Information	3/19/2019 3:25:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T09:55:18.458227300Z.
Information	3/19/2019 3:25:23 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 3:25:23 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 3:25:22 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T09:55:20.685227300Z.
Information	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:25:20 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 3:25:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T09:55:19.575227300Z.
Information	3/19/2019 3:25:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T09:55:18.458227300Z.
Information	3/19/2019 3:25:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55520\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15704.
Information	3/19/2019 3:07:56 PM	MTAService.OnSessionChange	0	None	3:07:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 3:03:30 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 3:03:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T09:33:29.607227300Z.
Information	3/19/2019 3:03:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T09:33:27.879227300Z.
Information	3/19/2019 2:51:45 PM	MTAService.OnSessionChange	0	None	2:51:45 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/19/2019 2:39:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 2:09:24 PM	MTAService.OnSessionChange	0	None	2:09:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 1:52:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/19/2019 1:52:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:22Z. Reason: GVLK.
Information	3/19/2019 1:47:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/19/2019 1:47:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 1:47:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 1:47:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/19/2019 1:41:04 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 10308) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 1:41:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T08:11:03.564227300Z.
Information	3/19/2019 1:41:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T08:11:00.876227300Z.
Information	3/19/2019 1:21:04 PM	MTAService.OnSessionChange	0	None	1:21:04 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/19/2019 12:57:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 12:57:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2019 12:56:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T07:26:08.942227300Z.
Information	3/19/2019 12:56:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T07:26:07.718227300Z.
Information	3/19/2019 12:56:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T07:26:06.338227300Z.
Information	3/19/2019 12:56:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55408\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15968.
Information	3/19/2019 12:56:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 12:56:11 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 12:56:10 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T07:26:08.942227300Z.
Information	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 12:56:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 12:56:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T07:26:07.718227300Z.
Information	3/19/2019 12:56:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T07:26:06.338227300Z.
Information	3/19/2019 12:56:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55408\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15968.
Information	3/19/2019 12:52:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40622)(?)])(1 )(2 )]

"
Information	3/19/2019 12:52:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2019 12:52:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40622)(?)])(1 )(2 )]

"
Information	3/19/2019 12:52:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40622)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 12:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40624)(?)])(1 )(2 )]

"
Information	3/19/2019 12:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2019 12:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40624)(?)])(1 )(2 )]

"
Information	3/19/2019 12:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40624)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 12:50:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2019 12:50:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 12:50:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2019 12:43:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/19/2019 12:42:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/19/2019 12:34:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/19/2019 12:34:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/19/2019 12:21:43 PM	MTAService.OnSessionChange	0	None	12:21:43 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 12:10:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9199.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 9720) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 11:52:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 11:52:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T06:22:47.858227300Z.
Information	3/19/2019 11:52:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T06:22:46.262227300Z.
Information	3/19/2019 11:33:25 AM	MTAService.OnSessionChange	0	None	11:33:25 AM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 11:27:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 11:27:20 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/19/2019 11:26:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/19/2019 10:59:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 10:59:02 AM	MTAService.OnSessionChange	0	None	10:59:02 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 10:54:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b756279-4a07-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 9720) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe' (pid 10692) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13280) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10364) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 10644) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 2920) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 10:41:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T05:11:48.009821600Z.
Information	3/19/2019 10:41:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎03‎-‎19T05:11:45.958616500Z.
Information	3/19/2019 10:39:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2019 10:34:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2019 10:34:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 10:34:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T04:55:24.703500800Z.
Information	3/19/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T04:55:23.585389000Z.
Information	3/19/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T04:55:23.036334100Z.
Information	3/19/2019 10:25:27 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55297\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 9528.
Information	3/19/2019 10:25:27 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 10:25:27 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Information	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T04:55:24.703500800Z.
Information	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Error	3/19/2019 10:25:26 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 10:25:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T04:55:23.585389000Z.
Information	3/19/2019 10:25:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T04:55:23.036334100Z.
Information	3/19/2019 10:25:21 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55297\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 9528.
Information	3/19/2019 10:14:49 AM	MTAService.OnSessionChange	0	None	10:14:49 AM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 10:00:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/19/2019 10:00:03 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/19/2019 9:53:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/19/2019 9:49:33 AM	MTAService.OnSessionChange	0	None	9:49:33 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 9:33:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/19/2019 9:33:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:09Z. Reason: GVLK.
Information	3/19/2019 9:28:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/19/2019 9:28:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 9:28:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 9:28:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/19/2019 9:15:45 AM	MTAService.OnSessionChange	0	None	9:15:45 AM - Session change notice received: SessionLock Session ID: 1
Information	3/19/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/19/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/19/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40847)(?)])(1 )(2 )]

"
Information	3/19/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40847)(?)])(1 )(2 )]

"
Information	3/19/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40847)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/19/2019 9:01:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 8:57:05 AM	MTAService.OnSessionChange	0	None	8:57:05 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/19/2019 7:58:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T02:28:25.557669000Z.
Information	3/19/2019 7:58:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T02:28:24.487669000Z.
Information	3/19/2019 7:58:28 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55190\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11760.
Information	3/19/2019 7:58:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎19T02:28:23.942669000Z.
Information	3/19/2019 7:58:28 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 7:58:28 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 7:58:27 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T02:28:25.557669000Z.
Information	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 7:58:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 7:58:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T02:28:24.487669000Z.
Information	3/19/2019 7:58:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎19T02:28:23.942669000Z.
Information	3/19/2019 7:58:22 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55190\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11760.
Information	3/19/2019 7:26:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/19/2019 7:04:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 5:54:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61a97e2d-49dd-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/19/2019 5:25:14 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T23:55:11.401060200Z.
Information	3/19/2019 5:25:14 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T23:55:10.372957400Z.
Information	3/19/2019 5:25:13 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T23:55:09.836903800Z.
Information	3/19/2019 5:25:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55082\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 3520.
Information	3/19/2019 5:25:13 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 5:25:13 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 5:25:13 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T23:55:11.401060200Z.
Information	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 5:25:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 5:25:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T23:55:10.372957400Z.
Information	3/19/2019 5:25:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T23:55:09.836903800Z.
Information	3/19/2019 5:25:08 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_55082\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 3520.
Warning	3/19/2019 5:11:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 5:05:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/19/2019 5:05:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:30Z. Reason: GVLK.
Information	3/19/2019 4:54:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/19/2019 4:54:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2019 4:54:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2019 4:54:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/19/2019 3:31:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 3:26:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2019 2:56:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T21:26:06.802624000Z.
Information	3/19/2019 2:56:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T21:26:05.181461900Z.
Information	3/19/2019 2:56:10 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_54976\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16860.
Information	3/19/2019 2:56:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T21:26:04.107354500Z.
Information	3/19/2019 2:56:09 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.152.49227. Product Language: 1033. Manufacturer: Google LLC. Installation success or error status: 1603.
Information	3/19/2019 2:56:09 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/19/2019 2:56:08 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T21:26:06.802624000Z.
Information	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11544) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/19/2019 2:56:06 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11628) cannot be restarted - Application SID does not match Conductor SID..
Information	3/19/2019 2:56:05 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T21:26:05.181461900Z.
Information	3/19/2019 2:56:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T21:26:04.107354500Z.
Information	3/19/2019 2:56:02 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_54976\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 16860.
Warning	3/19/2019 2:00:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 12:54:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 77d51caa-49b3-11e9-9ecd-204747d02364
Report Status: 0"
Warning	3/19/2019 12:25:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/18/2019 11:26:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/18/2019 11:26:25 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/18/2019 11:26:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/18/2019 10:28:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/18/2019 8:34:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 7:54:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e1cbde4-4989-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/18/2019 7:51:17 PM	MTAService.OnSessionChange	0	None	7:51:17 PM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 7:49:27 PM	MTAService.OnSessionChange	0	None	7:49:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 7:49:06 PM	MTAService.OnSessionChange	0	None	7:49:06 PM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 7:26:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/18/2019 7:17:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎18T13:47:07.877786800Z.
Information	3/18/2019 7:17:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10332.
Information	3/18/2019 7:17:39 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.4.0.5899. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/18/2019 7:17:39 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	3/18/2019 7:17:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎18T13:47:07.877786800Z.
Information	3/18/2019 7:17:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10332.
Warning	3/18/2019 6:54:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 5:47:54 PM	MTAService.OnSessionChange	0	None	5:47:54 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/18/2019 5:20:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 5:09:07 PM	MTAService.OnSessionChange	0	None	5:09:07 PM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 4:28:35 PM	MTAService.OnSessionChange	0	None	4:28:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 4:02:14 PM	MTAService.OnSessionChange	0	None	4:02:14 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/18/2019 3:36:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 3:25:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/18/2019 3:20:17 PM	MTAService.OnSessionChange	0	None	3:20:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 2:54:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a45b99e2-495f-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/18/2019 2:43:32 PM	MTAService.OnSessionChange	0	None	2:43:32 PM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 2:18:18 PM	MTAService.OnSessionChange	0	None	2:18:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 1:59:12 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/18/2019 1:43:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 1:26:39 PM	MTAService.OnSessionChange	0	None	1:26:39 PM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 1:24:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/18/2019 1:24:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/18/2019 11:52:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 11:52:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:15:19Z. Reason: GVLK.
Information	3/18/2019 11:51:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/18/2019 11:51:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/18/2019 11:49:19 AM	MTAService.OnSessionChange	0	None	11:49:19 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 11:47:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2019 11:47:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 11:47:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 11:47:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/18/2019 11:46:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 11:44:36 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/18/2019 11:44:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/18/2019 11:44:17 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/18/2019 11:43:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 31673, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/18/2019 11:41:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/18/2019 11:41:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/18/2019 11:32:22 AM	MTAService.OnSessionChange	0	None	11:32:22 AM - Session change notice received: SessionLock Session ID: 1
Information	3/18/2019 11:31:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 11:26:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/18/2019 11:26:12 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/18/2019 11:26:05 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/18/2019 11:26:02 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 718

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 764

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 265

Information	3/18/2019 11:26:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/18/2019 11:26:01 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/18/2019 11:25:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/18/2019 11:25:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42149)(?)])(1 )(2 )]

"
Information	3/18/2019 11:25:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/18/2019 11:25:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42149)(?)])(1 )(2 )]

"
Information	3/18/2019 11:25:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42149)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 11:24:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/18/2019 11:24:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 11:24:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 11:15:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9198.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/18/2019 10:50:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 10:50:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-25T05:14:44Z. Reason: GVLK.
Information	3/18/2019 10:45:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 10:45:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 10:45:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/03/18 05:15"
Information	3/18/2019 10:45:42 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/03/18 05:15, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/18/2019 10:40:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2019 10:40:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 10:40:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 10:40:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 10:14:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 10:14:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 10:14:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:06Z. Reason: GVLK.
Information	3/18/2019 10:13:42 AM	MTAService.OnSessionChange	0	None	10:13:42 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/18/2019 10:10:53 AM	MTAService.OnSessionChange	0	None	10:10:53 AM - Session change notice received: SessionLock Session ID: 1
Error	3/18/2019 10:09:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/18/2019 10:09:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42225)(?)])(1 )(2 )]

"
Information	3/18/2019 10:09:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/18/2019 10:09:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42225)(?)])(1 )(2 )]

"
Information	3/18/2019 10:09:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42225)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 10:09:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/18/2019 10:09:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 10:09:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 10:09:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2019 10:09:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 10:09:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 10:09:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 10:06:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2019 10:06:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:47Z. Reason: GVLK.
Information	3/18/2019 10:02:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/18/2019 9:55:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/18/2019 9:55:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42239)(?)])(1 )(2 )]

"
Information	3/18/2019 9:55:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/18/2019 9:55:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42239)(?)])(1 )(2 )]

"
Information	3/18/2019 9:54:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42239)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 9:54:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/18/2019 9:54:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2019 9:54:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 9:54:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b9e7f111-4935-11e9-9ecd-204747d02364
Report Status: 0"
Information	3/18/2019 9:54:27 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	3/18/2019 9:54:14 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2019 9:54:13 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/18/2019 9:54:12 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2019 9:54:10 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2019 9:53:45 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	3/18/2019 9:53:45 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	3/18/2019 9:53:37 AM	ESENT	302	Logging/Recovery	Windows (10224) Windows: The database engine has successfully completed recovery steps.
Information	3/18/2019 9:53:24 AM	ESENT	301	Logging/Recovery	Windows (10224) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/18/2019 9:53:24 AM	ESENT	300	Logging/Recovery	Windows (10224) Windows: The database engine is initiating recovery steps.
Information	3/18/2019 9:53:23 AM	ESENT	102	General	Windows (10224) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/18/2019 9:52:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2019 9:52:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2019 9:52:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	3/18/2019 9:52:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/18/2019 9:52:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2019 9:51:59 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9196.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/18/2019 9:51:41 AM	MTAService.OnSessionChange	0	None	9:51:41 AM - Logon : 212558710
Information	3/18/2019 9:51:36 AM	MTAService.OnSessionChange	0	None	9:51:36 AM - Session change notice received: SessionLogon Session ID: 1
Information	3/18/2019 9:51:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/18/2019 9:51:36 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/18/2019 9:51:36 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/18/2019 9:51:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/18/2019 9:51:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/18/2019 9:51:20 AM	Service1	0	None	Service started successfully.
Error	3/18/2019 9:51:15 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/18/2019 9:51:13 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/18/2019 9:51:01 AM	PostgreSQL	0	None	Server started and accepting connections

Information	3/18/2019 9:50:58 AM	PostgreSQL	0	None	"2019-03-18 09:50:58 IST LOG:  redirecting log output to logging collector process
2019-03-18 09:50:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/18/2019 9:50:54 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/18/2019 9:50:52 AM	PostgreSQL	0	None	Waiting for server startup...

Information	3/18/2019 9:50:49 AM	MTAService	0	None	Service started successfully.
Information	3/18/2019 9:50:49 AM	MTAService.OnStart	0	None	9:50:49 AM - Waiting for user to Logon
Information	3/18/2019 9:50:42 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/18/2019 9:50:42 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/18/2019 9:50:40 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:40 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/18/2019 9:50:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/18/2019 9:50:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/18/2019 9:50:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/18/2019 9:50:39 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/18/2019 9:50:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:39 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/18/2019 9:50:38 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/18/2019 9:50:37 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4828 at 3/16/2019 3:42:14 PM (local) 3/16/2019 10:12:14 AM (UTC). This is an informational message only; no user action is required.
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/18/2019 9:50:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/18/2019 9:50:33 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/18/2019 9:50:33 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/18/2019 9:50:33 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/18/2019 9:50:33 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4644.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/18/2019 9:50:22 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	3/18/2019 9:48:46 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	3/18/2019 9:48:44 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2019 9:48:19 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/18/2019 9:48:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/18/2019 9:48:19 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/16/2019 3:42:24 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	3/16/2019 3:42:24 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	3/16/2019 3:42:14 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	3/16/2019 3:42:02 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 192 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 528 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 528 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2568 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 528 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 528 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 528 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2452 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/16/2019 3:42:02 PM	MTAService.OnSessionChange	0	None	3:42:02 PM - Logoff
Information	3/16/2019 3:42:02 PM	MTAService.OnSessionChange	0	None	3:42:02 PM - Session change notice received: SessionLogoff Session ID: 1
Information	3/16/2019 3:42:00 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/16/2019 3:42:00 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/16/2019 3:42:00 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Installation complete
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Installation complete with an exit code of: 
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Started the installation of GE Reboot 1.0 V02 with the following commandline: /IC /Q
Information	3/16/2019 3:40:30 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/16/2019 3:40:23 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/16/2019 3:22:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2019 3:09:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7579d216-47cf-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/16/2019 2:31:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 12:51:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2019 12:51:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:12Z. Reason: GVLK.
Warning	3/16/2019 12:46:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 12:46:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2019 12:46:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2019 12:46:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2019 12:46:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2019 12:05:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9196.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/16/2019 11:22:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2019 11:22:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/16/2019 11:22:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/16/2019 11:12:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 10:09:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8bb46854-47a5-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/16/2019 9:28:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/16/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45167)(?)])(1 )(2 )]

"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45167)(?)])(1 )(2 )]

"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45167)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/16/2019 7:54:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 7:21:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/16/2019 5:58:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 5:09:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a1f05bad-477b-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/16/2019 4:50:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2019 4:50:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:32Z. Reason: GVLK.
Information	3/16/2019 4:45:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2019 4:45:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2019 4:45:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2019 4:45:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2019 4:42:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2019 4:42:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:40Z. Reason: GVLK.
Information	3/16/2019 4:37:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2019 4:37:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2019 4:37:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2019 4:37:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/16/2019 4:10:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 3:21:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/16/2019 2:36:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 12:44:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2019 12:44:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:52Z. Reason: GVLK.
Warning	3/16/2019 12:40:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2019 12:39:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2019 12:39:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2019 12:39:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2019 12:39:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2019 12:09:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b83b91bd-4751-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/16/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/15/2019 11:21:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2019 11:21:32 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/15/2019 11:21:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/15/2019 10:52:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 10:12:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 10:12:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:20Z. Reason: GVLK.
Information	3/15/2019 10:07:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 10:07:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 10:07:19 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	3/15/2019 10:07:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 10:07:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/15/2019 10:06:49 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/15/2019 10:05:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 10:05:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:44Z. Reason: GVLK.
Information	3/15/2019 10:00:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 10:00:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 10:00:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 10:00:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/15/2019 9:04:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 8:54:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 8:51:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/15/2019 7:44:22 PM	VPSX Printer Driver Management	5	None	"VPSX Printer Driver Management Utility information:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          
Printer (GEPRINT on vpsx01) deleted
"
Warning	3/15/2019 7:31:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 7:21:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2019 7:09:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ce819e2b-4727-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/15/2019 5:38:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/15/2019 3:58:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 3:33:26 PM	MTAService.OnSessionChange	0	None	3:33:26 PM - Session change notice received: SessionLock Session ID: 1
Information	3/15/2019 3:20:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2019 2:52:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 2:51:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 2:33:14 PM	MTAService.OnSessionChange	0	None	2:33:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/15/2019 2:33:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 2:28:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/15/2019 2:28:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 2:28:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/15/2019 2:09:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e4286150-46fd-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/15/2019 2:06:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 1:56:50 PM	MTAService.OnSessionChange	0	None	1:56:50 PM - Session change notice received: SessionLock Session ID: 1
Information	3/15/2019 1:53:19 PM	MTAService.OnSessionChange	0	None	1:53:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/15/2019 1:51:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 1:51:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 1:34:30 PM	MTAService.OnSessionChange	0	None	1:34:30 PM - Session change notice received: SessionLock Session ID: 1
Information	3/15/2019 1:29:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 1:29:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 1:09:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 1:09:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 12:44:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9195.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Warning	3/15/2019 12:27:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 12:22:49 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/15/2019 12:04:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 12:03:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 11:54:27 AM	MTAService.OnSessionChange	0	None	11:54:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/15/2019 11:39:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/15/2019 11:39:59 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/15/2019 11:32:11 AM	MTAService.OnSessionChange	0	None	11:32:11 AM - Session change notice received: SessionLock Session ID: 1
Information	3/15/2019 11:26:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 11:25:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 11:25:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/15/2019 11:25:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/15/2019 11:21:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2019 11:21:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/15/2019 11:21:20 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 406

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 296

Information	3/15/2019 11:20:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2019 11:20:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46474)(?)])(1 )(2 )]

"
Information	3/15/2019 11:20:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/15/2019 11:20:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46474)(?)])(1 )(2 )]

"
Information	3/15/2019 11:20:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46474)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 11:20:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/15/2019 11:20:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 11:20:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/15/2019 10:52:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 10:48:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 10:48:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:02Z. Reason: GVLK.
Information	3/15/2019 10:43:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 10:43:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 10:43:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 10:43:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/15/2019 9:52:08 AM	MTAService.OnSessionChange	0	None	9:52:08 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/15/2019 9:26:21 AM	MTAService.OnSessionChange	0	None	9:26:21 AM - Session change notice received: SessionLock Session ID: 1
Information	3/15/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 9:09:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fa6a67e2-46d3-11e9-a5a4-204747d02364
Report Status: 0"
Error	3/15/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/15/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46607)(?)])(1 )(2 )]

"
Information	3/15/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/15/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46607)(?)])(1 )(2 )]

"
Information	3/15/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46607)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/15/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/15/2019 9:01:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 9:00:34 AM	MTAService.OnSessionChange	0	None	9:00:34 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/15/2019 7:22:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/15/2019 5:39:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 4:09:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 10abe92f-46aa-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/15/2019 4:04:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 3:19:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 3:19:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:01Z. Reason: GVLK.
Information	3/15/2019 3:14:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 3:14:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 3:14:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 3:14:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/15/2019 3:12:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 3:12:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:24Z. Reason: GVLK.
Information	3/15/2019 3:07:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 3:07:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 3:07:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 3:07:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/15/2019 2:24:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 1:15:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 1:15:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:31Z. Reason: GVLK.
Information	3/15/2019 1:10:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2019 1:10:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2019 1:10:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2019 1:10:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/15/2019 12:45:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2019 12:04:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2019 12:04:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:00Z. Reason: GVLK.
Information	3/15/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/14/2019 11:58:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2019 11:58:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2019 11:58:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2019 11:58:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/14/2019 11:12:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 11:09:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 26c84e24-4680-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/14/2019 9:25:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 8:06:07 PM	MTAService.OnSessionChange	0	None	8:06:07 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 8:04:14 PM	MTAService.OnSessionChange	0	None	8:04:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 8:03:36 PM	MTAService.OnSessionChange	0	None	8:03:36 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/14/2019 7:30:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 6:25:08 PM	MTAService.OnSessionChange	0	None	6:25:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 6:09:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d2474bf-4656-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/14/2019 5:49:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 5:29:31 PM	MTAService.OnSessionChange	0	None	5:29:31 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 5:18:22 PM	MTAService.OnSessionChange	0	None	5:18:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 5:10:59 PM	MTAService.OnSessionChange	0	None	5:10:59 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 4:27:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2019 3:55:21 PM	MTAService.OnSessionChange	0	None	3:55:21 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/14/2019 3:54:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 3:17:27 PM	MTAService.OnSessionChange	0	None	3:17:27 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 2:23:57 PM	MTAService.OnSessionChange	0	None	2:23:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 2:09:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 2:09:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/14/2019 1:55:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 1:50:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2019 1:45:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2019 1:45:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2019 1:45:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/14/2019 1:25:21 PM	MTAService.OnSessionChange	0	None	1:25:21 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 1:09:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5360ebe4-462c-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/14/2019 1:05:36 PM	MTAService.OnSessionChange	0	None	1:05:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 1:02:49 PM	MTAService.OnSessionChange	0	None	1:02:49 PM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 12:45:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/14/2019 12:45:22 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/14/2019 12:41:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9194.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/14/2019 12:27:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2019 12:24:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 12:24:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 12:22:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 12:21:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 12:19:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/14/2019 12:07:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 12:01:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 12:01:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 11:57:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 11:57:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 11:57:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 11:57:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 11:56:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 11:55:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 11:51:19 AM	MTAService.OnSessionChange	0	None	11:51:19 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 11:45:00 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/14/2019 11:44:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 31615, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/14/2019 11:43:42 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/14/2019 11:43:42 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/14/2019 11:36:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/14/2019 11:36:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/14/2019 11:33:38 AM	MTAService.OnSessionChange	0	None	11:33:38 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/14/2019 10:28:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 9:36:35 AM	MTAService.OnSessionChange	0	None	9:36:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/14/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2019 9:11:18 AM	MTAService.OnSessionChange	0	None	9:11:18 AM - Session change notice received: SessionLock Session ID: 1
Information	3/14/2019 9:07:45 AM	MTAService.OnSessionChange	0	None	9:07:45 AM - Session change notice received: SessionUnlock Session ID: 1
Error	3/14/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/14/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48047)(?)])(1 )(2 )]

"
Information	3/14/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48047)(?)])(1 )(2 )]

"
Information	3/14/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48047)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/14/2019 8:49:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 8:30:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2019 8:30:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:16Z. Reason: GVLK.
Information	3/14/2019 8:27:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2019 8:27:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/14/2019 8:27:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2019 8:25:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2019 8:25:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2019 8:25:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2019 8:25:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/14/2019 8:09:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69879850-4602-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/14/2019 6:56:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/14/2019 5:19:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 4:27:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2019 3:54:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2019 3:54:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:17Z. Reason: GVLK.
Information	3/14/2019 3:45:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2019 3:45:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2019 3:45:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2019 3:45:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/14/2019 3:30:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 3:12:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/14/2019 3:09:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7fc9b914-45d8-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/14/2019 3:09:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/14/2019 1:59:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 12:27:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/14/2019 12:12:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/13/2019 10:23:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 10:09:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96186a90-45ae-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/13/2019 8:33:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 8:30:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 8:30:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:08Z. Reason: GVLK.
Information	3/13/2019 8:27:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 8:27:19 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/13/2019 8:27:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 8:25:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 8:25:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 8:25:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 8:25:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 8:22:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎13T14:48:22.074284000Z.
Information	3/13/2019 8:22:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎13T14:48:23.397416300Z.
Information	3/13/2019 8:22:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎13T14:48:19.502026800Z.
Information	3/13/2019 8:22:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{80F78F2E-64E6-4642-9FF6-5271C9A408B1}v4.22.8504.0\CsAgent.msi. Client Process Id: 24036.
Information	3/13/2019 8:22:06 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.22.8504.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	3/13/2019 8:22:06 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	3/13/2019 8:18:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎13T14:48:23.397416300Z.
Information	3/13/2019 8:18:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎13T14:48:22.074284000Z.
Information	3/13/2019 8:18:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎13T14:48:19.502026800Z.
Information	3/13/2019 8:18:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{80F78F2E-64E6-4642-9FF6-5271C9A408B1}v4.22.8504.0\CsAgent.msi. Client Process Id: 24036.
Information	3/13/2019 7:26:32 PM	MTAService.OnSessionChange	0	None	7:26:32 PM - Session change notice received: SessionLock Session ID: 1
Information	3/13/2019 7:16:59 PM	MTAService.OnSessionChange	0	None	7:16:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/13/2019 7:14:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 7:14:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:19Z. Reason: GVLK.
Information	3/13/2019 7:13:35 PM	MTAService.OnSessionChange	0	None	7:13:35 PM - Session change notice received: SessionLock Session ID: 1
Information	3/13/2019 7:09:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 7:09:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 7:09:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 7:09:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/13/2019 6:34:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 5:46:50 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/13/2019 5:46:38 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/13/2019 5:36:50 PM	MTAService.OnSessionChange	0	None	5:36:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/13/2019 5:11:19 PM	MTAService.OnSessionChange	0	None	5:11:19 PM - Session change notice received: SessionLock Session ID: 1
Information	3/13/2019 5:09:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac501327-4584-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/13/2019 5:01:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 4:27:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 3:47:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 3:47:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:02Z. Reason: GVLK.
Information	3/13/2019 3:42:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 3:42:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 3:42:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 3:42:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 3:34:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 3:34:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:08Z. Reason: GVLK.
Information	3/13/2019 3:29:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 3:29:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 3:29:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 3:29:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 3:20:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 3:20:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:03Z. Reason: GVLK.
Information	3/13/2019 3:15:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 3:15:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 3:15:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 3:14:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/13/2019 3:01:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 2:26:22 PM	MTAService.OnSessionChange	0	None	2:26:22 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/13/2019 1:18:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 12:57:30 PM	MTAService.OnSessionChange	0	None	12:57:30 PM - Session change notice received: SessionLock Session ID: 1
Information	3/13/2019 12:50:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9193.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/13/2019 12:39:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 12:39:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 12:36:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 12:36:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 12:26:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 12:23:40 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/13/2019 12:23:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 12:23:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 12:09:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c276f8ea-455a-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/13/2019 11:58:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 11:54:34 AM	MTAService.OnSessionChange	0	None	11:54:34 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/13/2019 11:53:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2019 11:53:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 11:52:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 11:33:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 11:32:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 11:32:45 AM	MTAService.OnSessionChange	0	None	11:32:45 AM - Session change notice received: SessionLock Session ID: 1
Information	3/13/2019 11:31:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 11:31:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 11:28:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 11:27:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 11:27:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 11:27:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/13/2019 11:19:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 10:51:25 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/13/2019 10:50:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/13/2019 9:46:01 AM	MTAService.OnSessionChange	0	None	9:46:01 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/13/2019 9:30:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 9:11:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/13/2019 9:06:54 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49487)(?)])(1 )(2 )]

"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49487)(?)])(1 )(2 )]

"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49487)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2019 9:06:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 9:06:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 8:27:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 8:27:04 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/13/2019 8:26:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/13/2019 7:42:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 7:09:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8a07dc7-4530-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/13/2019 5:54:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 4:26:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/13/2019 4:01:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 3:15:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 3:15:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:13Z. Reason: GVLK.
Information	3/13/2019 3:10:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 3:10:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 3:10:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 3:10:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 3:07:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2019 3:07:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:23Z. Reason: GVLK.
Information	3/13/2019 3:02:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2019 3:02:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2019 3:02:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2019 3:02:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2019 2:09:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eed2f05e-4506-11e9-a5a4-204747d02364
Report Status: 0"
Warning	3/13/2019 2:07:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/13/2019 12:32:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2019 12:26:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/12/2019 10:54:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 9:41:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/12/2019 9:41:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:36Z. Reason: GVLK.
Information	3/12/2019 9:36:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/12/2019 9:36:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2019 9:36:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 9:36:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/12/2019 9:11:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 9:09:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0502c6c0-44dd-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/12/2019 8:26:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 8:26:20 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/12/2019 8:26:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 7:36:18 PM	MTAService.OnSessionChange	0	None	7:36:18 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/12/2019 7:11:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 5:59:10 PM	MTAService.OnSessionChange	0	None	5:59:10 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/12/2019 5:26:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 5:23:06 PM	MTAService.OnSessionChange	0	None	5:23:06 PM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 5:22:21 PM	MTAService.OnSessionChange	0	None	5:22:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 5:21:57 PM	MTAService.OnSessionChange	0	None	5:21:57 PM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 4:29:00 PM	MTAService.OnSessionChange	0	None	4:29:00 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 4:26:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 4:09:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b456c00-44b3-11e9-a5a4-204747d02364
Report Status: 0"
Information	3/12/2019 4:04:34 PM	MTAService.OnSessionChange	0	None	4:04:34 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/12/2019 3:31:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 2:39:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/12/2019 2:39:09 PM	MTAService.OnSessionChange	0	None	2:39:09 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/12/2019 1:48:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 1:32:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 1:32:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 1:31:58 PM	MTAService.OnSessionChange	0	None	1:31:58 PM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 1:28:04 PM	MTAService.OnSessionChange	0	None	1:28:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 1:19:00 PM	MTAService.OnSessionChange	0	None	1:19:00 PM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 1:14:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 1:14:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 1:14:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 1:13:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 1:01:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 1:00:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 12:55:28 PM	MTAService.OnSessionChange	0	None	12:55:28 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 12:53:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9192.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/12/2019 12:52:06 PM	MTAService.OnSessionChange	0	None	12:52:06 PM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 12:43:01 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/12/2019 12:41:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 12:41:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 12:28:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 12:27:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 12:25:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 12:24:58 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/12/2019 11:51:55 AM	MTAService.OnSessionChange	0	None	11:51:55 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/12/2019 11:51:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 11:40:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/12/2019 11:40:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/12/2019 11:33:31 AM	MTAService.OnSessionChange	0	None	11:33:31 AM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 11:15:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/12/2019 11:15:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/12/2019 11:09:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 315c51b1-4489-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/12/2019 10:35:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/12/2019 10:30:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/12/2019 10:30:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 10:30:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/12/2019 9:55:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 9:45:26 AM	MTAService.OnSessionChange	0	None	9:45:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 9:17:08 AM	MTAService.OnSessionChange	0	None	9:17:08 AM - Session change notice received: SessionLock Session ID: 1
Information	3/12/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/12/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50927)(?)])(1 )(2 )]

"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50927)(?)])(1 )(2 )]

"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50927)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/12/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/12/2019 9:02:20 AM	MTAService.OnSessionChange	0	None	9:02:20 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/12/2019 8:25:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 8:25:56 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/12/2019 8:25:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/12/2019 8:00:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/12/2019 6:26:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 6:09:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47a1902e-445f-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/12/2019 4:50:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 4:25:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 4:25:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/12/2019 4:25:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 3:51:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/12/2019 3:51:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:18Z. Reason: GVLK.
Information	3/12/2019 3:46:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/12/2019 3:46:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2019 3:46:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 3:46:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/12/2019 3:44:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/12/2019 3:44:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:00Z. Reason: GVLK.
Information	3/12/2019 3:39:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/12/2019 3:39:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2019 3:39:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 3:39:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/12/2019 3:06:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 2:34:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/12/2019 2:34:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:06Z. Reason: GVLK.
Information	3/12/2019 2:29:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/12/2019 2:29:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2019 2:29:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2019 2:29:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/12/2019 1:09:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d2d5c5b-4435-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/12/2019 1:09:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2019 12:25:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/11/2019 11:09:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 90c29ea6-4424-11e9-a5a3-204747d02364
Report Status: 0"
Error	3/11/2019 11:09:00 PM	Group Policy Registry	8194	(2)	The client-side extension could not apply computer policy settings for 'GE000000000_WKS_WindowsUpdate {758EBEB8-8FFD-4A64-89CC-CEF0CCD98D84}' because it failed with error code '0x80070002 The system cannot find the file specified.' See trace file for more details.
Warning	3/11/2019 11:08:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 9:29:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 9:29:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:23Z. Reason: GVLK.
Warning	3/11/2019 9:27:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 9:24:23 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	3/11/2019 9:24:23 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	3/11/2019 9:24:23 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	3/11/2019 9:24:23 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	3/11/2019 9:24:23 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	3/11/2019 9:24:22 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	3/11/2019 9:24:20 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	3/11/2019 9:24:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 9:24:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 9:24:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 9:24:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 9:24:18 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	3/11/2019 8:52:35 PM	MTAService.OnSessionChange	0	None	8:52:35 PM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 8:25:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/11/2019 8:25:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/11/2019 8:25:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/11/2019 7:30:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 6:58:49 PM	MTAService.OnSessionChange	0	None	6:58:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/11/2019 6:20:44 PM	MTAService.OnSessionChange	0	None	6:20:44 PM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 6:12:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 301e7366-43fb-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/11/2019 5:44:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 5:17:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 5:17:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:52Z. Reason: GVLK.
Information	3/11/2019 5:12:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 5:12:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 5:12:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 5:12:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 4:25:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/11/2019 3:59:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 3:43:03 PM	MTAService.OnSessionChange	0	None	3:43:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/11/2019 3:01:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 3:01:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 2:16:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 2:16:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 2:11:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 2:11:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/11/2019 2:09:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 1:39:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 1:39:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 1:39:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:10:12Z. Reason: GVLK.
Information	3/11/2019 1:38:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 1:34:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 1:34:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 1:34:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 1:34:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 1:34:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 1:34:01 PM	MTAService.OnSessionChange	0	None	1:34:01 PM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 1:33:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 1:29:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 1:28:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 1:12:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4669a426-43d1-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/11/2019 1:06:00 PM	MTAService.OnSessionChange	0	None	1:06:00 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/11/2019 1:02:35 PM	MTAService.OnSessionChange	0	None	1:02:35 PM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 1:01:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 1:01:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 12:47:37 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/11/2019 12:35:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 12:34:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 12:32:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 12:30:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Error	3/11/2019 12:29:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/11/2019 12:25:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	3/11/2019 12:21:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 12:21:28 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/11/2019 12:20:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9191.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/11/2019 12:18:59 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/11/2019 11:52:51 AM	MTAService.OnSessionChange	0	None	11:52:51 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/11/2019 11:49:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:49:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 11:44:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:44:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 11:44:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 31409, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/11/2019 11:43:32 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/11/2019 11:38:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/11/2019 11:38:17 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/11/2019 11:37:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:36:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 11:34:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:33:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 11:33:16 AM	MTAService.OnSessionChange	0	None	11:33:16 AM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 11:28:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:27:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 11:17:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 11:17:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/11/2019 10:59:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/11/2019 10:59:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/11/2019 10:51:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 10:45:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 10:45:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-18T05:09:22Z. Reason: GVLK.
Information	3/11/2019 10:40:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 10:40:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 10:40:21 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/03/11 05:10"
Information	3/11/2019 10:40:20 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/03/11 05:10, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/11/2019 10:39:16 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.4.0.5899. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	3/11/2019 10:39:16 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	3/11/2019 10:39:04 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎11T05:05:03.800506200Z.
Information	3/11/2019 10:39:04 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9A8DE480-57CC-4C73-B9CD-92E0A38DD572}\4Sight™ 2.msi. Client Process Id: 15412.
Information	3/11/2019 10:35:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 10:35:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 10:35:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 10:35:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 10:35:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎11T05:05:03.800506200Z.
Information	3/11/2019 10:35:02 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9A8DE480-57CC-4C73-B9CD-92E0A38DD572}\4Sight™ 2.msi. Client Process Id: 15412.
Information	3/11/2019 10:31:20 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.4.0.5899. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	3/11/2019 10:31:20 AM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	3/11/2019 10:20:19 AM	MTAService.OnSessionChange	0	None	10:20:19 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/11/2019 9:55:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 9:50:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2019 9:50:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 9:50:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 9:22:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 9:18:17 AM	MTAService.OnSessionChange	0	None	9:18:17 AM - Session change notice received: SessionLock Session ID: 1
Information	3/11/2019 9:17:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52357)(?)])(1 )(2 )]

"
Information	3/11/2019 9:17:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/11/2019 9:17:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52357)(?)])(1 )(2 )]

"
Information	3/11/2019 9:17:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52357)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 9:17:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2019 9:17:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 9:17:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 9:11:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/11/2019 9:11:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/11/2019 9:10:48 AM	MTAService.OnSessionChange	0	None	9:10:48 AM - Session change notice received: SessionUnlock Session ID: 1
Error	3/11/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/11/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52367)(?)])(1 )(2 )]

"
Information	3/11/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/11/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52367)(?)])(1 )(2 )]

"
Information	3/11/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52367)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/11/2019 9:00:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 8:25:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/11/2019 8:25:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/11/2019 8:25:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/11/2019 8:12:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5c630414-43a7-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/11/2019 7:20:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/11/2019 5:42:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 4:25:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/11/2019 4:15:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 4:15:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:16Z. Reason: GVLK.
Information	3/11/2019 4:10:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 4:10:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 4:10:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 4:10:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 4:08:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2019 4:08:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:38Z. Reason: GVLK.
Warning	3/11/2019 4:03:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 4:03:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2019 4:03:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2019 4:03:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2019 4:03:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2019 3:12:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 72a24efa-437d-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/11/2019 2:09:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/11/2019 12:26:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/11/2019 12:24:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/11/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/10/2019 10:35:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 10:12:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 88ed02dc-4353-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/10/2019 8:57:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2019 8:57:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:58Z. Reason: GVLK.
Information	3/10/2019 8:52:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2019 8:52:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 8:52:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 8:52:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/10/2019 8:44:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 8:24:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/10/2019 8:24:57 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/10/2019 8:24:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/10/2019 7:11:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 6:41:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2019 6:41:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:46Z. Reason: GVLK.
Information	3/10/2019 6:36:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2019 6:36:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 6:36:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 6:36:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2019 5:27:35 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/10/2019 5:20:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 5:12:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9f2b635c-4329-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/10/2019 4:24:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/10/2019 3:41:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/10/2019 2:02:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 12:50:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9190.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/10/2019 12:36:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2019 12:36:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:17Z. Reason: GVLK.
Information	3/10/2019 12:31:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2019 12:31:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 12:31:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 12:31:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2019 12:24:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/10/2019 12:14:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 12:12:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5600d1d-42ff-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/10/2019 10:35:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/10/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/10/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53807)(?)])(1 )(2 )]

"
Information	3/10/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/10/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53807)(?)])(1 )(2 )]

"
Information	3/10/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53808)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/10/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/10/2019 8:55:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 8:24:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/10/2019 8:24:41 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/10/2019 8:24:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/10/2019 7:12:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb9e1e7d-42d5-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/10/2019 7:07:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/10/2019 5:36:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 4:24:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/10/2019 3:36:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 3:28:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2019 3:28:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:35Z. Reason: GVLK.
Information	3/10/2019 3:23:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2019 3:23:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 3:23:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 3:23:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2019 3:23:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2019 3:23:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:13Z. Reason: GVLK.
Information	3/10/2019 3:18:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2019 3:18:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2019 3:18:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2019 3:18:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2019 2:12:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1e6c6bc-42ab-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/10/2019 1:44:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/10/2019 12:24:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/10/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/9/2019 11:51:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/9/2019 9:58:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 9:45:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 9:45:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:11Z. Reason: GVLK.
Information	3/9/2019 9:40:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 9:40:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 9:40:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 9:40:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/9/2019 9:12:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f839ea61-4281-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/9/2019 8:24:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 8:24:16 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/9/2019 8:24:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/9/2019 8:08:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/9/2019 6:21:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 5:16:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 5:11:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/9/2019 5:11:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 5:11:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/9/2019 4:33:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 4:23:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 4:12:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e951781-4258-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, February 22, 2019 10:19:38 PM.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=SecureSign RootCA2, O=""Japan Certification Services, Inc."", C=JP> Sha1 thumbprint: <00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099>."
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=VAS Latvijas Pasts SSI(RCA), OU=Sertifikacijas pakalpojumi, O=VAS Latvijas Pasts - Vien.reg.Nr.40003052790, C=LV> Sha1 thumbprint: <086418E906CEE89C2353B6E27FBD9E7439F76316>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL> Sha1 thumbprint: <31F1FD68226320EEC63B3F9DEA4A3E537C7C3917>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL> Sha1 thumbprint: <3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=SSC Root CA A, OU=Certification Authority, O=Skaitmeninio sertifikavimo centras, C=LT> Sha1 thumbprint: <5A5A4DAF7861267C4B1F1E67586BAE6ED4FEB93F>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=Starfield Services Root Certificate Authority, OU=http://certificates.starfieldtech.com/repository/, O=""Starfield Technologies, Inc."", L=Scottsdale, S=Arizona, C=US> Sha1 thumbprint: <5D003860F002ED829DEAA41868F788186D62127F>."
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Swisscom Root CA 1, OU=Digital Certificate Services, O=Swisscom, C=ch> Sha1 thumbprint: <5F3AFC0A8B64F686673474DF7EA9A2FEF9FA7A51>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Certipost E-Trust Primary Qualified CA, O=Certipost s.a./n.v., C=BE> Sha1 thumbprint: <742CDF1594049CBF17A2046CC639BB3888E02E33>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=SecureSign RootCA3, O=""Japan Certification Services, Inc."", C=JP> Sha1 thumbprint: <8EB03FC3CF7BB292866268B751223DB5103405CB>."
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=VI Registru Centras RCSC (RootCA), OU=Registru Centro Sertifikavimo Centras, O=VI Registru Centras - I.k. 124110246, C=LT> Sha1 thumbprint: <971D3486FC1E8E6315F7C6F2E12967C724342214>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Root CA Generalitat Valenciana, OU=PKIGVA, O=Generalitat Valenciana, C=ES> Sha1 thumbprint: <A073E5C5BD43610D864C21130A855857CC9CEA46>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Certipost E-Trust Primary Normalised CA, O=Certipost s.a./n.v., C=BE> Sha1 thumbprint: <A59C9B10EC7357515ABB660C4D94F73B9E6E9272>.
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=SecureSign RootCA1, O=""Japan Certification Services, Inc."", C=JP> Sha1 thumbprint: <CABB51672400588E6419F1D40878D0403AA20264>."
Information	3/9/2019 3:03:19 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=ANF Server CA, SERIALNUMBER=G63287510, OU=ANF Clase 1 CA, O=ANF Autoridad de Certificación, L=Barcelona (see current address at https://www.anf.es/address/), S=Barcelona, C=ES> Sha1 thumbprint: <CEA9890D85D80753A626286CDAD78CB566D70CF2>.
Warning	3/9/2019 2:53:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 2:08:46 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/9/2019 1:17:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 12:55:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9189.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/9/2019 12:23:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/9/2019 11:33:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 11:30:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/9/2019 11:30:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/9/2019 11:12:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 24cf2862-422e-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/9/2019 10:26:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 10:26:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:21Z. Reason: GVLK.
Information	3/9/2019 10:21:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 10:21:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 10:21:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 10:21:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2019 9:44:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/9/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/9/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55247)(?)])(1 )(2 )]

"
Information	3/9/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/9/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55247)(?)])(1 )(2 )]

"
Information	3/9/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55247)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/9/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/9/2019 8:23:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 8:23:49 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/9/2019 8:23:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 8:22:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 8:22:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:03Z. Reason: GVLK.
Information	3/9/2019 8:17:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 8:17:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 8:17:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 8:17:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2019 8:11:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/9/2019 6:28:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 6:12:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3b0cc492-4204-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/9/2019 5:53:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 5:53:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:20Z. Reason: GVLK.
Information	3/9/2019 5:48:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 5:48:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 5:48:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 5:48:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2019 4:37:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 4:23:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 4:23:48 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/9/2019 4:23:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 3:43:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 3:43:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:11Z. Reason: GVLK.
Information	3/9/2019 3:38:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 3:38:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 3:38:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 3:38:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/9/2019 3:36:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2019 3:36:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:05Z. Reason: GVLK.
Information	3/9/2019 3:31:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2019 3:31:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2019 3:31:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2019 3:31:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2019 3:06:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/9/2019 1:20:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2019 1:12:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5157968d-41da-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/9/2019 12:23:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/8/2019 11:24:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/8/2019 9:26:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 8:39:52 PM	MTAService.OnSessionChange	0	None	8:39:52 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 8:23:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2019 8:23:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/8/2019 8:23:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2019 8:12:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 67970884-41b0-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/8/2019 7:37:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 7:27:01 PM	MTAService.OnSessionChange	0	None	7:27:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 7:07:23 PM	MTAService.OnSessionChange	0	None	7:07:23 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 6:08:58 PM	MTAService.OnSessionChange	0	None	6:08:58 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/8/2019 5:51:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 5:37:50 PM	MTAService.OnSessionChange	0	None	5:37:50 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 5:34:14 PM	MTAService.OnSessionChange	0	None	5:34:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 5:15:12 PM	MTAService.OnSessionChange	0	None	5:15:12 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 4:55:51 PM	MTAService.OnSessionChange	0	None	4:55:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 4:40:27 PM	MTAService.OnSessionChange	0	None	4:40:27 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 4:23:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2019 4:05:32 PM	MTAService.OnSessionChange	0	None	4:05:32 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/8/2019 3:52:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 3:31:36 PM	MTAService.OnSessionChange	0	None	3:31:36 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 3:27:41 PM	MTAService.OnSessionChange	0	None	3:27:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 3:25:44 PM	MTAService.OnSessionChange	0	None	3:25:44 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 3:12:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7dbb959d-4186-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/8/2019 2:20:42 PM	MTAService.OnSessionChange	0	None	2:20:42 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/8/2019 1:54:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 1:29:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/8/2019 1:29:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/8/2019 1:19:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2019 1:19:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:04Z. Reason: GVLK.
Information	3/8/2019 1:14:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2019 1:14:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2019 1:14:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2019 1:14:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/8/2019 1:08:19 PM	MTAService.OnSessionChange	0	None	1:08:19 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 12:58:13 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/8/2019 12:57:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/8/2019 12:54:46 PM	MTAService.OnSessionChange	0	None	12:54:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 12:45:30 PM	MTAService.OnSessionChange	0	None	12:45:30 PM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 12:33:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/8/2019 12:29:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/8/2019 12:29:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/8/2019 12:23:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	3/8/2019 12:11:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 12:03:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9188.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/8/2019 11:54:27 AM	MTAService.OnSessionChange	0	None	11:54:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 11:43:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/8/2019 11:43:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/8/2019 11:43:25 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 17, Compared: 31310, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/8/2019 11:42:01 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/8/2019 11:40:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/8/2019 11:40:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/8/2019 11:31:54 AM	MTAService.OnSessionChange	0	None	11:31:54 AM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 11:10:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/8/2019 11:10:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/8/2019 10:36:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 10:12:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 93feb12c-415c-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/8/2019 9:48:23 AM	MTAService.OnSessionChange	0	None	9:48:23 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/8/2019 9:46:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/8/2019 9:41:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/8/2019 9:41:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2019 9:41:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/8/2019 9:22:04 AM	MTAService.OnSessionChange	0	None	9:22:04 AM - Session change notice received: SessionLock Session ID: 1
Information	3/8/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/8/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/8/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56687)(?)])(1 )(2 )]

"
Information	3/8/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/8/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56687)(?)])(1 )(2 )]

"
Information	3/8/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56687)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/8/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/8/2019 9:03:52 AM	MTAService.OnSessionChange	0	None	9:03:52 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/8/2019 8:36:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 8:23:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2019 8:23:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/8/2019 8:23:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2019 7:02:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/8/2019 5:24:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 5:12:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa352309-4132-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/8/2019 4:22:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2019 3:49:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 2:12:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2019 2:12:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:05Z. Reason: GVLK.
Warning	3/8/2019 2:08:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 2:07:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2019 2:07:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2019 2:07:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2019 2:07:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/8/2019 12:22:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2019 12:16:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2019 12:12:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c06ddd39-4108-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/7/2019 10:30:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 10:05:26 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/7/2019 10:02:59 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/7/2019 9:38:43 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/7/2019 9:00:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 8:42:05 PM	MTAService.OnSessionChange	0	None	8:42:05 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 8:23:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2019 8:23:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/7/2019 8:22:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2019 7:22:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 7:12:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d6b94118-40de-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/7/2019 7:05:44 PM	MTAService.OnSessionChange	0	None	7:05:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 7:00:12 PM	MTAService.OnSessionChange	0	None	7:00:12 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 6:43:21 PM	MTAService.OnSessionChange	0	None	6:43:21 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/7/2019 5:48:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 5:44:42 PM	MTAService.OnSessionChange	0	None	5:44:42 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 4:43:53 PM	MTAService.OnSessionChange	0	None	4:43:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 4:31:38 PM	MTAService.OnSessionChange	0	None	4:31:38 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 4:27:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/7/2019 4:22:55 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 218

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1123

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 32

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 327

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	3/7/2019 4:22:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2019 4:22:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57692)(?)])(1 )(2 )]

"
Information	3/7/2019 4:22:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2019 4:22:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57692)(?)])(1 )(2 )]

"
Information	3/7/2019 4:22:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57692)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 4:21:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57693)(?)])(1 )(2 )]

"
Information	3/7/2019 4:21:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2019 4:21:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57693)(?)])(1 )(2 )]

"
Information	3/7/2019 4:21:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 4:21:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/7/2019 4:21:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 4:21:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/7/2019 4:18:46 PM	MTAService.OnSessionChange	0	None	4:18:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 4:09:53 PM	MTAService.OnSessionChange	0	None	4:09:53 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/7/2019 4:07:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 3:32:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 14836.
Information	3/7/2019 3:32:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎03‎-‎07T10:01:16.040548600Z.
Information	3/7/2019 3:32:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.4.0.12141. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	3/7/2019 3:32:29 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	3/7/2019 3:31:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎03‎-‎07T10:01:16.040548600Z.
Information	3/7/2019 3:31:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 14836.
Information	3/7/2019 2:50:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/7/2019 2:45:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2019 2:45:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2019 2:45:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57789)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 2:45:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/7/2019 2:45:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 2:45:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/7/2019 2:21:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 2:20:08 PM	MTAService.OnSessionChange	0	None	2:20:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 2:17:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 2:17:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 2:12:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ecdbb471-40b4-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/7/2019 1:55:00 PM	MTAService.OnSessionChange	0	None	1:55:00 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 1:52:09 PM	MTAService.OnSessionChange	0	None	1:52:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 1:51:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 1:51:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 1:51:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 1:50:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 1:19:40 PM	MTAService.OnSessionChange	0	None	1:19:40 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 1:11:33 PM	MTAService.OnSessionChange	0	None	1:11:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 1:06:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 1:05:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 1:01:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 1:00:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 1:00:09 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9187.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/7/2019 12:59:26 PM	MTAService.OnSessionChange	0	None	12:59:26 PM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 12:53:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:53:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 12:50:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:50:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	3/7/2019 12:41:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 12:34:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:34:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 12:28:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2019 12:27:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:26:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 12:21:08 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/7/2019 12:20:59 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/7/2019 12:20:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/7/2019 12:13:17 PM	MTAService.OnSessionChange	0	None	12:13:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 12:08:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:08:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 12:06:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 12:05:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 11:51:57 AM	MTAService.OnSessionChange	0	None	11:51:57 AM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 11:50:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/7/2019 11:50:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/7/2019 11:42:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2019 11:42:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:28Z. Reason: GVLK.
Information	3/7/2019 11:37:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2019 11:37:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 11:37:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 11:37:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/7/2019 11:06:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 10:11:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2019 10:11:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:04Z. Reason: GVLK.
Information	3/7/2019 10:06:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2019 10:06:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 10:06:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 10:06:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/7/2019 9:39:26 AM	MTAService.OnSessionChange	0	None	9:39:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 9:39:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/7/2019 9:34:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/7/2019 9:34:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 9:34:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/7/2019 9:17:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 9:13:54 AM	MTAService.OnSessionChange	0	None	9:13:54 AM - Session change notice received: SessionLock Session ID: 1
Information	3/7/2019 9:12:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0325a4fe-408b-11e9-a5a3-204747d02364
Report Status: 0"
Information	3/7/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/7/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/7/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58127)(?)])(1 )(2 )]

"
Information	3/7/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58128)(?)])(1 )(2 )]

"
Information	3/7/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58128)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/7/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 9:06:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/7/2019 9:01:34 AM	MTAService.OnSessionChange	0	None	9:01:34 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/7/2019 8:29:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2019 8:29:04 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/7/2019 8:28:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2019 7:34:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/7/2019 5:56:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 4:28:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2019 4:18:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 4:12:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 194c32e9-4061-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/7/2019 2:21:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/7/2019 12:35:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2019 12:28:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2019 12:28:20 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/7/2019 12:28:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 11:12:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2f9f50f4-4037-11e9-a5a3-204747d02364
Report Status: 0"
Warning	3/6/2019 10:56:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/6/2019 8:57:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 8:48:42 PM	MTAService.OnSessionChange	0	None	8:48:42 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 8:47:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 8:44:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 8:44:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:20Z. Reason: GVLK.
Error	3/6/2019 8:42:47 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/6/2019 8:42:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58872)(?)])(1 )(2 )]

"
Information	3/6/2019 8:42:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/6/2019 8:42:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58872)(?)])(1 )(2 )]

"
Information	3/6/2019 8:42:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58872)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 8:42:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/6/2019 8:42:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 8:42:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 8:39:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2019 8:39:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 8:39:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 8:39:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 8:36:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 8:36:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:57Z. Reason: GVLK.
Information	3/7/2019 8:32:18 PM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Friday, February 22, 2019 10:37:12 PM.
Information	3/7/2019 8:31:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2019 8:31:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2019 8:31:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2019 8:31:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 8:28:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 8:28:13 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/6/2019 8:28:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 8:23:16 PM	MTAService.OnSessionChange	0	None	8:23:16 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/6/2019 8:01:52 PM	MTAService.OnSessionChange	0	None	8:01:52 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 7:10:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 7:10:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:07Z. Reason: GVLK.
Warning	3/6/2019 7:07:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 7:05:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2019 7:05:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 7:05:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 7:05:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 6:24:04 PM	MTAService.OnSessionChange	0	None	6:24:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/6/2019 6:12:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 45b5055b-400d-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/6/2019 5:21:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 5:20:45 PM	MTAService.OnSessionChange	0	None	5:20:45 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 4:42:40 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/6/2019 4:41:10 PM	MTAService.OnSessionChange	0	None	4:41:10 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/6/2019 4:27:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 4:06:23 PM	MTAService.OnSessionChange	0	None	4:06:23 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/6/2019 3:44:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 3:20:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/6/2019 3:19:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/6/2019 3:19:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 3:19:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:01Z. Reason: GVLK.
Information	3/6/2019 3:14:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2019 3:14:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 3:14:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 3:13:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/6/2019 2:37:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 2:37:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 2:35:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 2:35:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/6/2019 2:35:06 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/6/2019 1:57:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/6/2019 1:57:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/6/2019 1:57:02 PM	MTAService.OnSessionChange	0	None	1:57:02 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/6/2019 1:55:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/6/2019 1:54:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:54:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/6/2019 1:54:56 PM	MTAService.OnSessionChange	0	None	1:54:56 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 1:54:03 PM	MTAService.OnSessionChange	0	None	1:54:03 PM - Session change notice received: SessionUnlock Session ID: 1
Error	3/6/2019 1:53:14 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:53:14 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:52:14 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:52:14 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:51:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:51:18 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:48:26 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:48:26 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:47:49 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	3/6/2019 1:47:49 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	3/6/2019 1:12:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5bdbdde7-3fe3-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/6/2019 1:04:50 PM	MTAService.OnSessionChange	0	None	1:04:50 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 12:49:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9186.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/6/2019 12:34:08 PM	MTAService.OnSessionChange	0	None	12:34:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/6/2019 12:32:26 PM	MTAService.OnSessionChange	0	None	12:32:26 PM - Session change notice received: SessionLock Session ID: 1
Information	3/6/2019 12:27:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 12:18:36 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/6/2019 11:57:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 11:41:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/6/2019 11:41:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	3/6/2019 10:07:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 9:57:29 AM	MTAService.OnSessionChange	0	None	9:57:29 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/6/2019 9:20:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 9:15:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/6/2019 9:15:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 9:15:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/6/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/6/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59567)(?)])(1 )(2 )]

"
Information	3/6/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/6/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59567)(?)])(1 )(2 )]

"
Information	3/6/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59568)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/6/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 8:27:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 8:27:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/6/2019 8:27:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/6/2019 8:24:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 8:12:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71ff2205-3fb9-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/6/2019 6:51:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/6/2019 5:02:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 4:27:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 4:17:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 4:17:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:12Z. Reason: GVLK.
Information	3/6/2019 4:12:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2019 4:12:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 4:12:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 4:12:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2019 4:09:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2019 4:09:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:53Z. Reason: GVLK.
Information	3/6/2019 4:04:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2019 4:04:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2019 4:04:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2019 4:04:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/6/2019 3:19:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 3:12:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 883c4905-3f8f-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/6/2019 2:54:11 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/6/2019 2:51:49 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/6/2019 1:38:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2019 12:27:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 12:27:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/6/2019 12:26:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/5/2019 11:57:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 10:29:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 10:29:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:06Z. Reason: GVLK.
Information	3/5/2019 10:24:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2019 10:24:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 10:24:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 10:24:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 10:12:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e6a3b61-3f65-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/5/2019 10:06:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 8:30:09 PM	MTAService.OnSessionChange	0	None	8:30:09 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 8:27:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 8:27:00 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/5/2019 8:26:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/5/2019 8:08:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 7:56:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 7:51:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60363)(?)])(1 )(2 )]

"
Information	3/5/2019 7:51:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:51:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60363)(?)])(1 )(2 )]

"
Information	3/5/2019 7:51:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60363)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:49:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60365)(?)])(1 )(2 )]

"
Information	3/5/2019 7:49:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:49:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60365)(?)])(1 )(2 )]

"
Information	3/5/2019 7:49:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60365)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:48:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:48:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]

"
Information	3/5/2019 7:48:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60366)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:46:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60368)(?)])(1 )(2 )]

"
Information	3/5/2019 7:46:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:46:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60368)(?)])(1 )(2 )]

"
Information	3/5/2019 7:46:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60368)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:43:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:43:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60371)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:43:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2019 7:43:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 7:43:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 7:35:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 7:30:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60384)(?)])(1 )(2 )]

"
Information	3/5/2019 7:30:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:30:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60384)(?)])(1 )(2 )]

"
Information	3/5/2019 7:30:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60384)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]

"
Information	3/5/2019 7:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:27:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]

"
Information	3/5/2019 7:27:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:26:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]

"
Information	3/5/2019 7:26:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 7:26:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]

"
Information	3/5/2019 7:26:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60387)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 7:26:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2019 7:26:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 7:26:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 7:13:24 PM	MTAService.OnSessionChange	0	None	7:13:24 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/5/2019 6:20:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 6:12:41 PM	MTAService.OnSessionChange	0	None	6:12:41 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 6:08:34 PM	MTAService.OnSessionChange	0	None	6:08:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 6:07:37 PM	MTAService.OnSessionChange	0	None	6:07:37 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 5:38:46 PM	MTAService.OnSessionChange	0	None	5:38:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 5:35:22 PM	MTAService.OnSessionChange	0	None	5:35:22 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 5:21:17 PM	MTAService.OnSessionChange	0	None	5:21:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 5:16:29 PM	MTAService.OnSessionChange	0	None	5:16:29 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 5:12:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b495afa5-3f3b-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/5/2019 4:38:14 PM	MTAService.OnSessionChange	0	None	4:38:14 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/5/2019 4:37:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 4:29:48 PM	MTAService.OnSessionChange	0	None	4:29:48 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 4:26:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 3:42:30 PM	MTAService.OnSessionChange	0	None	3:42:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 3:33:37 PM	MTAService.OnSessionChange	0	None	3:33:37 PM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 3:00:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60659)(?)])(1 )(2 )]

"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60659)(?)])(1 )(2 )]

"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60659)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2019 2:55:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 2:55:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/5/2019 2:54:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 2:20:19 PM	MTAService.OnSessionChange	0	None	2:20:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 1:18:44 PM	MTAService.OnSessionChange	0	None	1:18:44 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/5/2019 1:16:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 12:54:50 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/5/2019 12:54:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 12:54:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:12Z. Reason: GVLK.
Information	3/5/2019 12:49:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2019 12:49:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 12:49:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 12:49:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 12:42:11 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/5/2019 12:33:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9185.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/5/2019 12:29:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/5/2019 12:26:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 12:12:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: caa0c397-3f11-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/5/2019 11:55:27 AM	MTAService.OnSessionChange	0	None	11:55:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 11:43:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/5/2019 11:43:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/5/2019 11:43:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 31086, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/5/2019 11:43:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	3/5/2019 11:37:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 11:32:36 AM	MTAService.OnSessionChange	0	None	11:32:36 AM - Session change notice received: SessionLock Session ID: 1
Error	3/5/2019 10:36:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/5/2019 10:01:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 9:51:51 AM	MTAService.OnSessionChange	0	None	9:51:51 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 9:27:08 AM	MTAService.OnSessionChange	0	None	9:27:08 AM - Session change notice received: SessionLock Session ID: 1
Information	3/5/2019 9:26:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/5/2019 9:23:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/5/2019 9:23:33 AM	MTAService.OnSessionChange	0	None	9:23:33 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/5/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/5/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/5/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61007)(?)])(1 )(2 )]

"
Information	3/5/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61007)(?)])(1 )(2 )]

"
Information	3/5/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61007)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 8:57:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 8:52:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2019 8:52:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 8:52:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 8:26:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 8:26:39 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/5/2019 8:26:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/5/2019 8:22:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/5/2019 7:51:59 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (21) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190228_120334.log
"
Error	3/5/2019 7:51:59 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190228_120334.log
"
Information	3/5/2019 7:12:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e0d662b5-3ee7-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/5/2019 6:29:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/5/2019 4:54:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 4:25:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 3:55:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 3:55:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:07Z. Reason: GVLK.
Information	3/5/2019 3:50:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2019 3:50:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 3:50:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 3:50:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 3:42:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 3:42:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:59Z. Reason: GVLK.
Information	3/5/2019 3:37:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2019 3:37:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 3:37:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 3:37:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/5/2019 3:36:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2019 3:36:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:03Z. Reason: GVLK.
Information	3/5/2019 3:31:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2019 3:31:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2019 3:31:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2019 3:31:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/5/2019 3:10:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 2:12:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f716b70d-3ebd-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/5/2019 1:26:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2019 12:25:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/4/2019 11:45:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/4/2019 9:57:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 9:12:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d7d3df3-3e94-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/4/2019 8:26:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 8:26:03 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/4/2019 8:25:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/4/2019 8:14:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 7:57:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 7:57:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:39Z. Reason: GVLK.
Information	3/4/2019 7:52:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 7:52:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 7:52:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 7:52:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/4/2019 6:25:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/4/2019 4:49:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 4:25:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 4:12:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 23b86a26-3e6a-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/4/2019 2:57:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 1:47:51 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/4/2019 1:16:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 12:53:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9184.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/4/2019 12:25:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 12:03:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 12:03:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:54Z. Reason: GVLK.
Information	3/4/2019 11:58:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 11:58:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 11:58:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 11:58:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/4/2019 11:24:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 11:22:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 11:22:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:05:36Z. Reason: GVLK.
Information	3/4/2019 11:17:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 11:17:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 11:17:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 11:17:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/4/2019 11:11:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3a15ba09-3e40-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/4/2019 10:40:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 10:40:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-11T05:04:49Z. Reason: GVLK.
Information	3/4/2019 10:35:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 10:35:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 10:35:48 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/03/04 05:05"
Information	3/4/2019 10:35:47 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/03/04 05:05, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/4/2019 10:30:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 10:30:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 10:30:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 10:30:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/4/2019 9:25:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/4/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/4/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62447)(?)])(1 )(2 )]

"
Information	3/4/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/4/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62447)(?)])(1 )(2 )]

"
Information	3/4/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62448)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/4/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/4/2019 8:25:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 8:25:54 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/4/2019 8:25:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/4/2019 7:53:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 6:11:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 50500c70-3e16-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/4/2019 6:02:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 4:25:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 4:24:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 4:24:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:26Z. Reason: GVLK.
Information	3/4/2019 4:15:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 4:15:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 4:15:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 4:15:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/4/2019 4:11:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 2:41:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2019 2:41:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:10Z. Reason: GVLK.
Information	3/4/2019 2:36:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2019 2:36:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2019 2:36:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2019 2:36:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/4/2019 2:20:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 1:11:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 66720149-3dec-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/4/2019 12:40:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2019 12:25:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/4/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/3/2019 10:43:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/3/2019 9:07:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 8:25:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/3/2019 8:25:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/3/2019 8:24:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/3/2019 8:11:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7cc22c08-3dc2-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/3/2019 7:48:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2019 7:48:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:39Z. Reason: GVLK.
Information	3/3/2019 7:43:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2019 7:43:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2019 7:43:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 7:43:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/3/2019 7:25:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/3/2019 5:48:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 4:24:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/3/2019 4:09:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 3:36:49 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/3/2019 3:11:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 930d67e5-3d98-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/3/2019 2:38:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 1:50:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/3/2019 1:45:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/3/2019 1:45:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 1:45:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/3/2019 12:51:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 12:25:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9183.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/3/2019 12:24:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/3/2019 11:30:30 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/3/2019 11:30:30 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/3/2019 11:30:29 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	3/3/2019 11:10:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 10:11:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a94f0e8a-3d6e-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/3/2019 9:31:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/3/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/3/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63887)(?)])(1 )(2 )]

"
Information	3/3/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/3/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63888)(?)])(1 )(2 )]

"
Information	3/3/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63888)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/3/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 9:06:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/3/2019 8:24:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/3/2019 8:24:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/3/2019 8:24:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/3/2019 7:44:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/3/2019 5:52:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 5:11:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bf80fb62-3d44-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/3/2019 4:24:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/3/2019 3:56:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 3:27:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2019 3:27:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:36Z. Reason: GVLK.
Information	3/3/2019 3:17:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2019 3:17:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2019 3:17:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 3:17:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/3/2019 2:01:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 1:38:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2019 1:38:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:50Z. Reason: GVLK.
Information	3/3/2019 1:33:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2019 1:33:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2019 1:33:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 1:33:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2019 12:24:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/3/2019 12:24:39 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/3/2019 12:24:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/3/2019 12:21:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/3/2019 12:20:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2019 12:20:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:39Z. Reason: GVLK.
Information	3/3/2019 12:15:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2019 12:15:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2019 12:15:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2019 12:15:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2019 12:11:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5c02761-3d1a-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/3/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/2/2019 10:49:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/2/2019 9:13:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 8:24:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/2/2019 8:24:27 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/2/2019 8:24:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/2/2019 7:43:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 7:11:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec014817-3cf0-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/2/2019 5:54:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 4:23:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/2/2019 4:04:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 2:11:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 023d86c6-3cc7-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/2/2019 2:09:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 1:37:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/2/2019 12:48:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 12:43:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/2/2019 12:43:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 12:43:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/2/2019 12:31:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 12:23:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/2/2019 12:13:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9182.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/2/2019 11:31:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/2/2019 11:31:56 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/2/2019 11:31:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 1, Deleted: 0, Modified: 1, Compared: 31016, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	3/2/2019 11:30:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/2/2019 11:30:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 11:30:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:04Z. Reason: GVLK.
Information	3/2/2019 11:25:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/2/2019 11:25:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/2/2019 11:25:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 11:25:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/2/2019 10:34:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 9:11:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 9:11:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18887093-3c9d-11e9-a5a2-204747d02364
Report Status: 0"
Error	3/2/2019 9:06:52 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/2/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65327)(?)])(1 )(2 )]

"
Information	3/2/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/2/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65327)(?)])(1 )(2 )]

"
Information	3/2/2019 9:06:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65328)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/2/2019 9:06:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/2/2019 9:06:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/2/2019 8:42:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 8:23:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/2/2019 8:23:48 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/2/2019 8:23:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/2/2019 6:51:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 5:17:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 5:17:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:10Z. Reason: GVLK.
Information	3/2/2019 5:12:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/2/2019 5:12:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/2/2019 5:12:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 5:12:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/2/2019 5:06:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 4:23:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/2/2019 4:11:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2ec0896c-3c73-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/2/2019 3:23:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 3:23:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:06Z. Reason: GVLK.
Warning	3/2/2019 3:20:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 3:18:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/2/2019 3:18:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/2/2019 3:18:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 3:18:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/2/2019 3:17:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/2/2019 3:17:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:01Z. Reason: GVLK.
Information	3/2/2019 3:12:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/2/2019 3:12:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/2/2019 3:12:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/2/2019 3:12:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/2/2019 1:35:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/2/2019 12:22:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/2/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/1/2019 11:51:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 11:11:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44f93968-3c49-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/1/2019 10:09:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 8:40:27 PM	GE Software	0	(1)	++Installation complete
Information	3/1/2019 8:40:27 PM	GE Software	0	(1)	++ Current User shortcut created for profile: Default
Information	3/1/2019 8:40:27 PM	GE Software	0	(1)	++ Current User shortcut created for profile: MSSQL$SQLEXPRESS
Information	3/1/2019 8:40:27 PM	GE Software	0	(1)	++ Current User shortcut created for profile: DefaultAppPool
Information	3/1/2019 8:40:26 PM	GE Software	0	(1)	++ Current User shortcut created for profile: Administrator
Information	3/1/2019 8:40:26 PM	GE Software	0	(1)	++ Current User shortcut created for profile: admin
Information	3/1/2019 8:40:26 PM	GE Software	0	(1)	++ Current User shortcut created for profile: 212558710
Information	3/1/2019 8:40:26 PM	GE Software	0	(1)	++ Current User shortcut created for profile: 212553210
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++ Moving shortcut from All Users desktop to all current users desktops
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++I-Rev running : I02
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Warning	3/1/2019 8:40:25 PM	GE Software	0	(1)	++ Passed permissions check
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++Started the installation of GE RaiseAConcernShortcutBHGE 2.0 V01 with the following commandline: /Q
Information	3/1/2019 8:40:25 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/1/2019 8:40:20 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/1/2019 8:23:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 8:23:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/1/2019 8:22:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2019 8:20:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/1/2019 6:49:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 6:11:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5af6b5fc-3c1f-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/1/2019 5:01:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 4:45:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 4:45:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:05Z. Reason: GVLK.
Information	3/1/2019 4:40:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 4:40:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 4:40:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 4:40:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 4:22:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 3:22:31 PM	MTAService.OnSessionChange	0	None	3:22:31 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/1/2019 3:05:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 2:32:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 2:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66447)(?)])(1 )(2 )]

"
Error	3/1/2019 2:27:30 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/1/2019 2:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/1/2019 2:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66447)(?)])(1 )(2 )]

"
Information	3/1/2019 2:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66447)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 2:27:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/1/2019 2:27:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 2:27:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 2:14:08 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/1/2019 2:13:48 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/1/2019 2:13:03 PM	MTAService.OnSessionChange	0	None	2:13:03 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/1/2019 1:13:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 1:11:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 711c7b6c-3bf5-11e9-a5a2-204747d02364
Report Status: 0"
Information	3/1/2019 1:01:25 PM	MTAService.OnSessionChange	0	None	1:01:25 PM - Session change notice received: SessionLock Session ID: 1
Information	3/1/2019 12:40:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9181.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	3/1/2019 12:36:37 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/1/2019 12:22:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 12:11:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 12:06:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/1/2019 12:06:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 12:06:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 11:54:13 AM	MTAService.OnSessionChange	0	None	11:54:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/1/2019 11:30:55 AM	MTAService.OnSessionChange	0	None	11:30:55 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/1/2019 11:20:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 9:49:44 AM	MTAService.OnSessionChange	0	None	9:49:44 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/1/2019 9:28:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 9:28:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:44Z. Reason: GVLK.
Warning	3/1/2019 9:27:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 9:23:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 9:23:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 9:23:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 9:23:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 9:11:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/1/2019 9:06:53 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	3/1/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66767)(?)])(1 )(2 )]

"
Information	3/1/2019 9:06:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/1/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66767)(?)])(1 )(2 )]

"
Information	3/1/2019 9:06:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66767)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 9:06:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/1/2019 9:06:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 9:06:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 8:22:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 8:22:42 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/1/2019 8:22:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 8:11:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 872d7841-3bcb-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/1/2019 7:29:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/1/2019 5:40:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 4:21:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2019 4:05:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 4:05:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:41Z. Reason: GVLK.
Information	3/1/2019 4:00:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 4:00:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 4:00:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 4:00:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 4:00:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 4:00:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:23Z. Reason: GVLK.
Warning	3/1/2019 3:56:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 3:55:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 3:55:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 3:55:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 3:55:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 3:51:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 3:51:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:10Z. Reason: GVLK.
Information	3/1/2019 3:46:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 3:46:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 3:46:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 3:46:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 3:11:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d641c8d-3ba1-11e9-a5a2-204747d02364
Report Status: 0"
Warning	3/1/2019 1:57:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 12:59:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2019 12:59:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:54Z. Reason: GVLK.
Information	3/1/2019 12:54:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2019 12:54:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2019 12:54:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2019 12:54:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2019 12:21:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2019 12:18:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/28/2019 10:45:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 10:11:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3aaf336-3b77-11e9-a5a2-204747d02364
Report Status: 0"
Warning	2/28/2019 8:50:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 8:21:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 8:21:42 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/28/2019 8:21:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 8:19:29 PM	MTAService.OnSessionChange	0	None	8:19:29 PM - Session change notice received: SessionLock Session ID: 1
Warning	2/28/2019 7:06:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 6:44:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 6:22:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2019 6:22:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67651)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67651)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67651)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110851  Grace type=8.
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=bf4bb503-d627-4ca6-aeab-8158e4b28b44"
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=54e7a857-b0be-4f33-abe4-0b7fea764a30"
Information	2/28/2019 6:22:51 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/28/2019 6:22:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21572)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2019 6:22:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21572)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21572)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 6:22:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/28/2019 6:22:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 6:22:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 6:15:42 PM	MTAService.OnSessionChange	0	None	6:15:42 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	2/28/2019 5:22:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 5:19:04 PM	MTAService.OnSessionChange	0	None	5:19:04 PM - Session change notice received: SessionLock Session ID: 1
Information	2/28/2019 5:11:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c9ce62b7-3b4d-11e9-a5a2-204747d02364
Report Status: 0"
Information	2/28/2019 4:41:42 PM	MTAService.OnSessionChange	0	None	4:41:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	2/28/2019 4:35:52 PM	MTAService.OnSessionChange	0	None	4:35:52 PM - Session change notice received: SessionLock Session ID: 1
Information	2/28/2019 4:21:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 4:14:56 PM	MTAService.OnSessionChange	0	None	4:14:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	2/28/2019 3:51:39 PM	MTAService.OnSessionChange	0	None	3:51:39 PM - Session change notice received: SessionLock Session ID: 1
Warning	2/28/2019 3:33:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 2:16:17 PM	MTAService.OnSessionChange	0	None	2:16:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	2/28/2019 2:09:28 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/28/2019 2:02:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 2:01:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9180.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/28/2019 1:12:55 PM	MTAService.OnSessionChange	0	None	1:12:55 PM - Session change notice received: SessionLock Session ID: 1
Information	2/28/2019 1:09:24 PM	MTAService.OnSessionChange	0	None	1:09:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	2/28/2019 1:08:28 PM	MTAService.OnSessionChange	0	None	1:08:28 PM - Session change notice received: SessionLock Session ID: 1
Information	2/28/2019 1:03:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/28/2019 1:03:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/28/2019 12:27:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 12:22:41 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/28/2019 12:22:18 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 141

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 936

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 218

Error	2/28/2019 12:21:41 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/28/2019 12:21:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]

"
Information	2/28/2019 12:21:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2019 12:21:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]

"
Information	2/28/2019 12:21:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 12:21:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 12:21:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:22Z. Reason: GVLK.
Information	2/28/2019 12:21:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 12:21:05 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	2/28/2019 12:20:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]

"
Information	2/28/2019 12:20:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2019 12:20:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]

"
Information	2/28/2019 12:20:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21934)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 12:18:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:18 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.10730.20280. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:18:18 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	2/28/2019 12:18:18 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/28/2019 12:18:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 12:18:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	2/28/2019 12:18:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/28/2019 12:18:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 12:18:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/28/2019 12:18:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 12:18:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 12:18:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.10730.20280. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:18:09 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	2/28/2019 12:18:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20280. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:18:06 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	2/28/2019 12:18:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:18:04 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20280. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:18:04 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	2/28/2019 12:17:59 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/28/2019 12:17:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:17:59 PM	ESENT	102	General	Windows (11616) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/28/2019 12:17:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:17:59 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20280. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:17:59 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	2/28/2019 12:17:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:17:38 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/28/2019 12:17:38 PM	ESENT	103	General	Windows (7084) Windows: The database engine stopped the instance (0).
Information	2/28/2019 12:17:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:17:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20280. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/28/2019 12:17:38 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	2/28/2019 12:16:56 PM	MTAService	0	None	Service started successfully.
Information	2/28/2019 12:16:52 PM	MTAService.OnStart	0	None	12:16:52 PM - User is already logged in : 212558710
Information	2/28/2019 12:15:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10292.
Information	2/28/2019 12:14:50 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/28/2019 12:14:49 PM	ESENT	102	General	Windows (7084) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/28/2019 12:14:48 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/28/2019 12:14:48 PM	ESENT	103	General	Windows (1896) Windows: The database engine stopped the instance (0).
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:46 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:45 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:45 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:45 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:45 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:45 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:44 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:44 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/28/2019 12:14:44 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:44 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:44 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/28/2019 12:14:35 PM	MTAService	0	None	Service stopped successfully.
Information	2/28/2019 12:14:35 PM	MTAService	0	None	MTAService.OnStop: --> Stop
Information	2/28/2019 12:13:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 12:13:17 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	2/28/2019 12:13:17 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	2/28/2019 12:13:05 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/28/2019 12:12:56 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/28/2019 12:12:56 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft VS Code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9179.0000.
Information	2/28/2019 12:12:52 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	2/28/2019 12:11:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/28/2019 12:11:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df4a0b33-3b23-11e9-a5a2-204747d02364
Report Status: 0"
Information	2/28/2019 12:11:23 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/28/2019 12:11:23 PM	MTAService.OnSessionChange	0	None	12:11:23 PM - Logon : 212558710
Information	2/28/2019 12:11:23 PM	MTAService.OnSessionChange	0	None	12:11:23 PM - Session change notice received: SessionLogon Session ID: 1
Information	2/28/2019 12:11:23 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/28/2019 12:11:23 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/28/2019 12:11:23 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	2/28/2019 12:11:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 12:10:40 PM	MTAService.OnSessionChange	0	None	12:10:40 PM - Session change notice received: ConsoleConnect Session ID: 1
Warning	2/28/2019 12:10:38 PM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 155 second(s) to handle the notification event (CreateSession).
Information	2/28/2019 12:09:15 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Warning	2/28/2019 12:08:59 PM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	2/28/2019 12:08:58 PM	ESENT	302	Logging/Recovery	Windows (1896) Windows: The database engine has successfully completed recovery steps.
Information	2/28/2019 12:08:51 PM	ESENT	301	Logging/Recovery	Windows (1896) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/28/2019 12:08:51 PM	ESENT	300	Logging/Recovery	Windows (1896) Windows: The database engine is initiating recovery steps.
Information	2/28/2019 12:08:50 PM	ESENT	102	General	Windows (1896) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/28/2019 12:08:45 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e633ae97-1bc1-4fdb-873e-55456b30489a"
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60bf7784-81ca-4556-a959-9c152e15669d"
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=544d2e70-aa48-4e2b-a43d-52ec83aa0427"
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=cf84484a-44a0-4b67-b1e9-4186929240ca"
Information	2/28/2019 12:08:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3acae882-52ce-42dd-a708-eca29d35bb09"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=56421083-4260-4bf5-8bb8-2a9aed708066"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c6341c8-6dda-4a94-810d-45c3ba3108cf"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5a9f936e-3aee-409b-ada6-cd0169049418"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d6a534c8-cdf3-442d-850f-925004c6ed8f"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9d16bfa3-a0aa-4659-8555-04360305c600"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=576982b1-f73d-442b-8f34-4e9c8245f728"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4958405-6251-473b-b4e9-649f61239091"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=cb1acfd5-4ad6-46f7-a508-95096e7e53cb"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60c6b5ae-abeb-405a-ae22-b1a179b9a0b8"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f46cd2ab-a792-4421-a25b-10a2c2b6065e"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3fcfa8df-de4c-4ae9-a6eb-ce92f6000012"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=70abdf70-5bb0-46f5-bade-1e7fb728eb96"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=84904722-dfb7-4e90-b656-eac912151df3"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=380aa12a-eeb0-4851-8915-e97ff3c99037"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4e1412c-eafa-4c01-bf17-96f00ec2e8c0"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ba2baae7-dc04-4afe-82d9-abff518374c0"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=55e45973-1275-415b-84ea-5dd31d2bf5b6"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=59f44fbc-2ce4-4025-900a-219030f1d5f1"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=8c6aed11-5d85-47a7-98cd-91e8dd441d09"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=33ae5639-431e-4d01-a725-10b55fbf19fa"
Information	2/28/2019 12:08:43 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b6238cce-6111-4dd8-8e3a-2131345b41f4"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c2a811a-4066-41d9-b01e-6ce41951b612"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=96180128-4419-4223-81d5-455dd1f0b8cc"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f327bfa6-fbf6-4ed0-a4a9-bd4bfad744a4"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32d48179-769f-42a7-8318-85183032750f"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=1967969c-5f25-4bbb-b0b6-9b2a85956b82"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bf09d53d-e057-4345-8573-3258cbcdcef0"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f108a725-53a3-46f8-8638-671f21618af5"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=df86036a-2bdd-40fb-95e5-7758a40888a0"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8ad24e6d-710c-41c0-8442-09360563915a"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=528bab55-7786-4356-b2ad-88fe1b8fcac8"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=36c02486-b646-42e2-9d99-3f004cdf9417"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=63ac7ebe-fee9-4a32-837b-e3d4eb8aab69"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8c2ef592-c12b-4876-8763-5b9b86e92d9d"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43734373-179d-47a1-b21b-115629169450"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1d9e42c5-325e-442c-98af-fd1302c4df68"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=958bc5e1-123f-4165-bb7b-8e858e8e919e"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cbf0d3b-d091-4f6c-8e5d-4efbaec5b4e3"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=95f0af3a-edc0-44f3-b03c-b3bdf67435ca"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=48f8ef71-4394-4531-a9de-2ec4c93ec39a"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=22628221-fa6f-46db-a6d9-67311a301511"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f7934e94-8990-4c80-b27a-5cf7eece2fa5"
Information	2/28/2019 12:08:42 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5ad7f835-c1e8-44f5-baba-8bf994ae4d24"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4526aedc-292b-409a-bc96-f9d1d2381942"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c133fb56-f2de-4574-898a-41d104a45835"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2602ff5c-19a2-4669-b1cc-ab7fd12dfc65"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=450354ce-2bb6-4774-a3b6-f7a0a9b987d4"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2c74a701-ffb9-4c86-9f1e-73bf1fd37556"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=76be9fd9-fea4-4be2-ba66-936c33de5275"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9b5f2cc3-88de-453f-869e-57da5482fb25"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb57abfe-5d2d-4c1f-ba4a-61a7115e0583"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7b206866-c2d5-4e3e-9653-cd48d22d876e"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1664fd49-b86a-42c8-aac6-dee2ca9fd24a"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=4b14f23e-05d8-4f50-84c1-50bc046e8af4"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=707c0c99-18c9-4857-b121-a2294a144fdd"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	2/28/2019 12:08:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	2/28/2019 12:08:40 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	2/28/2019 12:08:40 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/28/2019 12:08:39 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/28/2019 12:08:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/28/2019 12:08:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 12:08:38 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/28/2019 12:08:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 12:07:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2019 12:07:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 12:07:55 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	2/28/2019 12:07:54 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (SMBServer)
License Id=72265f61-2ae6-0dcf-a15e-3495ea6c5663"
Information	2/28/2019 12:07:54 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (RasBase)
License Id=dbbd74e8-8a74-f200-ab6a-d5ac9689cb5b"
Information	2/28/2019 12:07:53 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	2/28/2019 12:07:53 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	2/28/2019 12:07:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 12:07:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 12:06:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎28T06:36:44.597316400Z.
Information	2/28/2019 12:06:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9179.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/28/2019 12:05:42 PM	Service1	0	None	Service started successfully.
Error	2/28/2019 12:05:31 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/28/2019 12:05:31 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/28/2019 12:05:06 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/28/2019 12:05:05 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/28/2019 12:05:04 PM	PostgreSQL	0	None	"2019-02-28 12:05:04 IST LOG:  redirecting log output to logging collector process
2019-02-28 12:05:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/28/2019 12:04:56 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/28/2019 12:04:45 PM	MTAService	0	None	Service started successfully.
Information	2/28/2019 12:04:45 PM	MTAService.OnStart	0	None	12:04:44 PM - Waiting for user to Logon
Information	2/28/2019 12:04:37 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:37 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/28/2019 12:04:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/28/2019 12:04:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/28/2019 12:04:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/28/2019 12:04:36 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/28/2019 12:04:35 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/28/2019 12:04:34 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/28/2019 12:04:32 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/28/2019 12:04:31 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:31 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:31 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4780 at 2/28/2019 11:30:32 AM (local) 2/28/2019 6:00:32 AM (UTC). This is an informational message only; no user action is required.
Information	2/28/2019 12:04:30 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/28/2019 12:04:29 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/28/2019 12:04:28 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/28/2019 12:04:28 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/28/2019 12:04:28 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/28/2019 12:04:28 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4828.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/28/2019 12:04:20 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	2/28/2019 12:02:25 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	2/28/2019 12:02:23 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/28/2019 12:00:53 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/28/2019 12:00:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/28/2019 12:00:53 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/28/2019 11:30:44 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/28/2019 11:30:42 AM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	2/28/2019 11:30:32 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	2/28/2019 11:30:21 AM	McLogEvent	257	None	The scan of C:\Windows\winsxs\wow64_microsoft-windows-ole-automation_31bf3856ad364e35_6.1.7601.24117_none_26072a225f95c653\oleaut32.dll has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9179.0000.
Warning	2/28/2019 11:29:34 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 22204 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Warning	2/28/2019 11:29:32 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 180 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2640 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 22204 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/28/2019 11:29:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/28/2019 11:29:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/28/2019 11:29:30 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/28/2019 11:29:13 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2019 11:29:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/28/2019 11:29:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2019 11:29:12 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎28T05:59:12.648810900Z.
Information	2/28/2019 11:29:11 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2019 11:29:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/28/2019 11:29:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/28/2019 11:29:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2019 11:29:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎28T05:59:10.948400000Z.
Information	2/28/2019 11:28:15 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎02‎-‎28T05:58:15.647542000Z.
Information	2/28/2019 11:28:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎28T05:58:15.647542000Z.
Warning	2/28/2019 11:00:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 10:15:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 10:15:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/28/2019 10:15:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2019 10:08:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9bf4a11-3b12-11e9-a1da-204747d02364
Report Status: 0"
Error	2/28/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/28/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22105)(?)])(1 )(2 )]

"
Information	2/28/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22105)(?)])(1 )(2 )]

"
Information	2/28/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22105)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/28/2019 9:24:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 9:08:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/28/2019 9:07:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	2/28/2019 7:24:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 6:15:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/28/2019 5:36:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 5:08:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bfd8179a-3ae8-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/28/2019 3:45:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 3:32:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 3:32:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:24Z. Reason: GVLK.
Information	2/28/2019 3:27:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2019 3:27:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 3:27:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 3:27:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 3:25:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2019 3:25:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:35Z. Reason: GVLK.
Information	2/28/2019 3:20:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2019 3:20:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2019 3:20:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2019 3:20:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2019 2:30:31 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/28/2019 2:27:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	2/28/2019 2:14:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/28/2019 2:12:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/28/2019 12:26:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2019 12:08:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d615dbd6-3abe-11e9-a1da-204747d02364
Report Status: 0"
Information	2/28/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/27/2019 11:23:35 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/27/2019 10:31:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 10:15:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2019 10:15:07 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/27/2019 10:14:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2019 9:58:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2019 9:58:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:08Z. Reason: GVLK.
Information	2/27/2019 9:53:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2019 9:53:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 9:53:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2019 9:53:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/27/2019 8:50:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 8:21:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎27T14:46:07.919917000Z.
Information	2/27/2019 8:21:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎27T14:46:09.031028100Z.
Information	2/27/2019 8:21:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎27T14:46:05.454670500Z.
Information	2/27/2019 8:21:21 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{E275C470-4DE7-487D-9FF8-B51E1DC27EC3}v4.21.8406.0\CsAgent.msi. Client Process Id: 21328.
Information	2/27/2019 8:21:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.21.8406.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	2/27/2019 8:21:20 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	2/27/2019 8:16:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎27T14:46:09.031028100Z.
Information	2/27/2019 8:16:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎27T14:46:07.919917000Z.
Information	2/27/2019 8:16:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎27T14:46:05.454670500Z.
Information	2/27/2019 8:16:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{E275C470-4DE7-487D-9FF8-B51E1DC27EC3}v4.21.8406.0\CsAgent.msi. Client Process Id: 21328.
Information	2/27/2019 7:08:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec3b7c9a-3a94-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/27/2019 7:03:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 6:14:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2019 5:26:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 3:40:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2019 3:40:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:09Z. Reason: GVLK.
Information	2/27/2019 3:35:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2019 3:35:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 3:35:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2019 3:35:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/27/2019 3:34:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 2:14:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2019 2:08:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 024f70a4-3a6b-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/27/2019 1:34:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 1:30:23 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/27/2019 1:30:23 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/27/2019 12:06:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9179.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/27/2019 11:45:03 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/27/2019 11:44:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 30942, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Warning	2/27/2019 11:43:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 11:43:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/27/2019 11:43:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/27/2019 10:19:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2019 10:19:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:19Z. Reason: GVLK.
Information	2/27/2019 10:14:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2019 10:14:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/27/2019 10:14:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2019 10:14:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 10:14:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2019 10:14:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2019 10:14:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2019 9:44:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/27/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/27/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23545)(?)])(1 )(2 )]

"
Information	2/27/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/27/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23545)(?)])(1 )(2 )]

"
Information	2/27/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23545)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 9:11:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/27/2019 9:11:01 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/27/2019 9:08:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18827d99-3a41-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/27/2019 8:04:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/27/2019 6:32:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 6:14:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2019 4:59:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 4:08:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e9970cc-3a17-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/27/2019 3:28:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 3:25:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2019 3:25:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:00Z. Reason: GVLK.
Information	2/27/2019 3:15:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2019 3:15:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 3:15:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2019 3:15:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2019 3:11:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2019 3:11:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:52Z. Reason: GVLK.
Information	2/27/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2019 3:06:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2019 2:14:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2019 1:53:27 AM	VPSX Printer Driver Management	5	None	"VPSX Printer Driver Management Utility information:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          
Printer (GEPRINT on vpsx) deleted
"
Warning	2/27/2019 1:34:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/26/2019 11:52:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 11:23:26 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/26/2019 11:08:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4562192f-39ed-11e9-a1da-204747d02364
Report Status: 0"
Information	2/26/2019 10:14:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2019 10:14:17 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/26/2019 10:13:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2019 9:53:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/26/2019 8:19:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/26/2019 6:39:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 6:13:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2019 6:08:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b8835f1-39c3-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/26/2019 4:55:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 4:23:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2019 4:23:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:18Z. Reason: GVLK.
Information	2/26/2019 4:18:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2019 4:18:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 4:18:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2019 4:18:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/26/2019 3:23:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 2:13:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/26/2019 1:39:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:39:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/26/2019 1:33:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 1:24:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:24:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 1:17:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:17:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 1:14:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:13:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 1:10:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:10:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 1:08:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71a3414f-3999-11e9-a1da-204747d02364
Report Status: 0"
Information	2/26/2019 1:05:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:05:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 1:02:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 1:01:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 12:46:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 12:46:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 12:25:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 12:24:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 12:16:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 12:15:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 12:08:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9178.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/26/2019 12:05:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 12:04:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 11:43:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 11:43:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/26/2019 11:40:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 11:06:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 11:06:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 11:04:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/26/2019 11:03:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/26/2019 10:13:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2019 10:13:26 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/26/2019 10:13:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2019 10:09:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/26/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/26/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24985)(?)])(1 )(2 )]

"
Information	2/26/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/26/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24985)(?)])(1 )(2 )]

"
Information	2/26/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24985)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 9:10:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/26/2019 9:08:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	2/26/2019 8:24:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 8:08:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 87beaf7f-396f-11e9-a1da-204747d02364
Report Status: 0"
Information	2/26/2019 7:06:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2019 7:06:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:56Z. Reason: GVLK.
Information	2/26/2019 7:01:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2019 7:01:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 7:01:55 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	2/26/2019 7:01:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2019 7:01:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/26/2019 6:57:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎26T01:19:18.076479900Z.
Information	2/26/2019 6:57:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎26T01:19:03.401479900Z.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 24068.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/26/2019 6:57:29 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4483451. Installation success or error status: 0.
Information	2/26/2019 6:57:29 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4483451' installed successfully.
Information	2/26/2019 6:55:46 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:46 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:45 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:45 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:45 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:44 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:44 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:44 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:43 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:43 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:29 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00007.log
Information	2/26/2019 6:55:28 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	2/26/2019 6:55:28 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/26/2019 6:55:21 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/26/2019 6:55:21 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:15 AM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	2/26/2019 6:55:15 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	2/26/2019 6:55:15 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00006.log
Information	2/26/2019 6:55:14 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	2/26/2019 6:55:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/26/2019 6:55:09 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/26/2019 6:55:09 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:55:03 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/26/2019 6:55:03 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/26/2019 6:54:56 AM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	2/26/2019 6:54:56 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	2/26/2019 6:54:50 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:54:49 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:54:37 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5716.
Information	2/26/2019 6:54:36 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5716.
Information	2/26/2019 6:54:36 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5716.
Information	2/26/2019 6:54:36 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4956.
Information	2/26/2019 6:54:36 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5716.
Information	2/26/2019 6:54:36 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4956.
Information	2/26/2019 6:51:47 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/26/2019 6:49:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 25708) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 15676) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 11740) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5716) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4956) cannot be restarted - Application SID does not match Conductor SID..
Information	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎26T01:19:18.076479900Z.
Information	2/26/2019 6:49:18 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 25708) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 15676) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 11740) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5716) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/26/2019 6:49:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4956) cannot be restarted - Application SID does not match Conductor SID..
Information	2/26/2019 6:49:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎26T01:19:03.401479900Z.
Information	2/26/2019 6:49:02 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 24068.
Information	2/26/2019 6:38:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/26/2019 6:31:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎26T00:56:51.587479900Z.
Information	2/26/2019 6:31:56 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 27420.
Information	2/26/2019 6:31:56 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/26/2019 6:31:56 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	2/26/2019 6:31:56 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4483470. Installation success or error status: 0.
Information	2/26/2019 6:31:56 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4483470' installed successfully.
Information	2/26/2019 6:29:33 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/26/2019 6:28:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2019 6:28:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:57Z. Reason: GVLK.
Information	2/26/2019 6:27:31 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:30 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:30 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:30 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:29 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:29 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:29 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:27:28 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/26/2019 6:26:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎26T00:56:51.587479900Z.
Information	2/26/2019 6:26:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 27420.
Information	2/26/2019 6:23:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2019 6:23:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 6:23:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2019 6:23:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/26/2019 6:13:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2019 5:12:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 3:42:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2019 3:42:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:34Z. Reason: GVLK.
Information	2/26/2019 3:37:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2019 3:37:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 3:37:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2019 3:37:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/26/2019 3:34:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2019 3:34:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:06Z. Reason: GVLK.
Information	2/26/2019 3:29:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2019 3:29:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2019 3:29:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2019 3:29:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/26/2019 3:12:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 3:07:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e086875-3945-11e9-a1da-204747d02364
Report Status: 0"
Information	2/26/2019 2:13:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2019 1:40:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/26/2019 12:00:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 11:23:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/25/2019 10:26:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 10:26:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:52Z. Reason: GVLK.
Information	2/25/2019 10:21:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 10:21:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 10:21:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 10:21:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2019 10:13:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 10:13:22 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	2/25/2019 10:13:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 10:12:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 10:07:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b4322efe-391b-11e9-a1da-204747d02364
Report Status: 0"
Information	2/25/2019 9:14:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 9:14:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:34Z. Reason: GVLK.
Information	2/25/2019 9:09:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 9:09:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 9:09:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 9:09:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/25/2019 8:17:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2019 6:29:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 6:12:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 5:33:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 5:33:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T05:00:05Z. Reason: GVLK.
Information	2/25/2019 5:28:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 5:28:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 5:28:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 5:28:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2019 5:07:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ca5e0fd4-38f1-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/25/2019 4:34:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2019 2:54:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 2:38:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 2:37:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 2:35:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 2:35:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 2:12:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/25/2019 1:19:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 1:19:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 1:07:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 1:06:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/25/2019 1:04:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 12:58:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 12:58:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 12:53:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 12:52:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 12:36:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9177.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/25/2019 12:32:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 12:31:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 12:07:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e0bc1bd7-38c7-11e9-a1da-204747d02364
Report Status: 0"
Information	2/25/2019 12:06:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 12:06:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 12:05:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 12:04:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 11:51:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 11:51:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 11:34:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 11:33:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/25/2019 11:15:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 11:04:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2019 11:04:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2019 10:35:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 10:35:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-03-04T04:59:35Z. Reason: GVLK.
Information	2/25/2019 10:30:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 10:30:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 10:30:34 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/02/25 05:00"
Information	2/25/2019 10:30:33 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/02/25 05:00, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/25/2019 10:25:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 10:25:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 10:25:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 10:25:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2019 10:12:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 10:12:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/25/2019 10:12:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 9:31:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/25/2019 9:31:26 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	2/25/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/25/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26425)(?)])(1 )(2 )]

"
Information	2/25/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/25/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26425)(?)])(1 )(2 )]

"
Information	2/25/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/25/2019 9:23:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2019 7:40:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 7:07:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6fe5664-389d-11e9-a1da-204747d02364
Report Status: 0"
Information	2/25/2019 6:12:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/25/2019 5:45:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 4:57:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 4:57:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:29Z. Reason: GVLK.
Information	2/25/2019 4:52:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 4:52:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 4:52:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 4:52:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2019 4:49:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2019 4:49:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:35Z. Reason: GVLK.
Information	2/25/2019 4:44:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2019 4:44:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2019 4:44:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2019 4:44:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/25/2019 4:12:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2019 2:20:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 2:12:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2019 2:07:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d3eed0f-3874-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/25/2019 12:42:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2019 12:32:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/25/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/24/2019 10:56:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 10:12:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2019 10:12:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/24/2019 10:12:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2019 9:46:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2019 9:46:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:08Z. Reason: GVLK.
Information	2/24/2019 9:41:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2019 9:41:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 9:41:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2019 9:41:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/24/2019 9:17:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 9:07:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 23862769-384a-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/24/2019 7:33:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 6:12:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/24/2019 5:44:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/24/2019 4:09:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 4:07:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 39bbcc21-3820-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/24/2019 2:20:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 2:11:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2019 1:44:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/24/2019 1:41:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/24/2019 1:34:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/24/2019 1:30:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/24/2019 1:30:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/24/2019 1:30:21 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/24/2019 1:30:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/24/2019 1:19:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/24/2019 1:17:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/24/2019 12:24:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9176.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Warning	2/24/2019 12:20:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 11:54:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/24/2019 11:53:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/24/2019 11:32:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/24/2019 11:32:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/24/2019 11:32:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/24/2019 11:31:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 30803, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/24/2019 11:30:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/24/2019 11:07:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4fd9f99e-37f6-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/24/2019 10:14:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 10:12:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2019 10:12:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/24/2019 10:11:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	2/24/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/24/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27865)(?)])(1 )(2 )]

"
Information	2/24/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/24/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27865)(?)])(1 )(2 )]

"
Information	2/24/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27865)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 9:21:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2019 9:21:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:03Z. Reason: GVLK.
Information	2/24/2019 9:16:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2019 9:16:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 9:16:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2019 9:16:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/24/2019 8:26:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/24/2019 6:45:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 6:11:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2019 6:07:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 66175c3d-37cc-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/24/2019 5:11:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 4:37:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2019 4:37:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:37Z. Reason: GVLK.
Information	2/24/2019 4:32:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2019 4:32:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 4:32:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2019 4:32:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/24/2019 4:08:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2019 4:08:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:26Z. Reason: GVLK.
Information	2/24/2019 4:03:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2019 4:03:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 4:03:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2019 4:03:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/24/2019 4:00:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2019 4:00:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:26Z. Reason: GVLK.
Information	2/24/2019 3:55:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2019 3:55:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2019 3:55:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2019 3:55:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/24/2019 3:11:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 2:11:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/24/2019 1:24:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2019 1:07:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c6195a9-37a2-11e9-a1da-204747d02364
Report Status: 0"
Information	2/24/2019 12:04:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/24/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/23/2019 11:52:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/23/2019 10:12:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 10:11:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2019 10:11:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/23/2019 10:11:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/23/2019 8:36:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 8:07:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 929a50b4-3778-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/23/2019 6:37:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 6:11:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2019 5:07:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/23/2019 5:07:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:54:54Z. Reason: GVLK.
Information	2/23/2019 5:02:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/23/2019 5:02:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2019 5:02:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2019 5:02:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/23/2019 4:39:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 3:07:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8d4e09e-374e-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/23/2019 3:01:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 2:10:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/23/2019 1:01:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 12:20:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9175.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Warning	2/23/2019 11:22:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 10:10:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2019 10:10:56 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/23/2019 10:10:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2019 10:07:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: befde35e-3724-11e9-a1da-204747d02364
Report Status: 0"
Error	2/23/2019 9:30:20 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/23/2019 9:30:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29305)(?)])(1 )(2 )]

"
Information	2/23/2019 9:30:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/23/2019 9:30:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29305)(?)])(1 )(2 )]

"
Information	2/23/2019 9:30:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29305)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/23/2019 9:30:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 8:29:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/23/2019 8:29:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:02Z. Reason: GVLK.
Information	2/23/2019 8:24:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/23/2019 8:24:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2019 8:24:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2019 8:24:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/23/2019 7:55:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 6:10:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/23/2019 5:58:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 5:07:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5028536-36fa-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/23/2019 4:03:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 3:29:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/23/2019 3:29:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:22Z. Reason: GVLK.
Information	2/23/2019 3:24:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/23/2019 3:24:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2019 3:24:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2019 3:24:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/23/2019 3:21:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/23/2019 3:21:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:29Z. Reason: GVLK.
Information	2/23/2019 3:16:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/23/2019 3:16:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2019 3:16:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2019 3:16:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/23/2019 2:14:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 2:10:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/23/2019 12:22:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2019 12:07:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eae13713-36d0-11e9-a1da-204747d02364
Report Status: 0"
Information	2/23/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/22/2019 11:23:37 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/22/2019 11:10:04 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/22/2019 11:10:02 PM	ESENT	102	General	Windows (20048) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/22/2019 11:04:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17268.
Information	2/22/2019 11:04:59 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	2/22/2019 11:04:59 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	2/22/2019 11:04:59 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.010.20098). Installation success or error status: 0.
Information	2/22/2019 11:04:59 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.010.20098)' installed successfully.
Information	2/22/2019 11:04:44 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/22/2019 11:04:44 PM	ESENT	103	General	Windows (6580) Windows: The database engine stopped the instance (0).
Information	2/22/2019 11:04:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17268.
Information	2/22/2019 11:02:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 16728.
Information	2/22/2019 11:02:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	2/22/2019 11:02:53 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	2/22/2019 11:02:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 16728.
Warning	2/22/2019 10:46:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 10:10:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2019 10:10:20 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/22/2019 10:10:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2019 9:11:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 9:04:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 9:04:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:54:56Z. Reason: GVLK.
Information	2/22/2019 8:59:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2019 8:59:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 8:59:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 8:59:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/22/2019 7:39:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 7:39:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:27Z. Reason: GVLK.
Information	2/22/2019 7:34:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2019 7:34:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 7:34:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 7:34:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2019 7:14:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 7:07:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 00c55fcd-36a7-11e9-a1da-204747d02364
Report Status: 0"
Information	2/22/2019 6:52:36 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9174.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : RDN/Generic Downloader.x (ED)
"
Information	2/22/2019 6:10:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2019 5:40:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 3:17:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2019 3:17:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 3:17:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/22/2019 2:15:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 2:09:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2019 2:07:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 16d0a10e-367d-11e9-a1da-204747d02364
Report Status: 0"
Information	2/22/2019 1:45:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 1:40:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2019 1:40:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 1:40:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/22/2019 12:53:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9174.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/22/2019 12:06:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/22/2019 12:05:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/22/2019 12:05:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/22/2019 12:04:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/22/2019 12:01:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 11:56:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30598)(?)])(1 )(2 )]

"
Information	2/22/2019 11:56:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/22/2019 11:56:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30598)(?)])(1 )(2 )]

"
Information	2/22/2019 11:56:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30598)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 11:56:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2019 11:56:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 11:56:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/22/2019 11:26:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 11:21:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 11:21:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:23Z. Reason: GVLK.
Information	2/22/2019 11:21:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2019 11:21:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 11:21:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/22/2019 11:16:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2019 11:16:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 11:16:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 11:16:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2019 11:07:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 10:44:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/22/2019 10:23:06 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/22/2019 10:09:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2019 10:09:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/22/2019 10:09:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/22/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/22/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30745)(?)])(1 )(2 )]

"
Information	2/22/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/22/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30745)(?)])(1 )(2 )]

"
Information	2/22/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30745)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/22/2019 9:14:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 9:07:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2b4fb0b8-3653-11e9-a1da-204747d02364
Report Status: 0"
Error	2/22/2019 8:01:10 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (32) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190214_154554.log
"
Error	2/22/2019 8:01:10 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190214_154554.log
"
Warning	2/22/2019 7:41:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 6:09:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2019 6:00:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 4:50:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 4:50:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:44Z. Reason: GVLK.
Information	2/22/2019 4:45:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2019 4:45:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 4:45:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 4:45:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/22/2019 4:41:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2019 4:41:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:10Z. Reason: GVLK.
Information	2/22/2019 4:36:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2019 4:36:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2019 4:36:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2019 4:36:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2019 4:20:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 4:07:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 418de70e-3629-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/22/2019 2:42:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 2:09:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2019 12:46:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/21/2019 11:59:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 11:59:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:06Z. Reason: GVLK.
Information	2/21/2019 11:54:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2019 11:54:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 11:54:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 11:54:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 11:26:29 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/21/2019 11:07:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57d2fe7a-35ff-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/21/2019 10:47:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 10:09:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2019 10:09:48 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/21/2019 10:09:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2019 8:58:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/21/2019 6:59:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 6:09:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2019 6:07:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6e11f415-35d5-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/21/2019 5:11:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 3:46:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 3:46:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:09Z. Reason: GVLK.
Information	2/21/2019 3:41:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2019 3:41:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 3:41:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 3:41:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/21/2019 3:36:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 2:09:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2019 1:43:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 1:30:14 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/21/2019 1:30:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/21/2019 1:07:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 844c5cdb-35ab-11e9-a1da-204747d02364
Report Status: 0"
Information	2/21/2019 12:21:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9173.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/21/2019 11:46:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 11:40:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/21/2019 11:40:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/21/2019 11:40:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 30885, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/21/2019 11:39:37 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/21/2019 10:30:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 10:25:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/21/2019 10:25:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎21T04:55:26.663550300Z.
Information	2/21/2019 10:25:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎21T04:55:24.480332000Z.
Information	2/21/2019 10:25:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/21/2019 10:25:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 10:25:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 10:09:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2019 10:09:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/21/2019 10:08:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2019 9:57:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/21/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/21/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32185)(?)])(1 )(2 )]

"
Information	2/21/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/21/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32185)(?)])(1 )(2 )]

"
Information	2/21/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/21/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 9:21:27 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 9:16:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]

"
Information	2/21/2019 9:16:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/21/2019 9:16:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]

"
Information	2/21/2019 9:16:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 9:16:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]

"
Information	2/21/2019 9:16:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/21/2019 9:16:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]

"
Information	2/21/2019 9:16:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32199)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32201)(?)])(1 )(2 )]

"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32201)(?)])(1 )(2 )]

"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32201)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/21/2019 9:14:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 9:14:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 9:05:07 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/21/2019 9:04:47 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/21/2019 8:53:32 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/21/2019 8:53:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎21T03:23:31.375983100Z.
Information	2/21/2019 8:53:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎21T03:23:29.118983100Z.
Warning	2/21/2019 8:22:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 8:07:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9a6b7d77-3581-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/21/2019 6:38:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 6:08:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2019 4:45:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 4:45:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:41Z. Reason: GVLK.
Warning	2/21/2019 4:40:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 4:40:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2019 4:40:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 4:40:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 4:40:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 4:38:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2019 4:38:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:27Z. Reason: GVLK.
Information	2/21/2019 4:33:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2019 4:33:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2019 4:33:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2019 4:33:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2019 3:07:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b097db97-3557-11e9-a1da-204747d02364
Report Status: 0"
Information	2/21/2019 2:59:16 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/21/2019 2:56:08 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/21/2019 2:41:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 2:08:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2019 12:51:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/20/2019 11:14:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 11:09:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/20/2019 10:23:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 10:23:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:06Z. Reason: GVLK.
Information	2/20/2019 10:18:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 10:18:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 10:18:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 10:18:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/20/2019 10:09:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 10:09:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/20/2019 10:08:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 10:07:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c6a29390-352d-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/20/2019 9:38:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 8:15:41 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/20/2019 8:15:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎20T14:45:40.371126300Z.
Information	2/20/2019 8:15:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎20T14:45:38.192908500Z.
Warning	2/20/2019 8:03:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/20/2019 6:18:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 6:08:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 5:49:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 5:44:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33130)(?)])(1 )(2 )]

"
Information	2/20/2019 5:44:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/20/2019 5:44:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33130)(?)])(1 )(2 )]

"
Information	2/20/2019 5:44:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33130)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 5:44:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/20/2019 5:44:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 5:44:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/20/2019 5:18:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎20T11:48:41.252868100Z.
Information	2/20/2019 5:18:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎20T11:48:30.080751000Z.
Information	2/20/2019 5:07:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dcc93b17-3503-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/20/2019 4:25:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 4:03:06 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.4.0.12141. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	2/20/2019 4:03:06 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	2/20/2019 4:03:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎20T10:27:42.510995800Z.
Information	2/20/2019 4:03:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{8C8A2EE0-CC9C-4920-9CDC-8499F906F8E5}\4Sight™ 2.msi. Client Process Id: 13096.
Information	2/20/2019 3:57:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎20T10:27:42.510995800Z.
Information	2/20/2019 3:57:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{8C8A2EE0-CC9C-4920-9CDC-8499F906F8E5}\4Sight™ 2.msi. Client Process Id: 13096.
Information	2/20/2019 2:51:16 PM	McLogEvent	257	None	The scan of D:\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9172.0000.
Warning	2/20/2019 2:49:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 2:08:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/20/2019 1:00:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 12:56:36 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9172.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/20/2019 12:07:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f2d87f86-34d9-11e9-a1da-204747d02364
Report Status: 0"
Information	2/20/2019 11:50:55 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/20/2019 11:50:54 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎20T06:20:54.580690700Z.
Information	2/20/2019 11:50:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎20T06:20:52.572489900Z.
Information	2/20/2019 11:32:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/20/2019 11:31:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/20/2019 11:05:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 10:08:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 10:08:51 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/20/2019 10:08:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 9:38:42 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 13272) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 1620) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 8476) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11944) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6584) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 4852) cannot be restarted - Application SID does not match Conductor SID..
Information	2/20/2019 9:38:41 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎20T04:08:41.379449900Z.
Information	2/20/2019 9:38:39 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎20T04:08:39.172229200Z.
Information	2/20/2019 9:36:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/20/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/20/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33625)(?)])(1 )(2 )]

"
Information	2/20/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/20/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33625)(?)])(1 )(2 )]

"
Information	2/20/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33625)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/20/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/20/2019 9:08:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 9:02:11 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/20/2019 9:01:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/20/2019 8:53:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 8:53:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:28Z. Reason: GVLK.
Information	2/20/2019 8:48:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 8:48:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 8:48:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 8:48:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/20/2019 7:32:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 7:07:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0908e3b5-34b0-11e9-a1da-204747d02364
Report Status: 0"
Information	2/20/2019 6:08:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 5:59:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 5:59:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:30Z. Reason: GVLK.
Information	2/20/2019 5:54:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 5:54:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 5:54:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 5:54:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/20/2019 5:43:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/20/2019 3:55:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 3:11:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 3:11:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:54:52Z. Reason: GVLK.
Information	2/20/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 3:06:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 3:06:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/20/2019 3:06:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 3:06:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:10Z. Reason: GVLK.
Information	2/20/2019 3:01:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 3:01:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 3:01:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 3:01:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/20/2019 2:53:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/20/2019 2:51:00 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	2/20/2019 2:13:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2019 2:13:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:29Z. Reason: GVLK.
Information	2/20/2019 2:08:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2019 2:08:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2019 2:08:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2019 2:08:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/20/2019 2:08:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/20/2019 2:07:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f315b79-3486-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/20/2019 2:03:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/20/2019 12:10:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/19/2019 11:17:05 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/19/2019 10:38:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 10:08:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 10:08:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/19/2019 10:08:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 9:07:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35475651-345c-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/19/2019 8:58:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/19/2019 7:24:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 6:28:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2019 6:28:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:33Z. Reason: GVLK.
Information	2/19/2019 6:23:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2019 6:23:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2019 6:23:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 6:23:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/19/2019 6:08:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 6:08:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/19/2019 6:07:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/19/2019 5:45:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 4:48:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/19/2019 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34632)(?)])(1 )(2 )]

"
Information	2/19/2019 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/19/2019 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34632)(?)])(1 )(2 )]

"
Information	2/19/2019 4:43:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34632)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2019 4:43:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/19/2019 4:43:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 4:43:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/19/2019 4:07:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b799071-3432-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/19/2019 3:46:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 3:22:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2019 3:22:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:19Z. Reason: GVLK.
Information	2/19/2019 3:17:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2019 3:17:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2019 3:17:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 3:17:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/19/2019 2:15:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 2:07:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/19/2019 12:44:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 12:20:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/19/2019 12:19:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/19/2019 12:05:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9171.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/19/2019 11:07:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61da08b3-3408-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/19/2019 10:51:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 10:07:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 10:07:39 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/19/2019 10:07:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 10:01:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/19/2019 10:01:17 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/19/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/19/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/19/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35065)(?)])(1 )(2 )]

"
Information	2/19/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/19/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35065)(?)])(1 )(2 )]

"
Information	2/19/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/19/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 9:30:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/19/2019 9:09:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 9:09:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/19/2019 9:04:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/19/2019 9:04:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 9:04:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/19/2019 7:10:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 6:07:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2019 6:07:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 781caf0f-33de-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/19/2019 5:37:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 4:16:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2019 4:16:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:25Z. Reason: GVLK.
Information	2/19/2019 4:07:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2019 4:07:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2019 4:07:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2019 4:07:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/19/2019 3:43:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 2:07:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/19/2019 1:59:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2019 1:06:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e6e1a3b-33b4-11e9-a1da-204747d02364
Report Status: 0"
Information	2/19/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/19/2019 12:01:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 11:12:32 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/18/2019 10:07:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2019 10:07:15 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/18/2019 10:07:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2019 10:06:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 8:51:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2019 8:51:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:55:05Z. Reason: GVLK.
Information	2/18/2019 8:46:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2019 8:46:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 8:46:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 8:46:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/18/2019 8:08:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 8:06:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4a94656-338a-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/18/2019 6:25:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 6:06:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2019 4:50:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 3:06:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: badee962-3360-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/18/2019 2:56:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 2:06:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2019 1:30:15 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/18/2019 1:30:15 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	2/18/2019 1:17:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 12:53:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9170.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/18/2019 12:02:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/18/2019 12:02:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/18/2019 11:33:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 11:32:07 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/18/2019 11:31:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 30741, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/18/2019 11:31:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/18/2019 11:31:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/18/2019 10:46:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/18/2019 10:46:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/18/2019 10:30:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2019 10:30:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-25T04:54:51Z. Reason: GVLK.
Information	2/18/2019 10:25:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 10:25:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 10:25:50 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/02/18 04:55"
Information	2/18/2019 10:25:49 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/02/18 04:55, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/18/2019 10:20:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2019 10:20:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 10:20:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 10:20:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/18/2019 10:06:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d10ea2e2-3336-11e9-a1da-204747d02364
Report Status: 0"
Information	2/18/2019 10:06:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2019 10:06:30 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/18/2019 10:06:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2019 9:42:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 9:35:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/18/2019 9:30:17 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/18/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36505)(?)])(1 )(2 )]

"
Information	2/18/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/18/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36505)(?)])(1 )(2 )]

"
Information	2/18/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 9:30:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/18/2019 9:30:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 9:30:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/18/2019 9:22:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2019 9:22:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:46Z. Reason: GVLK.
Information	2/18/2019 9:21:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/18/2019 9:21:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/18/2019 9:17:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2019 9:17:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 9:17:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 9:17:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/18/2019 8:57:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/18/2019 8:52:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/18/2019 8:52:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 8:52:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/18/2019 7:56:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 6:47:23 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/18/2019 6:06:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2019 5:57:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 5:06:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e74eff52-330c-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/18/2019 4:07:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 3:29:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2019 3:29:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:50Z. Reason: GVLK.
Information	2/18/2019 3:16:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2019 3:16:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2019 3:16:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2019 3:16:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/18/2019 2:30:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 2:06:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2019 12:32:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2019 12:06:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fd823358-32e2-11e9-a1da-204747d02364
Report Status: 0"
Information	2/18/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/17/2019 10:55:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 10:06:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2019 10:06:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/17/2019 10:06:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2019 9:12:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2019 7:13:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 7:06:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 13ce4fd2-32b9-11e9-a1da-204747d02364
Report Status: 0"
Information	2/17/2019 6:51:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/17/2019 6:51:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:19Z. Reason: GVLK.
Information	2/17/2019 6:46:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/17/2019 6:46:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2019 6:46:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2019 6:46:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/17/2019 6:05:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2019 5:22:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2019 3:49:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 2:06:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27ae7af2-328f-11e9-a1da-204747d02364
Report Status: 0"
Information	2/17/2019 2:05:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2019 1:59:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 12:45:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9169.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/17/2019 12:05:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2019 10:07:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 10:05:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2019 10:05:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/17/2019 10:05:57 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/17/2019 10:05:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/17/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/17/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37945)(?)])(1 )(2 )]

"
Information	2/17/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/17/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37945)(?)])(1 )(2 )]

"
Information	2/17/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/17/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/17/2019 9:06:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3df69e72-3265-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/17/2019 8:36:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 7:20:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/17/2019 7:20:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:34Z. Reason: GVLK.
Information	2/17/2019 7:15:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/17/2019 7:15:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2019 7:15:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2019 7:15:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/17/2019 6:42:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 6:05:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2019 5:01:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 4:22:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/17/2019 4:22:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:27Z. Reason: GVLK.
Information	2/17/2019 4:13:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/17/2019 4:13:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2019 4:13:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2019 4:13:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/17/2019 4:06:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 543ac155-323b-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/17/2019 3:22:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 2:05:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2019 1:22:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/16/2019 11:22:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 11:06:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a6412ab-3211-11e9-a1da-204747d02364
Report Status: 0"
Information	2/16/2019 10:05:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2019 10:05:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/16/2019 10:05:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2019 9:48:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/16/2019 7:55:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 6:20:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2019 6:20:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:25Z. Reason: GVLK.
Information	2/16/2019 6:15:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2019 6:15:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2019 6:15:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 6:15:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/16/2019 6:06:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 80aa7fff-31e7-11e9-a1da-204747d02364
Report Status: 0"
Information	2/16/2019 6:05:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2019 5:56:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 5:08:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2019 5:08:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:33Z. Reason: GVLK.
Information	2/16/2019 5:03:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2019 5:03:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2019 5:03:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 5:03:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/16/2019 4:46:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/16/2019 4:41:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2019 4:41:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 4:41:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/16/2019 4:19:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 3:24:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2019 3:24:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:52Z. Reason: GVLK.
Information	2/16/2019 3:19:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2019 3:19:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2019 3:19:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 3:19:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/16/2019 2:44:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 2:05:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2019 1:09:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 1:06:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96def6b5-31bd-11e9-a1da-204747d02364
Report Status: 0"
Information	2/16/2019 12:24:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9168.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/16/2019 11:25:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 10:05:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2019 10:05:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/16/2019 10:05:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/16/2019 9:32:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/16/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/16/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39385)(?)])(1 )(2 )]

"
Information	2/16/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/16/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39385)(?)])(1 )(2 )]

"
Information	2/16/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/16/2019 8:06:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: acfcd2c2-3193-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/16/2019 7:42:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 6:04:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2019 6:03:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/16/2019 4:28:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 3:09:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2019 3:09:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:49Z. Reason: GVLK.
Information	2/16/2019 3:06:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c32b4fc3-3169-11e9-a1da-204747d02364
Report Status: 0"
Information	2/16/2019 3:00:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2019 3:00:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2019 3:00:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2019 3:00:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/16/2019 2:50:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 2:04:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2019 1:17:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/15/2019 11:43:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 11:23:12 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/15/2019 11:20:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 11:20:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:28Z. Reason: GVLK.
Information	2/15/2019 11:15:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 11:15:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 11:15:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 11:15:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 10:06:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d96f1c7f-313f-11e9-a1da-204747d02364
Report Status: 0"
Information	2/15/2019 10:04:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2019 10:04:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/15/2019 10:04:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/15/2019 9:45:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/15/2019 8:11:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 7:06:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	2/15/2019 6:19:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 6:04:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/15/2019 4:44:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 4:39:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2019 4:39:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 4:39:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 4:37:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/15/2019 4:23:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/15/2019 2:39:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 2:06:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/15/2019 2:06:22 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/15/2019 2:01:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2019 1:01:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/15/2019 1:01:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/15/2019 12:58:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 12:31:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/15/2019 12:31:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/15/2019 12:14:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9167.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/15/2019 12:03:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a515f271-30eb-11e9-a1da-204747d02364
Report Status: 0"
Information	2/15/2019 11:44:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/15/2019 11:44:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 30720, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/15/2019 11:42:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/15/2019 11:42:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	2/15/2019 11:03:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 10:39:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 10:34:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40761)(?)])(1 )(2 )]

"
Information	2/15/2019 10:34:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/15/2019 10:34:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40761)(?)])(1 )(2 )]

"
Information	2/15/2019 10:34:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40761)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 10:34:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2019 10:34:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 10:34:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 10:26:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 10:26:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:01Z. Reason: GVLK.
Information	2/15/2019 10:21:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 10:21:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 10:21:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 10:21:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 10:06:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 10:03:35 AM	McLogEvent	257	None	The scan of C:\Users\212558710\Downloads\testingWhizSetup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9166.0000.
Information	2/15/2019 10:01:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2019 10:01:48 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/15/2019 10:01:47 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 110

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	2/15/2019 10:01:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40794)(?)])(1 )(2 )]

"
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40794)(?)])(1 )(2 )]

"
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40794)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2019 10:01:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 10:01:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/15/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/15/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40825)(?)])(1 )(2 )]

"
Information	2/15/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/15/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40825)(?)])(1 )(2 )]

"
Information	2/15/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 9:30:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/15/2019 9:08:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/15/2019 7:21:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 7:03:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb5a5633-30c1-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/15/2019 5:44:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 4:59:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 4:59:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:33Z. Reason: GVLK.
Information	2/15/2019 4:54:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 4:54:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 4:54:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 4:54:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 4:54:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 4:54:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:05Z. Reason: GVLK.
Information	2/15/2019 4:49:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 4:49:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 4:49:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 4:49:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/15/2019 3:48:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 3:46:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 3:46:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:20Z. Reason: GVLK.
Information	2/15/2019 3:41:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 3:41:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 3:41:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 3:41:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2019 2:29:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2019 2:29:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:04Z. Reason: GVLK.
Information	2/15/2019 2:24:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2019 2:24:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2019 2:24:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2019 2:24:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/15/2019 2:11:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 2:03:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d174f499-3097-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/15/2019 12:31:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/14/2019 11:03:48 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/14/2019 11:03:48 PM	ESENT	102	General	Windows (6580) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/14/2019 11:01:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 11000.
Information	2/14/2019 11:01:49 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20091. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	2/14/2019 11:01:49 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	2/14/2019 11:01:49 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20091. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.010.20091). Installation success or error status: 0.
Information	2/14/2019 11:01:49 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.010.20091)' installed successfully.
Information	2/14/2019 11:01:47 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/14/2019 11:01:20 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/14/2019 11:01:20 PM	ESENT	103	General	Windows (9232) Windows: The database engine stopped the instance (0).
Information	2/14/2019 11:01:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 11000.
Information	2/14/2019 11:00:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12512.
Information	2/14/2019 11:00:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20091. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	2/14/2019 11:00:33 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	2/14/2019 11:00:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12512.
Warning	2/14/2019 10:46:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2019 9:04:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 9:03:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7b11f3a-306d-11e9-a1da-204747d02364
Report Status: 0"
Warning	2/14/2019 7:11:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 6:39:11 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/14/2019 5:16:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 4:03:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fdf0d075-3043-11e9-a1da-204747d02364
Report Status: 0"
Information	2/14/2019 3:57:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2019 3:57:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:48Z. Reason: GVLK.
Information	2/14/2019 3:56:02 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/14/2019 3:52:00 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/14/2019 3:51:04 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/14/2019 3:51:02 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/14/2019 3:50:59 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/14/2019 3:50:56 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/14/2019 3:50:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9166.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	2/14/2019 3:50:35 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/14/2019 3:50:28 PM	ESENT	302	Logging/Recovery	Windows (9232) Windows: The database engine has successfully completed recovery steps.
Information	2/14/2019 3:50:26 PM	ESENT	301	Logging/Recovery	Windows (9232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/14/2019 3:50:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2019 3:50:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2019 3:50:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2019 3:50:05 PM	ESENT	301	Logging/Recovery	Windows (9232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS017BA.log.
Information	2/14/2019 3:50:05 PM	ESENT	300	Logging/Recovery	Windows (9232) Windows: The database engine is initiating recovery steps.
Information	2/14/2019 3:50:04 PM	ESENT	102	General	Windows (9232) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/14/2019 3:50:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41885)(?)])(1 )(2 )]

"
Information	2/14/2019 3:50:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/14/2019 3:50:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41885)(?)])(1 )(2 )]

"
Information	2/14/2019 3:49:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41885)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2019 3:49:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/14/2019 3:49:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2019 3:49:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/14/2019 3:49:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/14/2019 3:49:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: McShield
P2: mcshield.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1004630b-3042-11e9-a1da-204747d02364
Report Status: 0"
Information	2/14/2019 3:49:44 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	2/14/2019 3:49:44 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	2/14/2019 3:47:41 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/14/2019 3:47:41 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	2/14/2019 3:47:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2019 3:47:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/14/2019 3:47:30 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/14/2019 3:47:29 PM	PostgreSQL	0	None	"2019-02-14 15:47:29 IST LOG:  redirecting log output to logging collector process
2019-02-14 15:47:29 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/14/2019 3:47:28 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/14/2019 3:47:27 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/14/2019 3:47:15 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/14/2019 3:46:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/14/2019 3:46:38 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/14/2019 3:46:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/14/2019 3:46:37 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/14/2019 3:46:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/14/2019 3:46:36 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:36 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/14/2019 3:46:36 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/14/2019 3:46:36 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/14/2019 3:46:36 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4876 at 2/14/2019 3:42:53 PM (local) 2/14/2019 10:12:53 AM (UTC). This is an informational message only; no user action is required.
Information	2/14/2019 3:46:33 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/14/2019 3:46:32 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/14/2019 3:46:32 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/14/2019 3:46:32 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/14/2019 3:46:32 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/14/2019 3:46:32 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/14/2019 3:46:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/14/2019 3:46:31 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/14/2019 3:46:31 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/14/2019 3:46:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/14/2019 3:46:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4780.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/14/2019 3:46:20 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/14/2019 3:45:31 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/14/2019 3:45:09 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	2/14/2019 3:45:09 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/14/2019 3:44:45 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/14/2019 3:43:08 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/14/2019 3:44:45 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/14/2019 3:44:45 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/14/2019 3:42:54 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	2/14/2019 3:42:53 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	2/14/2019 3:42:50 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	2/14/2019 3:42:48 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 520 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1664 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/14/2019 3:42:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/14/2019 3:42:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/14/2019 3:42:47 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	2/14/2019 3:31:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2019 1:37:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 12:57:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2019 12:32:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2019 12:31:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/14/2019 12:28:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9166.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/14/2019 12:16:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2019 12:16:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/14/2019 12:13:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2019 12:13:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/14/2019 11:59:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2019 11:58:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/14/2019 11:58:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2019 11:58:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/14/2019 11:50:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 11:03:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0fa58d6d-301a-11e9-a173-204747d02364
Report Status: 0"
Information	2/14/2019 10:37:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/14/2019 10:36:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/14/2019 10:07:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/14/2019 9:30:17 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/14/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42265)(?)])(1 )(2 )]

"
Information	2/14/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/14/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42265)(?)])(1 )(2 )]

"
Information	2/14/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2019 9:11:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/14/2019 8:56:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2019 8:56:49 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/14/2019 8:56:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/14/2019 8:35:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2019 6:50:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 6:16:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2019 6:16:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:18Z. Reason: GVLK.
Information	2/14/2019 6:11:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2019 6:11:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2019 6:11:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2019 6:11:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/14/2019 6:03:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25e3bf29-2ff0-11e9-a173-204747d02364
Report Status: 0"
Information	2/14/2019 4:56:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/14/2019 4:53:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 4:23:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2019 4:23:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:50Z. Reason: GVLK.
Information	2/14/2019 4:15:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2019 4:15:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2019 4:15:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2019 4:15:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/14/2019 3:14:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 2:20:01 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/14/2019 2:17:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/14/2019 1:18:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2019 1:03:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3c2b65b7-2fc6-11e9-a173-204747d02364
Report Status: 0"
Information	2/14/2019 12:56:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/13/2019 11:38:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/13/2019 10:04:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 8:56:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2019 8:56:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/13/2019 8:56:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2019 8:31:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 8:03:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 527a1a52-2f9c-11e9-a173-204747d02364
Report Status: 0"
Warning	2/13/2019 6:48:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/13/2019 5:13:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 4:56:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2019 4:44:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 4:44:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:00Z. Reason: GVLK.
Information	2/13/2019 4:38:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 4:38:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 4:38:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 4:38:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2019 4:37:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 4:37:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:01Z. Reason: GVLK.
Information	2/13/2019 4:32:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 4:32:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 4:32:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 4:32:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2019 3:30:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 3:30:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:48Z. Reason: GVLK.
Information	2/13/2019 3:25:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 3:25:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 3:25:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 3:25:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/13/2019 3:19:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 3:18:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 3:18:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:23Z. Reason: GVLK.
Information	2/13/2019 3:13:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 3:13:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 3:13:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 3:13:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2019 3:08:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎02‎-‎13T09:38:15.482774600Z.
Information	2/13/2019 3:08:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎13T09:38:15.482774600Z.
Information	2/13/2019 3:03:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 689eae32-2f72-11e9-a173-204747d02364
Report Status: 0"
Information	2/13/2019 2:40:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 2:39:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 2:26:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 2:26:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 1:40:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 1:40:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 1:32:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 1:32:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 1:29:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 1:29:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/13/2019 1:18:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 1:12:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 1:12:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 12:55:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/13/2019 12:46:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 12:46:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 12:32:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 12:32:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 12:29:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 12:29:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/13/2019 12:16:55 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 26056 did not respond and is being forcibly terminated {filter host process 25116}. 

Information	2/13/2019 12:16:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9165.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/13/2019 12:09:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎02‎-‎13T06:39:46.712774600Z.
Information	2/13/2019 12:09:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎13T06:39:46.712774600Z.
Information	2/13/2019 11:58:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 11:57:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 11:43:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 11:43:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/13/2019 11:38:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 11:16:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 11:15:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 10:59:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2019 10:59:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/13/2019 10:03:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7e75e9b5-2f48-11e9-a173-204747d02364
Report Status: 0"
Warning	2/13/2019 9:58:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/13/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/13/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43705)(?)])(1 )(2 )]

"
Information	2/13/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/13/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43705)(?)])(1 )(2 )]

"
Information	2/13/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 9:19:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/13/2019 9:17:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/13/2019 9:10:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/13/2019 8:56:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2019 8:56:13 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/13/2019 8:55:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2019 8:16:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/13/2019 6:41:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 5:03:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94f84cf1-2f1e-11e9-a173-204747d02364
Report Status: 0"
Information	2/13/2019 4:55:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2019 4:42:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 3:37:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 3:37:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:23Z. Reason: GVLK.
Information	2/13/2019 3:32:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 3:32:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 3:32:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 3:32:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2019 3:31:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 3:31:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:46Z. Reason: GVLK.
Information	2/13/2019 3:26:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 3:26:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 3:26:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 3:26:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/13/2019 3:07:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/13/2019 1:16:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2019 12:55:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2019 12:16:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2019 12:16:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:48Z. Reason: GVLK.
Information	2/13/2019 12:11:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2019 12:11:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2019 12:11:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2019 12:11:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2019 12:03:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ab3c7127-2ef4-11e9-a173-204747d02364
Report Status: 0"
Information	2/13/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/12/2019 11:21:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/12/2019 9:38:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 8:55:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2019 8:55:46 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/12/2019 8:55:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2019 7:41:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 7:03:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1781275-2eca-11e9-a173-204747d02364
Report Status: 0"
Warning	2/12/2019 6:08:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 4:55:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2019 4:55:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/12/2019 4:55:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2019 4:41:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824311644_12904858485179372851977161391459945045.msi. Client Process Id: 22296.
Information	2/12/2019 4:41:01 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	2/12/2019 4:41:01 PM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	2/12/2019 4:41:01 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/12/2019 4:38:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824311644_12904858485179372851977161391459945045.msi. Client Process Id: 22296.
Warning	2/12/2019 4:36:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/12/2019 2:37:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 2:03:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7c9d981-2ea0-11e9-a173-204747d02364
Report Status: 0"
Information	2/12/2019 1:39:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 1:39:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 1:30:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/12/2019 1:30:02 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/12/2019 12:56:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9164.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/12/2019 12:54:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	2/12/2019 12:54:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 12:49:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:48:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 12:45:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:44:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 12:43:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:42:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 12:40:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:40:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 12:37:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:36:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 12:25:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2019 12:25:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 12:25:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/12/2019 12:22:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 12:21:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 11:51:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 11:51:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 11:40:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 70, Compared: 30580, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/12/2019 11:39:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/12/2019 11:21:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 11:20:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/12/2019 11:00:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 10:56:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/12/2019 10:56:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/12/2019 10:28:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 10:28:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:15Z. Reason: GVLK.
Information	2/12/2019 10:23:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2019 10:23:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2019 10:23:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 10:23:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 9:30:23 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/12/2019 9:30:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/12/2019 9:30:21 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	2/12/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/12/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45145)(?)])(1 )(2 )]

"
Information	2/12/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45145)(?)])(1 )(2 )]

"
Information	2/12/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/12/2019 9:13:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/12/2019 9:09:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 9:03:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee1afdb1-2e76-11e9-a173-204747d02364
Report Status: 0"
Information	2/12/2019 9:01:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/12/2019 8:55:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2019 8:55:07 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/12/2019 8:54:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2019 7:33:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/12/2019 5:52:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 5:29:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 5:29:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:29Z. Reason: GVLK.
Information	2/12/2019 5:26:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 5:24:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2019 5:24:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2019 5:24:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 5:24:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2019 5:21:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2019 5:21:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 5:21:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/12/2019 4:54:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2019 4:45:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 4:45:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:13Z. Reason: GVLK.
Information	2/12/2019 4:40:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2019 4:40:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2019 4:40:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 4:40:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/12/2019 4:19:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 4:03:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 04678c4e-2e4d-11e9-a173-204747d02364
Report Status: 0"
Information	2/12/2019 3:14:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2019 3:14:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:51:05Z. Reason: GVLK.
Information	2/12/2019 3:04:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2019 3:04:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2019 3:04:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2019 3:04:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/12/2019 2:37:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 12:54:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2019 12:43:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/11/2019 11:05:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 11:03:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1aba86c5-2e23-11e9-a173-204747d02364
Report Status: 0"
Error	2/11/2019 9:32:53 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	2/11/2019 9:07:47 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎11T15:37:43.823075100Z.
Information	2/11/2019 9:07:47 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎11T15:37:42.236075100Z.
Information	2/11/2019 9:07:47 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{D62D18A3-E141-42C2-BCDF-CD19FE286CA0}v4.17.8056.0\CsDeviceControl.msi. Client Process Id: 1720.
Information	2/11/2019 9:07:47 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Device Control. Product Version: 4.17.8056.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	2/11/2019 9:07:47 PM	MsiInstaller	11707	None	Product: CrowdStrike Device Control -- Installation completed successfully.
Information	2/11/2019 9:07:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎11T15:37:43.823075100Z.
Information	2/11/2019 9:07:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎11T15:37:42.236075100Z.
Information	2/11/2019 9:07:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎11T15:34:07.171075100Z.
Information	2/11/2019 9:07:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎02‎-‎11T15:34:03.817075100Z.
Information	2/11/2019 9:07:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{D62D18A3-E141-42C2-BCDF-CD19FE286CA0}v4.17.8056.0\CsDeviceControl.msi. Client Process Id: 1720.
Information	2/11/2019 9:07:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{FFD76AC8-44C8-4D67-BFD0-9676674AE1EB}v4.20.8305.0\CsAgent.msi. Client Process Id: 1720.
Information	2/11/2019 9:07:41 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.20.8305.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	2/11/2019 9:07:41 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	2/11/2019 9:07:37 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0xd0000450)
Error	2/11/2019 9:07:34 PM	Application Error	1000	(100)	"Faulting application name: svchost.exe_PcaSvc, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x000000000002a365
Faulting process id: 0x4ac
Faulting application start time: 0x01d4b6b8c2b41cbc
Faulting application path: C:\Windows\System32\svchost.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: f31b1f2f-2e12-11e9-a173-204747d02364"
Information	2/11/2019 9:04:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎11T15:34:07.171075100Z.
Information	2/11/2019 9:04:06 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	2/11/2019 9:04:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎02‎-‎11T15:34:03.817075100Z.
Information	2/11/2019 9:04:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{FFD76AC8-44C8-4D67-BFD0-9676674AE1EB}v4.20.8305.0\CsAgent.msi. Client Process Id: 1720.
Information	2/11/2019 8:54:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 8:54:31 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/11/2019 8:54:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/11/2019 7:41:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 6:03:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31052f0a-2df9-11e9-a173-204747d02364
Report Status: 0"
Warning	2/11/2019 5:49:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 4:53:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 4:32:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2019 4:32:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:51Z. Reason: GVLK.
Information	2/11/2019 4:27:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2019 4:27:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 4:27:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2019 4:27:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/11/2019 3:53:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/11/2019 2:12:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 2:02:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/11/2019 2:02:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/11/2019 1:03:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47589eb4-2dcf-11e9-a173-204747d02364
Report Status: 0"
Information	2/11/2019 12:53:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 12:45:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/11/2019 12:45:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/11/2019 12:45:03 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9163.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/11/2019 12:22:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/11/2019 10:47:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 10:26:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2019 10:26:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-18T04:50:36Z. Reason: GVLK.
Information	2/11/2019 10:21:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 10:21:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 10:21:35 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/02/11 04:51"
Information	2/11/2019 10:21:34 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/02/11 04:51, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/11/2019 10:16:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2019 10:16:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 10:16:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2019 10:16:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/11/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/11/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46585)(?)])(1 )(2 )]

"
Information	2/11/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/11/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46585)(?)])(1 )(2 )]

"
Information	2/11/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/11/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/11/2019 9:10:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/11/2019 8:54:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 8:53:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 8:53:46 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/11/2019 8:53:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 8:03:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d7b7e9f-2da5-11e9-a173-204747d02364
Report Status: 0"
Warning	2/11/2019 7:00:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/11/2019 5:13:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 4:53:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/11/2019 4:27:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2019 4:27:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:30Z. Reason: GVLK.
Information	2/11/2019 4:17:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2019 4:17:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 4:17:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2019 4:17:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/11/2019 3:34:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 3:03:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 739b59d7-2d7b-11e9-a173-204747d02364
Report Status: 0"
Information	2/11/2019 2:55:43 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Tuesday, January 15, 2019 11:40:58 PM.
Information	2/11/2019 2:55:43 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=ANCERT Certificados CGN V2, O=Agencia Notarial de Certificacion S.L.U. - CIF B83395988, C=ES> Sha1 thumbprint: <7EB1A0429BE5F428AC2B93971D7C8448A536070C>.
Warning	2/11/2019 1:47:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 1:17:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2019 1:17:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:40Z. Reason: GVLK.
Information	2/11/2019 1:12:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2019 1:12:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2019 1:12:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2019 1:12:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2019 12:53:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/11/2019 12:13:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/11/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/10/2019 10:21:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 10:03:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89f8bb19-2d51-11e9-a173-204747d02364
Report Status: 0"
Information	2/10/2019 8:53:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2019 8:53:07 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/10/2019 8:53:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/10/2019 8:42:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 8:07:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/10/2019 8:07:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/10/2019 6:43:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 5:03:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0409079-2d27-11e9-a173-204747d02364
Report Status: 0"
Warning	2/10/2019 5:00:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 4:52:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/10/2019 3:20:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 2:49:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2019 2:49:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:27Z. Reason: GVLK.
Information	2/10/2019 2:44:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2019 2:44:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2019 2:44:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 2:44:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/10/2019 1:37:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 1:26:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/10/2019 1:21:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/10/2019 1:21:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 1:21:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/10/2019 12:52:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2019 12:24:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9162.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/10/2019 12:05:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 12:03:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b68918bb-2cfd-11e9-a173-204747d02364
Report Status: 0"
Warning	2/10/2019 10:32:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 9:58:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/10/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/10/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48025)(?)])(1 )(2 )]

"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48025)(?)])(1 )(2 )]

"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48025)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/10/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/10/2019 8:52:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2019 8:52:57 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/10/2019 8:52:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/10/2019 8:40:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 7:03:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccb6f2d5-2cd3-11e9-a173-204747d02364
Report Status: 0"
Warning	2/10/2019 6:45:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 6:37:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2019 6:37:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:25Z. Reason: GVLK.
Information	2/10/2019 6:32:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2019 6:32:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2019 6:32:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 6:32:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/10/2019 5:11:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2019 5:11:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:31Z. Reason: GVLK.
Information	2/10/2019 5:06:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2019 5:06:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2019 5:06:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 5:06:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/10/2019 5:03:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 4:52:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2019 4:12:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2019 4:12:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:00Z. Reason: GVLK.
Information	2/10/2019 4:02:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2019 4:02:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2019 4:02:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2019 4:02:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/10/2019 3:05:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 2:02:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e31d7865-2ca9-11e9-a173-204747d02364
Report Status: 0"
Warning	2/10/2019 1:27:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2019 12:52:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/9/2019 11:36:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/9/2019 9:57:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 9:02:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f9581f6c-2c7f-11e9-a173-204747d02364
Report Status: 0"
Information	2/9/2019 8:52:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2019 8:52:16 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/9/2019 8:51:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/9/2019 8:16:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/9/2019 6:20:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 4:51:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/9/2019 4:43:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 4:02:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0fb7e99c-2c56-11e9-a173-204747d02364
Report Status: 0"
Warning	2/9/2019 3:02:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 1:30:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/9/2019 1:30:21 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/9/2019 1:30:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	2/9/2019 1:15:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 12:52:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2019 12:52:10 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/9/2019 12:51:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2019 12:35:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9161.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/9/2019 11:51:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2019 11:51:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:36Z. Reason: GVLK.
Information	2/9/2019 11:46:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2019 11:46:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2019 11:46:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2019 11:46:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2019 11:30:42 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 2, Compared: 30489, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/9/2019 11:30:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	2/9/2019 11:18:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 11:02:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25feb42b-2c2c-11e9-a173-204747d02364
Report Status: 0"
Information	2/9/2019 10:37:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/9/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/9/2019 9:32:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 9:31:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/9/2019 9:31:12 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/9/2019 9:31:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	2/9/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/9/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49465)(?)])(1 )(2 )]

"
Information	2/9/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49465)(?)])(1 )(2 )]

"
Information	2/9/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49465)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2019 9:30:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2019 9:20:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/9/2019 9:20:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/9/2019 8:51:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2019 8:51:38 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/9/2019 8:51:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/9/2019 7:39:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 7:35:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2019 7:30:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2019 7:30:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2019 7:30:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2019 6:36:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/9/2019 6:36:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/9/2019 6:02:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3c34d715-2c02-11e9-a173-204747d02364
Report Status: 0"
Warning	2/9/2019 5:52:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 5:00:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2019 5:00:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:45:57Z. Reason: GVLK.
Information	2/9/2019 4:51:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2019 4:51:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2019 4:51:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2019 4:51:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2019 4:51:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/9/2019 3:53:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/9/2019 2:04:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 1:02:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 526cc5fb-2bd8-11e9-a173-204747d02364
Report Status: 0"
Information	2/9/2019 12:51:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/9/2019 12:15:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/8/2019 10:19:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 8:51:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2019 8:51:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/8/2019 8:51:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2019 8:33:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2019 8:33:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:48Z. Reason: GVLK.
Information	2/8/2019 8:28:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2019 8:28:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2019 8:28:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2019 8:28:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/8/2019 8:23:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 8:02:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 68acfb47-2bae-11e9-a173-204747d02364
Report Status: 0"
Warning	2/8/2019 6:34:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 4:51:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/8/2019 4:42:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 3:02:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7eef0540-2b84-11e9-a173-204747d02364
Report Status: 0"
Warning	2/8/2019 2:47:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/8/2019 1:14:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 1:01:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2019 1:01:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:45Z. Reason: GVLK.
Information	2/8/2019 12:56:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2019 12:56:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2019 12:56:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2019 12:56:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2019 12:50:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2019 12:49:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9160.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/8/2019 11:22:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 10:02:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9534ded0-2b5a-11e9-a173-204747d02364
Report Status: 0"
Warning	2/8/2019 9:35:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/8/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/8/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50905)(?)])(1 )(2 )]

"
Information	2/8/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50905)(?)])(1 )(2 )]

"
Information	2/8/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/8/2019 9:12:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/8/2019 9:00:03 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/8/2019 8:59:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/8/2019 8:51:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2019 8:51:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/8/2019 8:50:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/8/2019 7:37:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/8/2019 5:47:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 5:02:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ab5bb41b-2b30-11e9-a173-204747d02364
Report Status: 0"
Information	2/8/2019 4:52:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2019 4:52:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:01Z. Reason: GVLK.
Information	2/8/2019 4:50:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2019 4:42:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2019 4:42:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2019 4:42:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2019 4:42:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/8/2019 3:50:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 2:08:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2019 2:08:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:45:59Z. Reason: GVLK.
Warning	2/8/2019 2:04:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 2:03:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2019 2:03:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2019 2:03:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2019 2:03:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2019 12:50:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/8/2019 12:04:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/8/2019 12:02:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c18a0d4a-2b06-11e9-a173-204747d02364
Report Status: 0"
Warning	2/7/2019 10:08:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 8:50:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/7/2019 8:50:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/7/2019 8:50:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2019 8:24:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 7:34:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2019 7:29:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2019 7:29:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2019 7:29:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/7/2019 7:02:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7fc4915-2adc-11e9-a173-204747d02364
Report Status: 0"
Warning	2/7/2019 6:35:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/7/2019 5:04:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 4:50:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2019 3:25:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 2:02:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee2b781c-2ab2-11e9-a173-204747d02364
Report Status: 0"
Warning	2/7/2019 1:55:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 12:59:37 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9159.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/7/2019 12:49:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2019 12:23:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 11:23:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2019 11:23:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:33Z. Reason: GVLK.
Information	2/7/2019 11:20:43 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/7/2019 11:20:22 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/7/2019 11:18:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2019 11:18:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2019 11:18:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2019 11:18:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/7/2019 10:51:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 10:30:12 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/7/2019 9:53:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/7/2019 9:53:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/7/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/7/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/7/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52345)(?)])(1 )(2 )]

"
Information	2/7/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52345)(?)])(1 )(2 )]

"
Information	2/7/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/7/2019 9:17:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 9:02:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 045f9e6c-2a89-11e9-a173-204747d02364
Report Status: 0"
Information	2/7/2019 8:50:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/7/2019 8:49:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/7/2019 8:49:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2019 7:46:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/7/2019 6:00:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 5:04:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2019 5:04:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:16Z. Reason: GVLK.
Information	2/7/2019 4:59:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2019 4:59:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2019 4:59:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2019 4:59:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2019 4:49:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2019 4:24:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 4:02:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1abe8a32-2a5f-11e9-a173-204747d02364
Report Status: 0"
Information	2/7/2019 4:02:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2019 4:02:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:35Z. Reason: GVLK.
Information	2/7/2019 3:52:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2019 3:52:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2019 3:52:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2019 3:52:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2019 2:42:15 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/7/2019 2:39:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/7/2019 2:38:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/7/2019 1:02:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2019 12:49:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/7/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/6/2019 11:05:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 11:02:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3102b738-2a35-11e9-a173-204747d02364
Report Status: 0"
Warning	2/6/2019 9:06:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 8:49:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 8:49:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/6/2019 8:49:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/6/2019 7:11:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 6:02:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4740ea0b-2a0b-11e9-a173-204747d02364
Report Status: 0"
Information	2/6/2019 5:35:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2019 5:30:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2019 5:30:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 5:30:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/6/2019 5:17:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 4:56:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2019 4:56:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:14Z. Reason: GVLK.
Information	2/6/2019 4:51:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2019 4:51:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2019 4:51:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 4:51:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2019 4:49:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/6/2019 3:17:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 1:33:57 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/6/2019 1:33:57 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	2/6/2019 1:28:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 1:02:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d884b76-29e1-11e9-a173-204747d02364
Report Status: 0"
Information	2/6/2019 12:49:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 12:49:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/6/2019 12:48:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 12:22:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9158.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/6/2019 11:45:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 30369, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/6/2019 11:43:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	2/6/2019 11:37:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/6/2019 9:56:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 9:54:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/6/2019 9:54:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/6/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/6/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/6/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53785)(?)])(1 )(2 )]

"
Information	2/6/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53785)(?)])(1 )(2 )]

"
Information	2/6/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/6/2019 9:15:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/6/2019 9:14:50 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/6/2019 9:01:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/6/2019 8:49:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 8:49:16 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/6/2019 8:48:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 8:02:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 738e57dc-29b7-11e9-a173-204747d02364
Report Status: 0"
Warning	2/6/2019 7:58:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/6/2019 6:08:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 4:48:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 4:42:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2019 4:42:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:21Z. Reason: GVLK.
Information	2/6/2019 4:37:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2019 4:37:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2019 4:37:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 4:37:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2019 4:36:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2019 4:36:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:46Z. Reason: GVLK.
Information	2/6/2019 4:31:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2019 4:31:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2019 4:31:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 4:31:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/6/2019 4:25:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 4:18:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2019 4:18:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:38Z. Reason: GVLK.
Information	2/6/2019 4:13:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2019 4:13:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2019 4:13:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2019 4:13:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2019 3:02:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89dd592c-298d-11e9-a173-204747d02364
Report Status: 0"
Warning	2/6/2019 2:35:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/6/2019 1:00:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2019 12:48:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/5/2019 11:24:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 10:02:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a022916d-2963-11e9-a173-204747d02364
Report Status: 0"
Warning	2/5/2019 9:40:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 8:49:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/5/2019 8:49:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/5/2019 8:48:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/5/2019 7:44:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/5/2019 5:58:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 5:02:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b64549ba-2939-11e9-a173-204747d02364
Report Status: 0"
Information	2/5/2019 4:55:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 4:55:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:47Z. Reason: GVLK.
Information	2/5/2019 4:50:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2019 4:50:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 4:50:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 4:50:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/5/2019 4:48:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/5/2019 4:28:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 3:38:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 3:33:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54862)(?)])(1 )(2 )]

"
Information	2/5/2019 3:33:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/5/2019 3:33:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54862)(?)])(1 )(2 )]

"
Information	2/5/2019 3:33:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54862)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 3:33:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2019 3:33:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 3:33:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/5/2019 3:05:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎02‎-‎05T09:30:06.295776100Z.
Error	2/5/2019 3:01:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/5/2019 3:00:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎02‎-‎05T09:30:06.295776100Z.
Warning	2/5/2019 2:35:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 1:32:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 1:27:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2019 1:27:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 1:27:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/5/2019 12:58:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 12:53:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55021)(?)])(1 )(2 )]

"
Information	2/5/2019 12:53:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/5/2019 12:53:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55021)(?)])(1 )(2 )]

"
Information	2/5/2019 12:53:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55021)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 12:53:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2019 12:53:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 12:53:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/5/2019 12:53:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 12:48:36 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 593

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 655

Information	2/5/2019 12:48:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/5/2019 12:47:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]

"
Information	2/5/2019 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/5/2019 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]

"
Information	2/5/2019 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2019 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 12:47:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/5/2019 12:41:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 12:36:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9157.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	2/5/2019 12:02:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cc787eac-290f-11e9-a173-204747d02364
Report Status: 0"
Information	2/5/2019 11:10:05 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/5/2019 10:57:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 10:54:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/5/2019 10:54:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/5/2019 10:53:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/5/2019 10:15:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/5/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/5/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/5/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55225)(?)])(1 )(2 )]

"
Information	2/5/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/5/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55225)(?)])(1 )(2 )]

"
Information	2/5/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55225)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/5/2019 9:13:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 8:59:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	2/5/2019 7:20:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 7:02:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e2be187b-28e5-11e9-a173-204747d02364
Report Status: 0"
Information	2/5/2019 6:53:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/5/2019 6:53:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 6:53:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:01Z. Reason: GVLK.
Information	2/5/2019 6:48:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2019 6:48:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 6:48:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 6:48:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/5/2019 5:48:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 5:09:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 5:09:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:51Z. Reason: GVLK.
Information	2/5/2019 5:04:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2019 5:04:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 5:04:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 5:04:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/5/2019 5:04:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2019 5:04:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:01Z. Reason: GVLK.
Information	2/5/2019 4:59:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2019 4:59:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2019 4:59:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2019 4:58:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/5/2019 3:51:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 2:53:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/5/2019 2:09:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 2:02:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f904191b-28bb-11e9-a173-204747d02364
Report Status: 0"
Warning	2/5/2019 12:35:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/4/2019 10:53:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2019 10:53:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/4/2019 10:53:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2019 10:46:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 9:02:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f5eeaa6-2892-11e9-a173-204747d02364
Report Status: 0"
Warning	2/4/2019 8:53:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/4/2019 7:12:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 6:53:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2019 5:31:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 4:02:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25a38cdf-2868-11e9-a173-204747d02364
Report Status: 0"
Warning	2/4/2019 3:55:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 3:23:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 3:23:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:46:25Z. Reason: GVLK.
Information	2/4/2019 3:18:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2019 3:18:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 3:18:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 3:18:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/4/2019 3:14:28 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/4/2019 2:53:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2019 2:19:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 2:16:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9156.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/4/2019 12:22:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 11:02:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3af7583e-283e-11e9-a173-204747d02364
Report Status: 0"
Information	2/4/2019 10:53:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2019 10:53:32 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/4/2019 10:53:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2019 10:46:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 10:21:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 10:21:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-11T04:45:55Z. Reason: GVLK.
Information	2/4/2019 10:16:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 10:16:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 10:16:54 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/02/04 04:46"
Information	2/4/2019 10:16:53 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/02/04 04:46, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/4/2019 9:58:28 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 9:56:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2019 9:56:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 9:56:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 9:56:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2019 9:53:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/4/2019 9:53:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 9:53:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/4/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/4/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/4/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56665)(?)])(1 )(2 )]

"
Information	2/4/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56665)(?)])(1 )(2 )]

"
Information	2/4/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56665)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/4/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/4/2019 9:22:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/4/2019 9:21:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/4/2019 9:21:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/4/2019 9:03:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/4/2019 7:12:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 6:53:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2019 6:02:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 513d0bee-2814-11e9-a173-204747d02364
Report Status: 0"
Warning	2/4/2019 5:13:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 4:31:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 4:31:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:04Z. Reason: GVLK.
Information	2/4/2019 4:26:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2019 4:26:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 4:26:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 4:26:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2019 3:58:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 3:58:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:10Z. Reason: GVLK.
Information	2/4/2019 3:48:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2019 3:48:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 3:48:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 3:48:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/4/2019 3:38:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 2:52:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2019 2:06:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 1:02:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6788120a-27ea-11e9-a173-204747d02364
Report Status: 0"
Warning	2/4/2019 12:16:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2019 12:12:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2019 12:12:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:50Z. Reason: GVLK.
Information	2/4/2019 12:07:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2019 12:07:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2019 12:07:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2019 12:07:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/3/2019 10:52:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/3/2019 10:52:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/3/2019 10:52:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/3/2019 10:24:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/3/2019 8:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 8:02:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7ddde837-27c0-11e9-a173-204747d02364
Report Status: 0"
Warning	2/3/2019 6:55:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 6:52:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/3/2019 5:12:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 3:59:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2019 3:59:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:58Z. Reason: GVLK.
Information	2/3/2019 3:54:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2019 3:54:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2019 3:54:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2019 3:54:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/3/2019 3:28:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 3:02:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 942c51d1-2796-11e9-a173-204747d02364
Report Status: 0"
Information	2/3/2019 2:52:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/3/2019 1:36:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 1:30:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/3/2019 1:30:21 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/3/2019 1:30:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/3/2019 12:38:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9155.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/3/2019 11:49:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 11:30:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 30280, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/3/2019 11:30:26 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/3/2019 10:52:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/3/2019 10:52:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/3/2019 10:52:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/3/2019 10:52:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/3/2019 10:07:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 10:02:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa6b1ee3-276c-11e9-a173-204747d02364
Report Status: 0"
Information	2/3/2019 9:54:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/3/2019 9:49:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2019 9:49:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2019 9:49:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/3/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/3/2019 9:30:33 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	2/3/2019 9:30:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/3/2019 9:30:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	2/3/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/3/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58105)(?)])(1 )(2 )]

"
Information	2/3/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58105)(?)])(1 )(2 )]

"
Information	2/3/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58105)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/3/2019 8:13:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 6:51:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/3/2019 6:22:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 5:02:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0bedcaf-2742-11e9-a173-204747d02364
Report Status: 0"
Warning	2/3/2019 4:45:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 3:49:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2019 3:49:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:48Z. Reason: GVLK.
Information	2/3/2019 3:40:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2019 3:40:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2019 3:40:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2019 3:40:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/3/2019 2:55:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 2:51:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/3/2019 1:20:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2019 1:20:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:24Z. Reason: GVLK.
Information	2/3/2019 1:15:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2019 1:15:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2019 1:15:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2019 1:15:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/3/2019 1:10:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/3/2019 12:02:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d70d7484-2718-11e9-a173-204747d02364
Report Status: 0"
Warning	2/2/2019 11:21:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 10:51:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/2/2019 10:51:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/2/2019 10:51:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/2/2019 9:48:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/2/2019 8:11:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 7:02:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed5bd994-26ee-11e9-a173-204747d02364
Report Status: 0"
Information	2/2/2019 6:51:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/2/2019 6:18:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/2/2019 4:36:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 2:50:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/2/2019 2:43:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 2:03:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/2/2019 2:03:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:51Z. Reason: GVLK.
Information	2/2/2019 2:02:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03a82e95-26c5-11e9-a173-204747d02364
Report Status: 0"
Information	2/2/2019 1:58:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/2/2019 1:58:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/2/2019 1:58:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/2/2019 1:58:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/2/2019 12:51:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 12:25:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9154.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/2/2019 11:06:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 10:50:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/2/2019 10:50:50 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/2/2019 10:50:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/2/2019 9:57:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/2/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/2/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/2/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59545)(?)])(1 )(2 )]

"
Information	2/2/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/2/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59545)(?)])(1 )(2 )]

"
Information	2/2/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59545)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/2/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/2/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/2/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/2/2019 9:07:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 9:02:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a05b0a1-269b-11e9-a173-204747d02364
Report Status: 0"
Warning	2/2/2019 7:09:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 6:50:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/2/2019 5:38:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 4:55:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/2/2019 4:55:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:06Z. Reason: GVLK.
Information	2/2/2019 4:45:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/2/2019 4:45:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/2/2019 4:45:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/2/2019 4:45:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/2/2019 4:06:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/2/2019 4:03:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 4:02:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3055bc34-2671-11e9-a173-204747d02364
Report Status: 0"
Information	2/2/2019 4:01:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/2/2019 4:01:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/2/2019 4:01:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/2/2019 2:50:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/2/2019 2:24:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/2/2019 12:27:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/2/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/1/2019 11:01:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46999b18-2647-11e9-a173-204747d02364
Report Status: 0"
Information	2/1/2019 11:01:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 11:01:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:22Z. Reason: GVLK.
Information	2/1/2019 10:56:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 10:56:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 10:56:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 10:56:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 10:50:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 10:50:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2019 10:50:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/1/2019 10:50:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/1/2019 9:15:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/1/2019 7:38:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 6:50:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2019 6:01:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5bfd9325-261d-11e9-a173-204747d02364
Report Status: 0"
Warning	2/1/2019 5:46:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 5:20:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 5:20:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:22Z. Reason: GVLK.
Information	2/1/2019 5:15:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 5:15:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 5:15:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 5:15:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 3:47:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 2:50:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/1/2019 2:00:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 1:01:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7251b1c0-25f3-11e9-a173-204747d02364
Report Status: 0"
Information	2/1/2019 12:19:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9153.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	2/1/2019 12:17:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 10:50:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2019 10:50:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/1/2019 10:50:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/1/2019 10:45:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/1/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60985)(?)])(1 )(2 )]

"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60985)(?)])(1 )(2 )]

"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60985)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/1/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 9:10:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 9:09:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/1/2019 9:09:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/1/2019 9:09:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/1/2019 8:01:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 88609c99-25c9-11e9-a173-204747d02364
Report Status: 0"
Warning	2/1/2019 7:33:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 6:49:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2019 6:34:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 6:34:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:29Z. Reason: GVLK.
Information	2/1/2019 6:29:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 6:29:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 6:29:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 6:29:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 5:47:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 4:11:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 4:11:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:16Z. Reason: GVLK.
Information	2/1/2019 4:06:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 4:06:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 4:06:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 4:06:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/1/2019 4:05:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 4:05:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:05Z. Reason: GVLK.
Information	2/1/2019 4:00:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 4:00:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 4:00:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 4:00:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 3:56:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 3:01:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9eb38e11-259f-11e9-a173-204747d02364
Report Status: 0"
Information	2/1/2019 2:49:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2019 2:34:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2019 2:34:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:52Z. Reason: GVLK.
Information	2/1/2019 2:29:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2019 2:29:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2019 2:29:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2019 2:29:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2019 2:22:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/1/2019 12:35:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/31/2019 10:50:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2019 10:49:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/31/2019 10:49:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 10:38:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 10:01:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b50b1c86-2575-11e9-a173-204747d02364
Report Status: 0"
Warning	1/31/2019 9:05:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 8:54:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 8:49:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/31/2019 8:49:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 8:49:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/31/2019 7:30:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 6:49:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 5:39:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 5:01:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb4af57a-254b-11e9-a173-204747d02364
Report Status: 0"
Information	1/31/2019 4:00:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 4:00:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:28Z. Reason: GVLK.
Information	1/31/2019 3:55:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2019 3:55:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 3:55:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 3:55:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/31/2019 3:47:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 2:49:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 2:13:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 1:30:18 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/31/2019 1:30:18 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/31/2019 12:26:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 12:01:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e19e639a-2521-11e9-a173-204747d02364
Report Status: 0"
Information	1/31/2019 12:01:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9152.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/31/2019 11:37:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 30223, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/31/2019 11:36:33 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/31/2019 10:49:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2019 10:49:04 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/31/2019 10:48:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 10:28:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 10:19:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 10:19:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:42Z. Reason: GVLK.
Information	1/31/2019 10:14:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2019 10:14:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 10:14:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 10:14:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2019 9:47:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/31/2019 9:47:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/31/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/31/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/31/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62425)(?)])(1 )(2 )]

"
Information	1/31/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/31/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62425)(?)])(1 )(2 )]

"
Information	1/31/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/31/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/31/2019 8:59:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/31/2019 8:59:20 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/31/2019 8:59:08 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/31/2019 8:55:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/31/2019 7:24:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 7:01:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7cc4da7-24f7-11e9-a173-204747d02364
Report Status: 0"
Information	1/31/2019 6:48:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 5:42:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/31/2019 3:48:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 3:30:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 3:30:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:14Z. Reason: GVLK.
Information	1/31/2019 3:25:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2019 3:25:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 3:25:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 3:25:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2019 3:24:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 3:24:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:51Z. Reason: GVLK.
Information	1/31/2019 3:19:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2019 3:19:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 3:19:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 3:19:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2019 2:48:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2019 2:17:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 2:03:40 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/31/2019 2:01:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e3711e3-24ce-11e9-a173-204747d02364
Report Status: 0"
Information	1/31/2019 2:00:49 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/31/2019 12:31:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2019 12:31:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:49Z. Reason: GVLK.
Warning	1/31/2019 12:30:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2019 12:26:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2019 12:26:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2019 12:26:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2019 12:26:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/30/2019 10:48:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/30/2019 10:48:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/30/2019 10:48:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2019 10:34:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 9:01:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 248deab1-24a4-11e9-a173-204747d02364
Report Status: 0"
Warning	1/30/2019 8:44:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/30/2019 7:09:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 7:00:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 6:55:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/30/2019 6:55:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 6:55:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 6:47:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2019 5:21:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 4:07:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 4:07:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:44Z. Reason: GVLK.
Information	1/30/2019 4:02:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2019 4:02:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 4:02:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 4:02:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 4:01:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3ae3a6c3-247a-11e9-a173-204747d02364
Report Status: 0"
Warning	1/30/2019 3:47:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 3:29:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 3:29:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:33Z. Reason: GVLK.
Information	1/30/2019 3:24:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2019 3:24:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 3:24:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 3:24:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 3:19:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 3:19:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:49Z. Reason: GVLK.
Information	1/30/2019 3:14:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2019 3:14:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 3:14:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 3:14:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 2:47:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2019 1:47:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 12:34:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9151.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	1/30/2019 11:58:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 11:01:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 512e2444-2450-11e9-a173-204747d02364
Report Status: 0"
Information	1/30/2019 10:48:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/30/2019 10:47:57 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/30/2019 10:47:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2019 10:02:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 9:35:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/30/2019 9:30:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/30/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63865)(?)])(1 )(2 )]

"
Information	1/30/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/30/2019 9:30:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63865)(?)])(1 )(2 )]

"
Information	1/30/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63865)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 9:30:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/30/2019 9:30:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 9:30:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 8:59:17 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/30/2019 8:58:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/30/2019 8:58:45 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/30/2019 8:25:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 6:47:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2019 6:37:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 6:01:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 676ddd1d-2426-11e9-a173-204747d02364
Report Status: 0"
Warning	1/30/2019 4:48:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 4:16:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 4:16:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:35Z. Reason: GVLK.
Information	1/30/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 4:11:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/30/2019 4:09:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2019 4:09:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:58Z. Reason: GVLK.
Information	1/30/2019 4:04:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2019 4:04:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2019 4:04:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2019 4:04:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/30/2019 3:01:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 2:47:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/30/2019 1:49:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/30/2019 1:46:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	1/30/2019 1:09:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2019 1:01:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7daf1f78-23fc-11e9-a173-204747d02364
Report Status: 0"
Information	1/30/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/29/2019 11:37:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 10:47:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2019 10:47:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/29/2019 10:47:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/29/2019 9:44:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 8:48:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 8:48:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:57Z. Reason: GVLK.
Information	1/29/2019 8:43:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 8:43:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 8:43:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 8:43:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/29/2019 8:01:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 93f67cd9-23d2-11e9-a173-204747d02364
Report Status: 0"
Warning	1/29/2019 7:48:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 6:47:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/29/2019 5:57:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 4:33:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎01‎-‎29T11:03:58.517290600Z.
Information	1/29/2019 4:33:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎29T11:03:58.517290600Z.
Warning	1/29/2019 4:23:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 3:01:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa28cab2-23a8-11e9-a173-204747d02364
Report Status: 0"
Information	1/29/2019 2:47:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/29/2019 2:41:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 2:33:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 2:28:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2019 2:28:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 2:28:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2019 12:59:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9150.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/29/2019 12:55:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/29/2019 12:54:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/29/2019 12:53:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 12:27:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Error	1/29/2019 12:27:00 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/29/2019 12:26:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/29/2019 12:05:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/29/2019 12:00:49 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/29/2019 12:00:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65154)(?)])(1 )(2 )]

"
Information	1/29/2019 12:00:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2019 12:00:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65154)(?)])(1 )(2 )]

"
Information	1/29/2019 12:00:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65154)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 12:00:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2019 12:00:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 12:00:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/29/2019 11:22:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 10:47:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2019 10:47:16 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/29/2019 10:47:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2019 10:01:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0733913-237e-11e9-a173-204747d02364
Report Status: 0"
Warning	1/29/2019 9:45:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 9:35:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/29/2019 9:30:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/29/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65305)(?)])(1 )(2 )]

"
Information	1/29/2019 9:30:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65305)(?)])(1 )(2 )]

"
Information	1/29/2019 9:30:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65305)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 9:30:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2019 9:30:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 9:30:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2019 9:12:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/29/2019 9:12:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/29/2019 9:12:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/29/2019 8:35:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 8:35:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:20Z. Reason: GVLK.
Information	1/29/2019 8:30:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 8:30:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 8:30:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 8:30:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/29/2019 8:13:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 6:46:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/29/2019 6:32:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 5:01:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d6b76a67-2354-11e9-a173-204747d02364
Report Status: 0"
Warning	1/29/2019 4:57:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 3:47:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 3:47:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:16Z. Reason: GVLK.
Information	1/29/2019 3:42:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 3:42:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 3:42:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 3:42:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/29/2019 3:41:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 3:41:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:22Z. Reason: GVLK.
Information	1/29/2019 3:36:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 3:36:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 3:36:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 3:36:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/29/2019 3:15:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 2:46:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2019 2:09:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 2:09:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:15Z. Reason: GVLK.
Information	1/29/2019 2:04:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 2:04:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 2:04:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 2:04:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/29/2019 1:31:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2019 1:17:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2019 1:17:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:46:17Z. Reason: GVLK.
Information	1/29/2019 1:12:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2019 1:12:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2019 1:12:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2019 1:12:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/29/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/29/2019 12:01:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed17006d-232a-11e9-a173-204747d02364
Report Status: 0"
Warning	1/28/2019 11:33:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 10:46:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/28/2019 10:46:38 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/28/2019 10:46:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/28/2019 9:38:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/28/2019 7:41:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 7:01:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 034817c3-2301-11e9-a173-204747d02364
Report Status: 0"
Information	1/28/2019 6:46:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/28/2019 5:46:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 5:06:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 5:01:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66293)(?)])(1 )(2 )]

"
Information	1/28/2019 5:01:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/28/2019 5:01:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66293)(?)])(1 )(2 )]

"
Information	1/28/2019 5:01:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66293)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 5:01:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 5:01:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 5:01:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/28/2019 3:46:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 2:45:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/28/2019 2:13:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 2:06:24 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/28/2019 2:01:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 193cff8c-22d7-11e9-a173-204747d02364
Report Status: 0"
Information	1/28/2019 1:58:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 1:53:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 1:53:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 1:53:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 1:30:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/28/2019 1:30:02 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/28/2019 12:27:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 11:19:06 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎01‎-‎28T05:49:06.617679600Z.
Information	1/28/2019 11:19:06 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎28T05:49:06.617679600Z.
Information	1/28/2019 11:09:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 29779, Deleted: 0, Modified: 28, Compared: 30298, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/28/2019 11:06:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/28/2019 10:52:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎01‎-‎28T05:22:29.378819500Z.
Information	1/28/2019 10:52:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎28T05:22:29.378819500Z.
Information	1/28/2019 10:50:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 10:45:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/28/2019 10:45:30 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 32

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	1/28/2019 10:45:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66670)(?)])(1 )(2 )]

"
Information	1/28/2019 10:45:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/28/2019 10:45:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66670)(?)])(1 )(2 )]

"
Information	1/28/2019 10:45:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66670)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:45:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 10:45:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 10:45:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/28/2019 10:45:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/28/2019 10:36:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 10:25:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.10730.20262.
Information	1/28/2019 10:25:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/28/2019 10:25:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66689)(?)])(1 )(2 )]

"
Information	1/28/2019 10:25:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66689)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:25:36 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/28/2019 10:25:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66689)(?)])(1 )(2 )]

"
Information	1/28/2019 10:25:35 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/28/2019 10:25:35 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109889  Grace type=8.
Information	1/28/2019 10:25:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=94c4e796-6200-4e0f-a66e-3e704c222dbf"
Information	1/28/2019 10:25:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=1804e960-8150-4646-ae78-65310fa108fa"
Information	1/28/2019 10:25:34 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/28/2019 10:25:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/28/2019 10:25:32 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/28/2019 10:25:32 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 858

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 218

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	1/28/2019 10:25:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/28/2019 10:24:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20610)(?)])(1 )(2 )]

"
Information	1/28/2019 10:24:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/28/2019 10:24:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20610)(?)])(1 )(2 )]

"
Information	1/28/2019 10:24:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20610)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:24:50 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 10:24:50 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 10:24:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 10:21:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 10:21:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-02-04T04:45:51Z. Reason: GVLK.
Information	1/28/2019 10:16:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:16:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:16:50 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/01/28 04:46"
Information	1/28/2019 10:16:49 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/01/28 04:46, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/28/2019 10:11:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/28/2019 10:11:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 10:11:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 10:11:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 9:31:42 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9149.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/28/2019 9:27:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 9:27:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:45Z. Reason: GVLK.
Information	1/28/2019 9:22:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/28/2019 9:22:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 9:22:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 9:22:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 9:11:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 9:09:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 9:09:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:18Z. Reason: GVLK.
Error	1/28/2019 9:06:15 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20689)(?)])(1 )(2 )]

"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20689)(?)])(1 )(2 )]

"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20689)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 9:06:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 9:06:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 9:04:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/28/2019 9:01:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2ed06c47-22ad-11e9-a173-204747d02364
Report Status: 0"
Information	1/28/2019 9:01:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	1/28/2019 9:00:16 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	1/28/2019 8:58:58 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0CB41D68-BB5B-4521-8DAA-503EF9DE7299}
Error	1/28/2019 8:58:58 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0CB41D68-BB5B-4521-8DAA-503EF9DE7299}
Error	1/28/2019 8:58:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/28/2019 8:58:44 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/28/2019 8:58:43 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/28/2019 8:58:42 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/28/2019 8:58:40 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/28/2019 8:58:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/28/2019 8:58:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 8:58:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 8:58:19 AM	ESENT	302	Logging/Recovery	Windows (9048) Windows: The database engine has successfully completed recovery steps.
Information	1/28/2019 8:58:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20697)(?)])(1 )(2 )]

"
Information	1/28/2019 8:58:14 AM	ESENT	301	Logging/Recovery	Windows (9048) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	1/28/2019 8:58:13 AM	ESENT	300	Logging/Recovery	Windows (9048) Windows: The database engine is initiating recovery steps.
Information	1/28/2019 8:58:13 AM	ESENT	102	General	Windows (9048) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/28/2019 8:58:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 8:58:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Error	1/28/2019 8:58:05 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/28/2019 8:58:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20697)(?)])(1 )(2 )]

"
Information	1/28/2019 8:58:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 20697)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/28/2019 8:58:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/28/2019 8:58:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/28/2019 8:58:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/28/2019 8:57:51 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9148.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/28/2019 8:57:25 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/28/2019 8:57:25 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	1/28/2019 8:55:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/28/2019 8:55:37 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/28/2019 8:55:35 AM	PostgreSQL	0	None	Server started and accepting connections

Information	1/28/2019 8:55:32 AM	PostgreSQL	0	None	"2019-01-28 08:55:32 IST LOG:  redirecting log output to logging collector process
2019-01-28 08:55:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/28/2019 8:55:32 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/28/2019 8:55:30 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/28/2019 8:55:28 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/28/2019 8:55:22 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/28/2019 8:54:43 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:43 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/28/2019 8:54:43 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/28/2019 8:54:43 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/28/2019 8:54:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/28/2019 8:54:40 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:39 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/28/2019 8:54:38 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/28/2019 8:54:38 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/28/2019 8:54:38 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 1940 at 1/27/2019 1:30:46 PM (local) 1/27/2019 8:00:46 AM (UTC). This is an informational message only; no user action is required.
Information	1/28/2019 8:54:35 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/28/2019 8:54:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/28/2019 8:54:34 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/28/2019 8:54:34 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/28/2019 8:54:34 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/28/2019 8:54:34 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/28/2019 8:54:31 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/28/2019 8:54:31 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	1/28/2019 8:54:31 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/28/2019 8:54:31 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/28/2019 8:54:31 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4876.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/28/2019 8:54:22 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/28/2019 8:53:10 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/28/2019 8:52:59 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	1/28/2019 8:52:58 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/28/2019 8:52:56 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/28/2019 8:52:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/28/2019 8:52:56 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	1/27/2019 1:30:53 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	1/27/2019 1:30:46 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	1/27/2019 1:30:46 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	1/27/2019 1:30:38 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	1/27/2019 1:30:36 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 17 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 988 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2328 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4224 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4224 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 7844 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/27/2019 1:30:37 PM	McLogEvent	257	None	The scan of C:\Windows\System32\wlanapi.dll has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9148.0000.
Information	1/27/2019 1:30:36 PM	MTAService.OnSessionChange	0	None	1:30:36 PM - Logoff
Information	1/27/2019 1:30:36 PM	MTAService.OnSessionChange	0	None	1:30:36 PM - Session change notice received: SessionLogoff Session ID: 1
Information	1/27/2019 1:30:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	1/27/2019 1:30:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/27/2019 1:30:35 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	1/27/2019 12:38:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9148.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	1/27/2019 12:11:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:11:32 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:10:41 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:10:27 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:09:19 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:09:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:06:28 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/27/2019 12:06:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/27/2019 12:06:15 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 12:01:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/27/2019 12:01:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21953)(?)])(1 )(2 )]

"
Information	1/27/2019 12:01:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/27/2019 12:01:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21953)(?)])(1 )(2 )]

"
Information	1/27/2019 12:01:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21953)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	1/27/2019 11:59:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/27/2019 11:59:23 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/27/2019 11:59:15 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10048.
Information	1/27/2019 11:59:15 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.10730.20264. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:59:15 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	1/27/2019 11:59:14 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/27/2019 11:59:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21956)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/27/2019 11:59:12 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/27/2019 11:59:12 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/27/2019 11:59:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/27/2019 11:59:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/27/2019 11:59:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/27/2019 11:59:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/27/2019 11:59:01 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10048.
Information	1/27/2019 11:59:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:59:00 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.10730.20264. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:59:00 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	1/27/2019 11:58:59 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:59 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:59 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20264. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:58:59 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/27/2019 11:58:56 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:56 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:56 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.10730.20264. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:58:56 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/27/2019 11:58:51 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/27/2019 11:58:51 AM	ESENT	102	General	Windows (10972) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/27/2019 11:58:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:51 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20264. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:58:51 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/27/2019 11:58:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:32 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/27/2019 11:58:32 AM	ESENT	103	General	Windows (7960) Windows: The database engine stopped the instance (0).
Information	1/27/2019 11:58:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:58:32 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.10730.20264. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/27/2019 11:58:32 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/27/2019 11:57:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/27/2019 11:57:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10048.
Information	1/27/2019 11:56:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/27/2019 11:56:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:42Z. Reason: GVLK.
Warning	1/27/2019 11:56:11 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	1/27/2019 11:56:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/27/2019 11:56:10 AM	ESENT	102	General	Windows (7960) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/27/2019 11:56:08 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/27/2019 11:56:08 AM	ESENT	103	General	Windows (8736) Windows: The database engine stopped the instance (0).
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:56:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/27/2019 11:55:59 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/27/2019 11:55:59 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/27/2019 11:55:58 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/27/2019 11:55:58 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Error	1/27/2019 11:53:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/27/2019 11:53:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/27/2019 11:52:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {FF2FD955-CFDA-489D-AF52-515B90836F5E}
Error	1/27/2019 11:52:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/27/2019 11:52:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/27/2019 11:51:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21963)(?)])(1 )(2 )]

"
Information	1/27/2019 11:51:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/27/2019 11:51:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21963)(?)])(1 )(2 )]

"
Information	1/27/2019 11:51:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 21963)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/27/2019 11:51:51 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/27/2019 11:51:50 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e633ae97-1bc1-4fdb-873e-55456b30489a"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60bf7784-81ca-4556-a959-9c152e15669d"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=544d2e70-aa48-4e2b-a43d-52ec83aa0427"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=cf84484a-44a0-4b67-b1e9-4186929240ca"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3acae882-52ce-42dd-a708-eca29d35bb09"
Information	1/27/2019 11:51:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=56421083-4260-4bf5-8bb8-2a9aed708066"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c6341c8-6dda-4a94-810d-45c3ba3108cf"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5a9f936e-3aee-409b-ada6-cd0169049418"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d6a534c8-cdf3-442d-850f-925004c6ed8f"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9d16bfa3-a0aa-4659-8555-04360305c600"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=576982b1-f73d-442b-8f34-4e9c8245f728"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4958405-6251-473b-b4e9-649f61239091"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=cb1acfd5-4ad6-46f7-a508-95096e7e53cb"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=60c6b5ae-abeb-405a-ae22-b1a179b9a0b8"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f46cd2ab-a792-4421-a25b-10a2c2b6065e"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3fcfa8df-de4c-4ae9-a6eb-ce92f6000012"
Information	1/27/2019 11:51:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	1/27/2019 11:51:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=70abdf70-5bb0-46f5-bade-1e7fb728eb96"
Information	1/27/2019 11:51:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=84904722-dfb7-4e90-b656-eac912151df3"
Information	1/27/2019 11:51:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=380aa12a-eeb0-4851-8915-e97ff3c99037"
Information	1/27/2019 11:51:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a4e1412c-eafa-4c01-bf17-96f00ec2e8c0"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ba2baae7-dc04-4afe-82d9-abff518374c0"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=55e45973-1275-415b-84ea-5dd31d2bf5b6"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=59f44fbc-2ce4-4025-900a-219030f1d5f1"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=8c6aed11-5d85-47a7-98cd-91e8dd441d09"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=33ae5639-431e-4d01-a725-10b55fbf19fa"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b6238cce-6111-4dd8-8e3a-2131345b41f4"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=0c2a811a-4066-41d9-b01e-6ce41951b612"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=96180128-4419-4223-81d5-455dd1f0b8cc"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f327bfa6-fbf6-4ed0-a4a9-bd4bfad744a4"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32d48179-769f-42a7-8318-85183032750f"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=1967969c-5f25-4bbb-b0b6-9b2a85956b82"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bf09d53d-e057-4345-8573-3258cbcdcef0"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f108a725-53a3-46f8-8638-671f21618af5"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=df86036a-2bdd-40fb-95e5-7758a40888a0"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8ad24e6d-710c-41c0-8442-09360563915a"
Information	1/27/2019 11:51:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=528bab55-7786-4356-b2ad-88fe1b8fcac8"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=36c02486-b646-42e2-9d99-3f004cdf9417"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=63ac7ebe-fee9-4a32-837b-e3d4eb8aab69"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8c2ef592-c12b-4876-8763-5b9b86e92d9d"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43734373-179d-47a1-b21b-115629169450"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1d9e42c5-325e-442c-98af-fd1302c4df68"
Information	1/27/2019 11:51:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=958bc5e1-123f-4165-bb7b-8e858e8e919e"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cbf0d3b-d091-4f6c-8e5d-4efbaec5b4e3"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=95f0af3a-edc0-44f3-b03c-b3bdf67435ca"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=48f8ef71-4394-4531-a9de-2ec4c93ec39a"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=22628221-fa6f-46db-a6d9-67311a301511"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f7934e94-8990-4c80-b27a-5cf7eece2fa5"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5ad7f835-c1e8-44f5-baba-8bf994ae4d24"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4526aedc-292b-409a-bc96-f9d1d2381942"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c133fb56-f2de-4574-898a-41d104a45835"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2602ff5c-19a2-4669-b1cc-ab7fd12dfc65"
Information	1/27/2019 11:51:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=450354ce-2bb6-4774-a3b6-f7a0a9b987d4"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2c74a701-ffb9-4c86-9f1e-73bf1fd37556"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=76be9fd9-fea4-4be2-ba66-936c33de5275"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9b5f2cc3-88de-453f-869e-57da5482fb25"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb57abfe-5d2d-4c1f-ba4a-61a7115e0583"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7b206866-c2d5-4e3e-9653-cd48d22d876e"
Information	1/27/2019 11:51:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1664fd49-b86a-42c8-aac6-dee2ca9fd24a"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=4b14f23e-05d8-4f50-84c1-50bc046e8af4"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=707c0c99-18c9-4857-b121-a2294a144fdd"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	1/27/2019 11:51:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	1/27/2019 11:50:59 AM	McLogEvent	257	None	The scan of C:\ProgramData\SquirrelMachineInstalls\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9146.0000.
Information	1/27/2019 11:50:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/27/2019 11:50:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/27/2019 11:50:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/27/2019 11:50:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	1/27/2019 11:50:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/27/2019 11:50:16 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	1/27/2019 11:50:02 AM	ESENT	302	Logging/Recovery	Windows (8736) Windows: The database engine has successfully completed recovery steps.
Information	1/27/2019 11:50:02 AM	ESENT	301	Logging/Recovery	Windows (8736) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	1/27/2019 11:49:59 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/27/2019 11:49:57 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/27/2019 11:49:54 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/27/2019 11:49:54 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	1/27/2019 11:49:54 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/27/2019 11:49:43 AM	ESENT	301	Logging/Recovery	Windows (8736) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0149B.log.
Information	1/27/2019 11:49:43 AM	ESENT	300	Logging/Recovery	Windows (8736) Windows: The database engine is initiating recovery steps.
Information	1/27/2019 11:49:40 AM	ESENT	102	General	Windows (8736) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/27/2019 11:48:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/27/2019 11:48:43 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/27/2019 11:48:43 AM	MTAService.OnSessionChange	0	None	11:48:43 AM - Logon : 212558710
Information	1/27/2019 11:48:43 AM	MTAService.OnSessionChange	0	None	11:48:43 AM - Session change notice received: SessionLogon Session ID: 1
Information	1/27/2019 11:48:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/27/2019 11:48:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	1/27/2019 11:48:19 AM	MTAService.OnSessionChange	0	None	11:48:19 AM - Session change notice received: ConsoleConnect Session ID: 1
Information	1/27/2019 11:48:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/27/2019 11:48:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/27/2019 11:48:11 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	1/27/2019 11:48:11 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	1/27/2019 11:48:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	1/27/2019 11:48:00 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/27/2019 11:47:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/27/2019 11:47:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎27T06:17:49.691730000Z.
Information	1/27/2019 11:47:43 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9146.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/27/2019 11:46:57 AM	Service1	0	None	Service started successfully.
Error	1/27/2019 11:46:46 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/27/2019 11:46:46 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/27/2019 11:46:35 AM	PostgreSQL	0	None	Server started and accepting connections

Information	1/27/2019 11:46:30 AM	PostgreSQL	0	None	"2019-01-27 11:46:30 IST LOG:  redirecting log output to logging collector process
2019-01-27 11:46:30 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/27/2019 11:46:26 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/27/2019 11:46:24 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/27/2019 11:46:18 AM	MTAService	0	None	Service started successfully.
Information	1/27/2019 11:46:18 AM	MTAService.OnStart	0	None	11:46:18 AM - Waiting for user to Logon
Information	1/27/2019 11:46:18 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:17 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/27/2019 11:46:17 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/27/2019 11:46:17 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/27/2019 11:46:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/27/2019 11:46:16 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:16 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/27/2019 11:46:16 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/27/2019 11:46:15 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/27/2019 11:46:14 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/27/2019 11:46:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/27/2019 11:46:14 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:14 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/27/2019 11:46:13 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/27/2019 11:46:13 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/27/2019 11:46:13 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/27/2019 11:46:10 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/27/2019 11:46:09 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:09 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:09 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4812 at 1/25/2019 3:27:35 PM (local) 1/25/2019 9:57:35 AM (UTC). This is an informational message only; no user action is required.
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/27/2019 11:46:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/27/2019 11:46:06 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/27/2019 11:46:06 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/27/2019 11:46:06 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/27/2019 11:46:06 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 1940.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/27/2019 11:45:56 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/27/2019 11:42:35 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/27/2019 11:42:29 AM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	1/27/2019 11:42:26 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/27/2019 11:41:47 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/27/2019 11:41:47 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/27/2019 11:41:47 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	1/25/2019 3:27:45 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	1/25/2019 3:27:44 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	1/25/2019 3:27:34 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	1/25/2019 3:26:13 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	1/25/2019 3:26:10 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 36 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 176 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 24396 (\Device\HarddiskVolume1\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 24396 (\Device\HarddiskVolume1\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/25/2019 3:26:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	1/25/2019 3:26:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/25/2019 3:26:05 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	1/25/2019 3:26:00 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	1/25/2019 3:26:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	1/25/2019 3:21:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 3:20:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]

"
Information	1/25/2019 3:20:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/25/2019 3:20:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]

"
Information	1/25/2019 3:20:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 3:20:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]

"
Information	1/25/2019 3:20:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/25/2019 3:20:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]

"
Information	1/25/2019 3:20:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 24634)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 2:48:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/25/2019 2:15:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2019 1:30:13 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/25/2019 1:30:12 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/25/2019 1:30:10 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/25/2019 1:28:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 12:58:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de23ea84-2072-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/25/2019 12:52:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9146.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/25/2019 12:30:35 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	1/25/2019 11:44:35 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	1/25/2019 11:42:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/25/2019 11:26:28 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/25/2019 10:15:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2019 10:15:05 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/25/2019 9:46:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/25/2019 8:15:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 7:58:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f44c8d8f-2048-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/25/2019 6:54:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2019 6:54:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:34Z. Reason: GVLK.
Information	1/25/2019 6:49:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2019 6:49:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 6:49:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2019 6:49:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2019 6:35:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 6:15:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2019 5:54:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2019 5:54:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:11Z. Reason: GVLK.
Information	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 11400) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 13020) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 7596) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 11524) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 9332) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 3016) cannot be restarted - Application SID does not match Conductor SID..
Information	1/25/2019 5:49:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎25T00:19:27.286260700Z.
Information	1/25/2019 5:49:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎25T00:19:24.796260700Z.
Information	1/25/2019 5:49:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2019 5:49:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 5:49:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2019 5:49:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2019 5:01:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 4:32:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2019 4:32:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:38Z. Reason: GVLK.
Information	1/25/2019 4:27:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2019 4:27:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 4:27:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2019 4:27:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/25/2019 4:27:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2019 4:27:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:42:04Z. Reason: GVLK.
Information	1/25/2019 4:22:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2019 4:22:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 4:22:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2019 4:22:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2019 3:01:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 2:58:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0a880677-201f-11e9-b9ae-204747d02364
Report Status: 0"
Error	1/25/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/25/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 25403)(?)])(1 )(2 )]

"
Information	1/25/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/25/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 25403)(?)])(1 )(2 )]

"
Information	1/25/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 25403)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2019 2:15:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/25/2019 1:10:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/24/2019 11:28:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 11:12:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2019 11:12:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:48Z. Reason: GVLK.
Information	1/24/2019 11:07:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2019 11:07:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 11:07:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2019 11:07:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/24/2019 10:14:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 10:14:48 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/24/2019 10:14:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 9:58:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 20da8bbb-1ff5-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/24/2019 9:46:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/24/2019 8:14:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 8:12:19 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/24/2019 8:10:12 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/24/2019 7:50:47 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/24/2019 6:20:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 6:14:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 4:58:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 371031bc-1fcb-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/24/2019 4:47:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 4:00:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 4:00:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:42:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:42:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:40:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:38:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:23:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:20:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:20:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:19:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:17:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:16:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:14:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:14:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:12:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:11:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:11:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:10:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:10:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	1/24/2019 3:10:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 3:08:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:08:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:04:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:04:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:03:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 3:02:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 3:01:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 2:58:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 2:57:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 2:54:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 2:53:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 2:52:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 2:51:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 2:51:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/24/2019 2:48:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/24/2019 2:14:59 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 156

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 624

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	1/24/2019 2:14:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 2:13:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26141)(?)])(1 )(2 )]

"
Information	1/24/2019 2:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/24/2019 2:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26141)(?)])(1 )(2 )]

"
Information	1/24/2019 2:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26141)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/24/2019 1:26:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 12:47:10 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/24/2019 12:46:50 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/24/2019 12:26:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9145.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/24/2019 12:02:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/24/2019 11:58:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4d55e56c-1fa1-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/24/2019 11:37:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 11:37:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/24/2019 11:37:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/24/2019 11:36:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/24/2019 9:40:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 9:14:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2019 9:14:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:48Z. Reason: GVLK.
Information	1/24/2019 9:09:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2019 9:09:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 9:09:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2019 9:09:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/24/2019 7:54:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 7:37:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 6:58:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63899dbd-1f77-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/24/2019 6:14:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/24/2019 4:28:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 4:18:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2019 4:18:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:42:04Z. Reason: GVLK.
Information	1/24/2019 4:13:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2019 4:13:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 4:13:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2019 4:13:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/24/2019 4:10:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2019 4:10:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:42:01Z. Reason: GVLK.
Information	1/24/2019 4:05:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2019 4:05:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 4:05:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2019 4:04:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/24/2019 3:36:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2019 3:36:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/24/2019 2:39:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/24/2019 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/24/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26843)(?)])(1 )(2 )]

"
Information	1/24/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/24/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26843)(?)])(1 )(2 )]

"
Information	1/24/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 26843)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 1:58:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79d8ed2d-1f4d-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/24/2019 12:52:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2019 12:21:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2019 12:21:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:57Z. Reason: GVLK.
Information	1/24/2019 12:16:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2019 12:16:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2019 12:16:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2019 12:16:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/23/2019 11:36:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 11:36:55 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/23/2019 11:36:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2019 10:58:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 10:20:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2019 10:20:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:42:02Z. Reason: GVLK.
Information	1/23/2019 10:15:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2019 10:15:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2019 10:15:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2019 10:15:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/23/2019 9:23:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 8:58:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8ff17ae6-1f23-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/23/2019 7:55:57 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/23/2019 7:55:34 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 23, Compared: 30060, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/23/2019 7:54:07 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/23/2019 7:54:07 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/23/2019 7:36:41 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 32

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 187

Information	1/23/2019 7:36:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 7:36:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27259)(?)])(1 )(2 )]

"
Information	1/23/2019 7:36:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/23/2019 7:36:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27259)(?)])(1 )(2 )]

"
Information	1/23/2019 7:36:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27259)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/23/2019 7:27:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/23/2019 5:51:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 4:36:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 764

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 78

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 484

Information	1/23/2019 4:36:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 4:35:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27439)(?)])(1 )(2 )]

"
Information	1/23/2019 4:35:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/23/2019 4:35:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27439)(?)])(1 )(2 )]

"
Information	1/23/2019 4:35:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 27439)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/23/2019 4:08:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 3:58:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a645b727-1ef9-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/23/2019 2:58:21 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	1/23/2019 2:57:46 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	1/23/2019 2:56:52 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	1/23/2019 2:56:49 PM	ASP.NET 4.0.30319.0	1077	None	State server stops listening
Information	1/23/2019 2:56:31 PM	ASP.NET 4.0.30319.0	1076	None	State server starts listening with 24 listeners
Information	1/23/2019 2:20:14 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 14524 milliseconds
Information	1/23/2019 2:19:01 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft VS Code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9144.0000.
Information	1/23/2019 2:18:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/23/2019 2:16:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2019 2:16:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 1:42:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/23/2019 1:42:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/23/2019 12:46:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/23/2019 12:46:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/23/2019 12:38:40 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9144.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	1/23/2019 12:35:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 12:32:51 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/23/2019 12:32:44 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/23/2019 12:13:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/23/2019 12:12:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/23/2019 12:09:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/23/2019 12:09:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/23/2019 12:09:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/23/2019 12:00:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2019 12:00:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:45Z. Reason: GVLK.
Information	1/23/2019 11:55:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2019 11:55:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2019 11:55:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2019 11:55:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/23/2019 10:58:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc68f2d5-1ecf-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/23/2019 10:47:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 10:17:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 10:16:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 10:16:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2019 9:12:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/23/2019 7:33:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 6:17:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 6:17:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 6:16:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 6:16:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 5:58:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2a68701-1ea5-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/23/2019 5:37:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 4:00:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2019 4:00:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:42:05Z. Reason: GVLK.
Information	1/23/2019 3:55:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2019 3:55:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2019 3:55:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2019 3:55:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/23/2019 3:52:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2019 3:52:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:27Z. Reason: GVLK.
Information	1/23/2019 3:47:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2019 3:47:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2019 3:47:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2019 3:47:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/23/2019 3:45:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/23/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/23/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 28283)(?)])(1 )(2 )]

"
Information	1/23/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/23/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 28283)(?)])(1 )(2 )]

"
Information	1/23/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 28283)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2019 2:17:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:17:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2019 2:16:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/23/2019 2:16:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2019 2:05:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2019 12:58:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e90393da-1e7b-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/23/2019 12:08:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 10:17:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:17:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:16:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:16:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2019 10:13:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/22/2019 8:15:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 7:58:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff629509-1e51-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/22/2019 6:40:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 6:17:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:16:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:16:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:16:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:16:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/22/2019 6:16:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2019 4:49:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/22/2019 3:18:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 2:58:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15ae6361-1e28-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/22/2019 2:17:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:16:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:16:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:16:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:15:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:15:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/22/2019 2:15:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 1:49:33 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/22/2019 1:49:32 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/22/2019 1:44:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 1:43:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/22/2019 1:43:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 1:37:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 1:37:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 1:19:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 1:19:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Error	1/22/2019 12:48:15 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/22/2019 12:47:35 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9143.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	1/22/2019 12:46:12 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/22/2019 12:44:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 12:43:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 12:40:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 12:39:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 12:33:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 12:32:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 12:16:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 12:16:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 12:11:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 12:10:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 12:03:05 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/22/2019 12:03:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/22/2019 12:02:56 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/22/2019 11:46:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	1/22/2019 11:45:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 11:44:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 11:11:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/22/2019 11:10:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/22/2019 10:16:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:16:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:15:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 10:09:23 AM	Outlook	27	None	An unexpected error has occurred.
Warning	1/22/2019 10:08:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 9:58:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2be37ad3-1dfe-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/22/2019 8:25:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/22/2019 6:49:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 6:16:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:16:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:15:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 6:15:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2019 5:07:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 4:58:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 42081774-1dd4-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/22/2019 4:46:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2019 4:46:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:46Z. Reason: GVLK.
Information	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 9664) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 13020) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 7596) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 11524) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 9332) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/22/2019 4:42:07 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 3016) cannot be restarted - Application SID does not match Conductor SID..
Information	1/22/2019 4:42:06 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎21T23:12:06.831958800Z.
Information	1/22/2019 4:42:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎21T23:12:03.646958800Z.
Information	1/22/2019 4:41:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2019 4:41:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2019 4:41:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2019 4:41:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/22/2019 3:31:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 3:27:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2019 3:27:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:55Z. Reason: GVLK.
Information	1/22/2019 3:22:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2019 3:22:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2019 3:22:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2019 3:22:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/22/2019 3:20:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2019 3:20:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:45Z. Reason: GVLK.
Information	1/22/2019 3:15:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2019 3:15:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2019 3:15:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2019 3:15:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/22/2019 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/22/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 29723)(?)])(1 )(2 )]

"
Information	1/22/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/22/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 29723)(?)])(1 )(2 )]

"
Information	1/22/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 29723)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2019 2:16:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:16:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:15:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2019 2:15:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/22/2019 2:15:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2019 1:40:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/22/2019 12:01:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 11:58:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58603005-1daa-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/21/2019 10:16:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 10:15:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/21/2019 10:12:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/21/2019 8:14:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 7:52:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9142.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	1/21/2019 7:52:11 PM	Application Error	1000	(100)	"Faulting application name: mcshield.exe, version: 15.6.0.1551, time stamp: 0x58d45994
Faulting module name: RPCRT4.dll, version: 6.1.7601.24308, time stamp: 0x5be85fcb
Exception code: 0xc0000005
Fault offset: 0x000000000002e3f0
Faulting process id: 0x18c8
Faulting application start time: 0x01d4a975fe576a32
Faulting application path: C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
Faulting module path: C:\Windows\system32\RPCRT4.dll
Report Id: f07a79bb-1d87-11e9-b9ae-204747d02364"
Error	1/21/2019 7:52:08 PM	McLogEvent	5019	None	"Exception in McShield.Exe!
 Exception details follow : 
VSCORE.15.6.0.1551
Exception Code       : 0X00000000C0000005
Exception Address    : 0X000007FEFEA8E3F0
Exception Parameters : 2
 Param 1 = 0000000000000000
 Param 2 = 0XFFFFFFFFFFFFFFFF

More information :
"
Information	1/21/2019 6:58:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6eae967e-1d80-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/21/2019 6:30:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 6:16:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 6:15:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/21/2019 4:57:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 4:32:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 30322)(?)])(1 )(2 )]

"
Information	1/21/2019 4:32:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/21/2019 4:32:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 30322)(?)])(1 )(2 )]

"
Information	1/21/2019 4:32:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 30322)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/21/2019 2:58:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 2:15:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/21/2019 1:58:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 84a05307-1d56-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/21/2019 1:18:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 12:52:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9142.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/21/2019 12:00:05 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/21/2019 11:59:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/21/2019 11:59:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	1/21/2019 11:38:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 11:30:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/21/2019 11:30:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:50Z. Reason: GVLK.
Information	1/21/2019 11:25:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/21/2019 11:25:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 11:25:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/21/2019 11:25:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/21/2019 10:57:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:56:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:55:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:52:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:50:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:45:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:45:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:42:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:40:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:38:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:23:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:22:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:20:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:17:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:17:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/21/2019 10:17:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-28T04:41:12Z. Reason: GVLK.
Information	1/21/2019 10:15:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/21/2019 10:15:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 10:15:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 10:14:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:13:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:12:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 10:12:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 10:12:10 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/01/21 04:42"
Information	1/21/2019 10:12:09 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/01/21 04:42, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/21/2019 10:07:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/21/2019 10:07:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 10:07:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/21/2019 10:07:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/21/2019 10:06:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 10:05:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:05:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 10:01:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 10:00:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:44:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:43:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:39:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:38:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:28:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:28:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:21:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:21:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:16:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:15:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:13:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:13:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:08:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 9:08:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 9:07:50 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/21/2019 8:58:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 8:58:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9acd26e4-1d2c-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/21/2019 8:58:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 8:56:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 8:55:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 8:54:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 8:54:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/21/2019 8:39:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 8:38:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/21/2019 8:17:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 8:09:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/21/2019 8:08:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/21/2019 6:37:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 6:15:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 6:15:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 6:15:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/21/2019 4:52:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 3:58:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b12149dc-1d02-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/21/2019 3:56:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/21/2019 3:56:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:06Z. Reason: GVLK.
Information	1/21/2019 3:51:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/21/2019 3:51:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 3:51:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/21/2019 3:51:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/21/2019 3:50:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/21/2019 3:50:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:42Z. Reason: GVLK.
Information	1/21/2019 3:45:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/21/2019 3:45:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 3:45:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/21/2019 3:45:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/21/2019 3:14:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/21/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/21/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 31163)(?)])(1 )(2 )]

"
Information	1/21/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/21/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 31163)(?)])(1 )(2 )]

"
Information	1/21/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 31163)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/21/2019 2:15:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/21/2019 2:15:13 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/21/2019 1:34:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/21/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/20/2019 11:56:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 10:58:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c777771c-1cd8-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/20/2019 10:15:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 10:15:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 10:15:08 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/20/2019 10:00:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/20/2019 8:22:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/20/2019 6:48:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 6:15:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 6:15:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 6:15:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 5:58:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ddc80566-1cae-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/20/2019 5:14:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 3:31:07 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 29866, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/20/2019 3:30:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/20/2019 3:30:10 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/20/2019 3:30:04 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/20/2019 3:30:01 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/20/2019 3:30:01 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	1/20/2019 3:25:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 2:15:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:15:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:15:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:15:05 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/20/2019 1:33:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 12:58:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f404911a-1c84-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/20/2019 12:56:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9141.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	1/20/2019 11:50:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 10:15:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 10:15:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 10:15:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 10:14:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/20/2019 9:54:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/20/2019 8:11:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 7:58:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0a1fcfb3-1c5b-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/20/2019 6:24:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 6:15:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 6:15:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 6:14:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 6:14:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/20/2019 4:49:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 4:27:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/20/2019 4:27:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:59Z. Reason: GVLK.
Information	1/20/2019 4:22:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/20/2019 4:22:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/20/2019 4:22:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/20/2019 4:22:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/20/2019 4:22:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/20/2019 4:22:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:03Z. Reason: GVLK.
Information	1/20/2019 4:17:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/20/2019 4:17:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/20/2019 4:17:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/20/2019 4:17:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 9664) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 13020) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 7596) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 11524) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 9332) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/20/2019 3:38:25 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 3016) cannot be restarted - Application SID does not match Conductor SID..
Information	1/20/2019 3:38:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎19T22:08:24.961001800Z.
Information	1/20/2019 3:38:21 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎19T22:08:21.249630700Z.
Information	1/20/2019 3:26:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/20/2019 3:26:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:55Z. Reason: GVLK.
Information	1/20/2019 3:21:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/20/2019 3:21:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/20/2019 3:21:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/20/2019 3:21:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/20/2019 3:00:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 2:58:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2074edc0-1c31-11e9-b9ae-204747d02364
Report Status: 0"
Error	1/20/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/20/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 32603)(?)])(1 )(2 )]

"
Information	1/20/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/20/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 32603)(?)])(1 )(2 )]

"
Information	1/20/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 32603)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/20/2019 2:15:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:15:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:15:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:14:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/20/2019 2:14:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/20/2019 2:14:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/20/2019 1:07:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/20/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/19/2019 11:07:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 10:15:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 10:15:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 10:14:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 9:58:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 36d61780-1c07-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/19/2019 9:35:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 8:39:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/19/2019 8:39:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/19/2019 7:47:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 6:15:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:15:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:14:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:14:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:14:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/19/2019 6:00:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 4:58:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4d2116dd-1bdd-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/19/2019 4:22:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/19/2019 2:44:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 2:15:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:15:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:14:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:14:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:14:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/19/2019 1:52:32 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/19/2019 12:46:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 12:30:29 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/19/2019 12:30:28 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/19/2019 12:30:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/19/2019 12:17:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9140.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/19/2019 11:58:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6364326c-1bb3-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/19/2019 11:15:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 10:15:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 10:14:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/19/2019 9:40:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/19/2019 8:04:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 6:58:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 798deff6-1b89-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/19/2019 6:15:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:14:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 6:14:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/19/2019 6:05:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 4:56:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/19/2019 4:56:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:44Z. Reason: GVLK.
Information	1/19/2019 4:51:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/19/2019 4:51:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2019 4:51:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2019 4:51:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/19/2019 4:50:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/19/2019 4:50:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:05Z. Reason: GVLK.
Information	1/19/2019 4:45:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/19/2019 4:45:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2019 4:45:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2019 4:45:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/19/2019 4:18:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/19/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/19/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 34043)(?)])(1 )(2 )]

"
Information	1/19/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/19/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 34043)(?)])(1 )(2 )]

"
Information	1/19/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 34043)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/19/2019 2:20:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 2:14:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:14:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 2:14:38 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/19/2019 2:14:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2019 1:58:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8fd7c271-1b5f-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/19/2019 12:36:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2019 12:03:11 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/18/2019 10:37:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 10:14:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 10:14:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 8:58:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a61e981e-1b35-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/18/2019 8:57:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/18/2019 6:59:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 6:14:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 6:14:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/18/2019 5:11:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 4:14:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/18/2019 4:14:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/18/2019 4:10:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/18/2019 4:10:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/18/2019 4:09:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/18/2019 4:08:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/18/2019 3:58:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc48100e-1b0b-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/18/2019 3:32:03 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/18/2019 3:16:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 2:14:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/18/2019 2:14:34 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/18/2019 1:15:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 12:47:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/18/2019 12:42:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 12:42:37 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:37Z. Reason: GVLK.
Information	1/18/2019 12:37:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 12:37:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 12:37:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 12:37:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 12:30:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 12:30:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:08Z. Reason: GVLK.
Information	1/18/2019 12:25:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 12:25:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 12:25:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 12:25:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 12:23:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9139.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	1/18/2019 11:42:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 10:59:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 10:59:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:50Z. Reason: GVLK.
Information	1/18/2019 10:58:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d29b634f-1ae1-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/18/2019 10:54:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 10:54:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 10:54:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 10:54:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 10:14:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/18/2019 10:07:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/18/2019 8:12:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 6:40:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 6:40:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:51Z. Reason: GVLK.
Warning	1/18/2019 6:37:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 6:35:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 6:35:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 6:35:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 6:35:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 6:14:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 6:14:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 5:58:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e8e6910c-1ab7-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/18/2019 4:58:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 4:34:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 4:34:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:57Z. Reason: GVLK.
Information	1/18/2019 4:29:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 4:29:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 4:29:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 4:29:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 3:53:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 3:53:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:56Z. Reason: GVLK.
Information	1/18/2019 3:48:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 3:48:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 3:48:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 3:48:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2019 3:48:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2019 3:48:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:08Z. Reason: GVLK.
Information	1/18/2019 3:43:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2019 3:43:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 3:43:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2019 3:43:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/18/2019 3:14:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/18/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/18/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 35483)(?)])(1 )(2 )]

"
Information	1/18/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/18/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 35483)(?)])(1 )(2 )]

"
Information	1/18/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 35483)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2019 2:14:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 2:14:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2019 2:14:12 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/18/2019 1:36:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2019 12:57:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff6e05b3-1a8d-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/18/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/17/2019 11:43:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 10:14:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 10:14:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 10:14:06 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/17/2019 9:54:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 7:57:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15b81dde-1a64-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/17/2019 7:54:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/17/2019 6:21:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 6:14:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2019 4:40:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 4:21:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2019 4:21:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:23Z. Reason: GVLK.
Information	1/17/2019 4:16:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2019 4:16:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2019 4:16:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2019 4:16:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/17/2019 3:31:31 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/17/2019 3:31:15 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 29828, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/17/2019 3:30:27 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/17/2019 3:30:27 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	1/17/2019 3:01:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 2:57:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2c0db076-1a3a-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/17/2019 2:14:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 2:14:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/17/2019 2:14:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2019 1:04:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 12:46:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9138.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/17/2019 12:44:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:43:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:41:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:41:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:41:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:40:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:27:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:26:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:19:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:18:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:16:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:16:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:12:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 12:11:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/17/2019 12:01:07 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/17/2019 12:00:57 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/17/2019 12:00:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/17/2019 11:38:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/17/2019 11:38:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/17/2019 11:09:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 10:14:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 10:13:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 10:13:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 9:57:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 424ea103-1a10-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/17/2019 9:34:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/17/2019 7:39:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 6:13:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 6:13:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 6:13:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2019 6:07:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 5:49:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2019 5:49:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:28Z. Reason: GVLK.
Information	1/17/2019 5:44:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2019 5:44:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2019 5:44:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2019 5:44:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/17/2019 4:57:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 587dd275-19e6-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/17/2019 4:16:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 4:10:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2019 4:10:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:48Z. Reason: GVLK.
Information	1/17/2019 4:05:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2019 4:05:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2019 4:05:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2019 4:05:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/17/2019 4:04:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2019 4:04:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:36Z. Reason: GVLK.
Information	1/17/2019 3:59:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2019 3:59:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2019 3:59:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2019 3:59:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/17/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/17/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 36923)(?)])(1 )(2 )]

"
Information	1/17/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/17/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 36923)(?)])(1 )(2 )]

"
Information	1/17/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 36923)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	1/17/2019 2:29:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 2:13:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 2:13:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/17/2019 2:13:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2019 1:42:59 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/17/2019 1:41:04 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	1/17/2019 12:46:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2019 12:03:10 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/16/2019 11:57:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6eb74a39-19bc-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/16/2019 10:58:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 10:13:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:13:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:13:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:13:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:13:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2019 9:21:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/16/2019 7:28:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 6:57:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 84dacf09-1992-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/16/2019 6:13:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:13:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:13:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:13:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:13:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/16/2019 6:12:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2019 5:30:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 4:31:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2019 4:31:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:22Z. Reason: GVLK.
Information	1/16/2019 4:26:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2019 4:26:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2019 4:26:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2019 4:26:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/16/2019 3:30:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 2:13:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 2:13:41 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/16/2019 2:13:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 2:12:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/16/2019 1:57:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9b21f85a-1968-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/16/2019 1:35:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 1:13:15 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/16/2019 1:13:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/16/2019 12:53:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2019 12:53:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:03Z. Reason: GVLK.
Information	1/16/2019 12:48:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2019 12:48:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2019 12:48:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2019 12:48:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/16/2019 12:41:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9137.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/16/2019 12:27:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/16/2019 12:26:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/16/2019 12:08:30 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/16/2019 12:08:14 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/16/2019 12:08:14 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/16/2019 11:43:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 10:13:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:12:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:12:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 10:12:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2019 9:55:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 8:57:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b0e05ac4-193e-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/16/2019 8:19:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/16/2019 6:41:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 6:13:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:12:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 6:12:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2019 4:53:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 4:16:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2019 4:16:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:35Z. Reason: GVLK.
Information	1/16/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2019 4:11:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/16/2019 4:10:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2019 4:10:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:39Z. Reason: GVLK.
Information	1/16/2019 4:05:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2019 4:05:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2019 4:05:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2019 4:05:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/16/2019 3:57:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c72a4bae-1914-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/16/2019 3:05:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 2:33:48 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Error	1/16/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/16/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 38363)(?)])(1 )(2 )]

"
Information	1/16/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/16/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 38363)(?)])(1 )(2 )]

"
Information	1/16/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 38363)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2019 2:32:01 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/16/2019 2:12:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2019 2:12:57 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/16/2019 2:12:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2019 1:15:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2019 12:03:14 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/15/2019 11:19:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 10:57:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dd6a843e-18ea-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/15/2019 10:12:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 10:12:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 10:12:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 10:12:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:24Z. Reason: GVLK.
Information	1/15/2019 10:07:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 10:07:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 10:07:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 10:07:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/15/2019 9:27:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/15/2019 7:55:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/15/2019 6:21:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 6:12:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 6:12:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 5:57:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f3b0212b-18c0-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/15/2019 4:33:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/15/2019 2:57:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 2:50:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/15/2019 2:50:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 2:50:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 2:41:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:41:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:41:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:39:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:33:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:33:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:23:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:22:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:18:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:17:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:15:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:15:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:13:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:12:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/15/2019 2:12:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 2:12:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:12:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/15/2019 2:12:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 2:05:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 2:05:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:59Z. Reason: GVLK.
Information	1/15/2019 2:04:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:04:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 2:01:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 2:00:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:59:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 1:59:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 1:59:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 1:59:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 1:57:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:57:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:54:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:53:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:51:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:51:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:31:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:30:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:26:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:25:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/15/2019 1:20:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 1:17:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:16:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:16:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:15:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:14:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:14:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:13:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:12:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:10:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:08:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 1:05:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 1:04:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:57:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 09fcc747-1897-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/15/2019 12:54:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:54:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:53:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:52:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:49:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:49:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:41:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:40:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:38:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:37:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:36:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:35:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:32:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/15/2019 12:32:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/15/2019 12:32:08 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/15/2019 12:31:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9136.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/15/2019 12:08:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/15/2019 12:07:22 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/15/2019 11:25:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 10:12:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 10:12:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2019 9:53:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 9:21:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 9:21:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:43Z. Reason: GVLK.
Information	1/15/2019 9:17:29 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/15/2019 9:16:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 9:16:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 9:16:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 9:16:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 9:13:15 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎01‎-‎15T03:42:46.509422000Z.
Information	1/15/2019 9:13:15 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 5464.
Information	1/15/2019 9:13:15 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/15/2019 9:13:15 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	1/15/2019 9:13:15 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4480072. Installation success or error status: 0.
Information	1/15/2019 9:13:15 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4480072' installed successfully.
Information	1/15/2019 9:13:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:13:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:12:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎15T03:42:46.509422000Z.
Information	1/15/2019 9:12:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 5464.
Information	1/15/2019 9:10:55 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2019‎-‎01‎-‎15T03:38:12.025662500Z.
Information	1/15/2019 9:10:55 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 12052.
Information	1/15/2019 9:10:55 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/15/2019 9:10:55 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	1/15/2019 9:10:55 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4480055. Installation success or error status: 0.
Information	1/15/2019 9:10:55 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4480055' installed successfully.
Information	1/15/2019 9:10:50 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/15/2019 9:09:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:33 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:33 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:22 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/15/2019 9:09:22 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00005.log
Information	1/15/2019 9:09:18 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/15/2019 9:09:18 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:13 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	1/15/2019 9:09:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/15/2019 9:09:13 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00004.log
Information	1/15/2019 9:09:10 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/15/2019 9:09:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:09:01 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/15/2019 9:09:01 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/15/2019 9:08:57 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	1/15/2019 9:08:52 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:08:52 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/15/2019 9:08:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 9:08:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:43Z. Reason: GVLK.
Information	1/15/2019 9:08:12 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎15T03:38:12.025662500Z.
Information	1/15/2019 9:08:11 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 12052.
Information	1/15/2019 9:03:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 9:03:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 9:03:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 9:03:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/15/2019 8:01:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 7:57:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2021d6e6-186d-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/15/2019 6:12:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 6:12:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 6:12:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:15Z. Reason: GVLK.
Information	1/15/2019 6:12:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2019 6:07:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 6:07:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 6:07:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 6:07:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 6:07:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 4:54:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 4:54:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:28Z. Reason: GVLK.
Information	1/15/2019 4:45:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 4:45:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 4:45:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 4:45:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 4:13:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2019 4:13:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:47Z. Reason: GVLK.
Warning	1/15/2019 4:09:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 4:08:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2019 4:08:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 4:08:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 4:08:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2019 2:57:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 366169e0-1843-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/15/2019 2:37:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/15/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/15/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 39803)(?)])(1 )(2 )]

"
Information	1/15/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/15/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 39803)(?)])(1 )(2 )]

"
Information	1/15/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 39803)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2019 2:32:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/15/2019 2:32:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2019 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/15/2019 2:28:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 2:12:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2019 2:12:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/15/2019 2:12:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2019 12:34:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2019 12:03:09 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/14/2019 10:41:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 10:12:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 10:12:00 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/14/2019 10:12:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 9:57:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4ca1a599-1819-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/14/2019 8:49:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 8:02:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 8:02:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:37:16Z. Reason: GVLK.
Information	1/14/2019 7:57:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/14/2019 7:57:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 7:57:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 7:57:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/14/2019 7:01:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 6:11:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/14/2019 5:21:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 4:57:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 62ec15eb-17ef-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/14/2019 3:47:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 3:30:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/14/2019 3:30:40 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/14/2019 3:30:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 29752, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/14/2019 3:30:12 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/14/2019 2:23:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 2:18:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40536)(?)])(1 )(2 )]

"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40536)(?)])(1 )(2 )]

"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40536)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 2:18:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/14/2019 2:16:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 2:11:53 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	1/14/2019 2:11:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 2:11:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/14/2019 2:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40543)(?)])(1 )(2 )]

"
Information	1/14/2019 2:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/14/2019 2:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40543)(?)])(1 )(2 )]

"
Information	1/14/2019 2:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 40543)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 2:11:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/14/2019 2:11:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 2:11:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/14/2019 2:03:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 12:22:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/14/2019 12:22:13 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/14/2019 12:13:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 12:10:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9135.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/14/2019 12:03:38 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/14/2019 11:57:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79341ce3-17c5-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/14/2019 11:53:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 11:53:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/14/2019 10:26:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 10:12:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/14/2019 10:12:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 10:12:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-21T04:36:19Z. Reason: GVLK.
Information	1/14/2019 10:07:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 10:07:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 10:07:18 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/01/14 04:37"
Information	1/14/2019 10:07:17 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/01/14 04:37, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/14/2019 10:02:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/14/2019 10:02:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 10:02:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 10:02:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/14/2019 8:53:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 8:53:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:14Z. Reason: GVLK.
Information	1/14/2019 8:48:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/14/2019 8:48:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 8:48:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 8:48:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/14/2019 8:31:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 7:53:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 6:57:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8f866e2c-179b-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/14/2019 6:54:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/14/2019 5:16:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 4:36:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 4:36:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:39Z. Reason: GVLK.
Information	1/14/2019 4:31:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/14/2019 4:31:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 4:31:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 4:31:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/14/2019 3:53:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/14/2019 3:53:41 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/14/2019 3:47:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/14/2019 3:47:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:28Z. Reason: GVLK.
Information	1/14/2019 3:38:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/14/2019 3:38:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 3:38:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 3:38:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/14/2019 3:24:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/14/2019 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/14/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 41243)(?)])(1 )(2 )]

"
Information	1/14/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/14/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 41243)(?)])(1 )(2 )]

"
Information	1/14/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 41243)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/14/2019 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/14/2019 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/14/2019 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/14/2019 1:57:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5c6af6a-1771-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/14/2019 1:28:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/14/2019 12:03:14 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/13/2019 11:53:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/13/2019 11:50:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/13/2019 10:15:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 8:57:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bbff381b-1747-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/13/2019 8:41:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 7:53:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/13/2019 7:07:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/13/2019 5:09:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 4:13:19 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/13/2019 3:57:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d23bc1d8-171d-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/13/2019 3:53:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 3:53:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 3:53:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/13/2019 3:53:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/13/2019 3:18:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/13/2019 1:36:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 1:32:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/13/2019 1:32:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:21Z. Reason: GVLK.
Information	1/13/2019 1:27:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/13/2019 1:27:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/13/2019 1:27:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/13/2019 1:27:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/13/2019 12:31:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9134.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/13/2019 12:30:09 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/13/2019 12:30:09 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/13/2019 12:30:09 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/13/2019 11:58:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 11:53:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 11:53:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 10:57:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e860acaf-16f3-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/13/2019 10:27:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/13/2019 8:27:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 7:53:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 7:53:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/13/2019 6:49:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 5:57:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fe8b877a-16c9-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/13/2019 5:05:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/13/2019 5:05:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:02Z. Reason: GVLK.
Information	1/13/2019 4:55:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/13/2019 4:55:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/13/2019 4:55:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/13/2019 4:55:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/13/2019 4:52:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 4:23:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/13/2019 4:23:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:57Z. Reason: GVLK.
Information	1/13/2019 4:18:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/13/2019 4:18:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/13/2019 4:18:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/13/2019 4:18:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/13/2019 3:53:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/13/2019 3:53:08 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/13/2019 3:04:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/13/2019 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/13/2019 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 42683)(?)])(1 )(2 )]

"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 42683)(?)])(1 )(2 )]

"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 42683)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/13/2019 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/13/2019 1:16:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/13/2019 12:57:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 14c691e7-16a0-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/13/2019 12:03:14 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/12/2019 11:53:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2019 11:34:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/12/2019 11:11:02 PM	Application Error	1000	(100)	"Faulting application name: cscript.exe, version: 5.8.7601.24288, time stamp: 0x5bd3d5b9
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x2570
Faulting application start time: 0x01d4aa9df933df27
Faulting application path: C:\Windows\SysWOW64\cscript.exe
Faulting module path: unknown
Report Id: 3a27ee06-1691-11e9-b9ae-204747d02364"
Information	1/12/2019 10:56:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 10:56:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:32Z. Reason: GVLK.
Information	1/12/2019 10:51:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 10:51:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 10:51:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 10:51:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2019 10:01:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 8:37:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 8:37:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:29Z. Reason: GVLK.
Information	1/12/2019 8:32:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 8:32:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 8:32:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 8:32:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2019 8:04:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 7:57:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2af65071-1676-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/12/2019 7:53:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2019 6:05:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 5:01:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 5:01:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:32Z. Reason: GVLK.
Information	1/12/2019 4:56:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 4:56:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 4:56:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 4:56:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2019 4:09:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/12/2019 3:54:58 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (6) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190111_114956.log
"
Error	1/12/2019 3:54:58 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190111_114956.log
"
Information	1/12/2019 3:53:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 3:52:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 3:52:54 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/12/2019 2:57:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 411ec4d0-164c-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/12/2019 2:18:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 2:15:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 2:15:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:53Z. Reason: GVLK.
Information	1/12/2019 2:10:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 2:10:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 2:10:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 2:10:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/12/2019 12:51:03 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/12/2019 12:18:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 12:17:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9133.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/12/2019 11:52:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 11:52:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 11:52:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2019 10:42:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 9:57:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5732fd97-1622-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/12/2019 8:43:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 7:52:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 7:52:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 7:52:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2019 6:59:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/12/2019 5:13:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 4:57:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d76bc36-15f8-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/12/2019 3:52:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 3:52:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2019 3:52:37 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/12/2019 3:52:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2019 3:37:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 3:37:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 3:37:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:40Z. Reason: GVLK.
Information	1/12/2019 3:32:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 3:32:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 3:32:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 3:32:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/12/2019 3:31:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 3:31:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:36Z. Reason: GVLK.
Information	1/12/2019 3:26:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 3:26:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 3:26:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 3:26:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/12/2019 2:37:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/12/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/12/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44123)(?)])(1 )(2 )]

"
Information	1/12/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/12/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44123)(?)])(1 )(2 )]

"
Information	1/12/2019 2:32:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44123)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 2:32:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2019 2:32:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/12/2019 2:05:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 1:15:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2019 1:15:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:41Z. Reason: GVLK.
Information	1/12/2019 1:10:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2019 1:10:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2019 1:10:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2019 1:10:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2019 12:16:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2019 12:03:14 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/11/2019 11:57:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 83ba8db4-15ce-11e9-b9ae-204747d02364
Report Status: 0"
Information	1/11/2019 11:52:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 11:52:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/11/2019 10:35:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/11/2019 8:46:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 7:52:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 7:52:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 7:52:29 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/11/2019 7:00:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 6:57:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 99f803c9-15a4-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/11/2019 5:21:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 3:57:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 3:54:58 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 41, Deleted: 0, Modified: 4, Compared: 29743, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/11/2019 3:52:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/11/2019 3:52:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/11/2019 3:52:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 3:52:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/11/2019 3:52:35 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/11/2019 3:52:34 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	1/11/2019 3:52:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 3:52:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44763)(?)])(1 )(2 )]

"
Information	1/11/2019 3:52:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2019 3:52:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44763)(?)])(1 )(2 )]

"
Information	1/11/2019 3:52:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44763)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 3:52:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2019 3:52:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 3:52:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/11/2019 3:23:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 1:57:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b01dbab1-157a-11e9-b9ae-204747d02364
Report Status: 0"
Warning	1/11/2019 1:31:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 1:12:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 1:12:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:06Z. Reason: GVLK.
Information	1/11/2019 1:08:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/11/2019 1:07:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 1:07:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 1:07:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 1:07:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 12:42:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 12:42:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:07Z. Reason: GVLK.
Information	1/11/2019 12:37:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 12:37:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 12:37:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 12:37:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 12:27:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9132.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/11/2019 12:12:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 12:12:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 12:12:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:09Z. Reason: GVLK.
Information	1/11/2019 12:07:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44987)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2019 12:07:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44987)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44987)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44988)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2019 12:07:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44988)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44988)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2019 12:07:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 12:07:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 12:07:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 12:07:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 12:07:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 12:07:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 12:01:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 12:00:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 12:00:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:55Z. Reason: GVLK.
Information	1/11/2019 11:57:01 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	1/11/2019 11:56:02 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/11/2019 11:55:52 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	1/11/2019 11:55:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44999)(?)])(1 )(2 )]

"
Information	1/11/2019 11:55:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2019 11:55:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44999)(?)])(1 )(2 )]

"
Information	1/11/2019 11:55:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 44999)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 11:55:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2019 11:55:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 11:55:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 11:55:28 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	1/11/2019 11:55:21 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/11/2019 11:55:19 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/11/2019 11:55:17 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/11/2019 11:55:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/11/2019 11:54:31 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/11/2019 11:54:31 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	1/11/2019 11:54:28 AM	ESENT	302	Logging/Recovery	Windows (8488) Windows: The database engine has successfully completed recovery steps.
Information	1/11/2019 11:54:27 AM	ESENT	301	Logging/Recovery	Windows (8488) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Warning	1/11/2019 11:54:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 11:54:11 AM	ESENT	301	Logging/Recovery	Windows (8488) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS01457.log.
Information	1/11/2019 11:54:11 AM	ESENT	300	Logging/Recovery	Windows (8488) Windows: The database engine is initiating recovery steps.
Information	1/11/2019 11:54:09 AM	ESENT	102	General	Windows (8488) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/11/2019 11:54:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 11:54:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 11:54:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 11:53:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/11/2019 11:53:18 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	1/11/2019 11:53:03 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/11/2019 11:52:50 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9131.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	1/11/2019 11:52:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/11/2019 11:52:39 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/11/2019 11:52:14 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	1/11/2019 11:52:14 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/11/2019 11:52:00 AM	PostgreSQL	0	None	"2019-01-11 11:52:00 IST LOG:  redirecting log output to logging collector process
2019-01-11 11:52:00 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/11/2019 11:51:59 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/11/2019 11:51:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/11/2019 11:51:48 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	1/11/2019 11:51:48 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/11/2019 11:51:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/11/2019 11:51:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	1/11/2019 11:51:31 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/11/2019 11:51:30 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/11/2019 11:51:30 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/11/2019 11:51:30 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/11/2019 11:51:30 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/11/2019 11:51:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/11/2019 11:51:29 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/11/2019 11:51:28 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/11/2019 11:50:58 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	1/11/2019 11:50:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/11/2019 11:50:58 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4640 at 1/7/2019 9:50:57 AM (local) 1/7/2019 4:20:57 AM (UTC). This is an informational message only; no user action is required.
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/11/2019 11:50:57 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/11/2019 11:50:56 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/11/2019 11:50:56 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/11/2019 11:50:56 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/11/2019 11:50:56 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4812.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/11/2019 11:50:48 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	1/11/2019 11:49:07 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/11/2019 11:48:41 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/11/2019 11:48:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/11/2019 11:48:41 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	1/11/2019 10:24:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 10:12:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/11/2019 10:05:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 8:57:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c6bb85a1-1550-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/11/2019 8:44:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/11/2019 7:12:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 6:04:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/11/2019 5:30:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 4:03:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 4:03:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:18Z. Reason: GVLK.
Information	1/11/2019 3:57:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dd030629-1526-11e9-bb59-204747d02364
Report Status: 0"
Information	1/11/2019 3:53:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 3:53:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 3:53:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 3:53:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/11/2019 3:46:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 3:14:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 3:14:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:41Z. Reason: GVLK.
Information	1/11/2019 3:09:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 3:09:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 3:09:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 3:09:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/11/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/11/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 45563)(?)])(1 )(2 )]

"
Information	1/11/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 45563)(?)])(1 )(2 )]

"
Information	1/11/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 45563)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 2:17:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2019 2:17:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:06Z. Reason: GVLK.
Warning	1/11/2019 2:12:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 2:12:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2019 2:12:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2019 2:12:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2019 2:12:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2019 2:04:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2019 2:04:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	1/11/2019 12:39:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2019 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/10/2019 10:57:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f344854a-14fc-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/10/2019 10:54:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 10:04:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2019 9:05:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/10/2019 7:30:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 6:04:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 5:57:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0984b7a9-14d3-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/10/2019 5:47:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/10/2019 4:13:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 2:29:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 2:29:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/10/2019 2:13:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 2:04:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 2:04:41 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/10/2019 1:32:03 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 48, Compared: 29653, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/10/2019 1:30:13 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/10/2019 1:26:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/10/2019 1:26:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/10/2019 1:18:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 1:17:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/10/2019 12:57:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1fb8cc8f-14a9-11e9-bb59-204747d02364
Report Status: 0"
Information	1/10/2019 12:53:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 12:53:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/10/2019 12:51:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 12:50:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/10/2019 12:23:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9131.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	1/10/2019 12:21:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 12:12:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 12:11:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/10/2019 11:35:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 11:35:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/10/2019 11:12:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/10/2019 11:12:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/10/2019 10:50:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 10:17:16 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/10/2019 10:06:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/10/2019 10:06:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/10/2019 10:04:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 10:04:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 9:46:42 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/10/2019 9:46:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	1/10/2019 8:52:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 8:06:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2019 8:06:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:24Z. Reason: GVLK.
Information	1/10/2019 8:01:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2019 8:01:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2019 8:01:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2019 8:01:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/10/2019 7:57:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35d195a7-147f-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/10/2019 6:56:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 6:04:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 5:10:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2019 5:10:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:04Z. Reason: GVLK.
Information	1/10/2019 5:05:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2019 5:05:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2019 5:05:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2019 5:05:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/10/2019 5:04:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2019 5:04:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:58Z. Reason: GVLK.
Information	1/10/2019 4:59:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2019 4:59:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2019 4:59:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2019 4:59:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/10/2019 4:58:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 4:40:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2019 4:40:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:17Z. Reason: GVLK.
Information	1/10/2019 4:35:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2019 4:35:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2019 4:35:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2019 4:35:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/10/2019 3:21:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2019 2:58:15 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/10/2019 2:57:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c1704b8-1455-11e9-bb59-204747d02364
Report Status: 0"
Information	1/10/2019 2:55:54 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/10/2019 2:41:55 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Error	1/10/2019 2:32:13 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/10/2019 2:32:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47003)(?)])(1 )(2 )]

"
Information	1/10/2019 2:32:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/10/2019 2:32:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47003)(?)])(1 )(2 )]

"
Information	1/10/2019 2:32:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47003)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	1/10/2019 2:24:48 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (12) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190107_094946.log
"
Error	1/10/2019 2:24:48 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20190107_094946.log
"
Information	1/10/2019 2:04:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 2:04:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2019 2:04:06 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/10/2019 2:04:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2019 1:42:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/10/2019 12:06:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/9/2019 10:25:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 10:22:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 10:22:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:02Z. Reason: GVLK.
Information	1/9/2019 10:17:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2019 10:17:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 10:17:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 10:16:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/9/2019 10:04:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 10:04:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 9:56:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 622737e2-142b-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/9/2019 8:38:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 7:43:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2019 7:43:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 7:43:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/9/2019 6:39:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 6:04:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 4:56:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7836b764-1401-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/9/2019 4:49:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 4:16:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 4:16:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:58Z. Reason: GVLK.
Information	1/9/2019 4:11:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2019 4:11:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 4:11:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 4:11:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/9/2019 4:01:30 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/9/2019 4:00:39 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/9/2019 4:00:35 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/9/2019 4:00:29 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/9/2019 3:06:35 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	1/9/2019 3:00:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 2:03:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 2:03:47 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/9/2019 2:03:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/9/2019 1:20:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 12:15:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9130.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/9/2019 11:56:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e844028-13d7-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/9/2019 11:33:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 11:20:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 11:15:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47919)(?)])(1 )(2 )]

"
Information	1/9/2019 11:15:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2019 11:15:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47919)(?)])(1 )(2 )]

"
Information	1/9/2019 11:15:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47919)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 11:15:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2019 11:15:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 11:15:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2019 10:55:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 10:50:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47945)(?)])(1 )(2 )]

"
Information	1/9/2019 10:50:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2019 10:50:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47945)(?)])(1 )(2 )]

"
Information	1/9/2019 10:50:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 10:50:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2019 10:50:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 10:50:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2019 10:42:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 10:37:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47957)(?)])(1 )(2 )]

"
Information	1/9/2019 10:37:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2019 10:37:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47957)(?)])(1 )(2 )]

"
Information	1/9/2019 10:37:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 47957)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 10:37:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2019 10:37:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 10:37:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2019 10:10:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/9/2019 10:09:04 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/9/2019 10:09:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/9/2019 10:03:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 10:03:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/9/2019 9:43:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/9/2019 7:47:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 6:56:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4cebf24-13ad-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/9/2019 6:13:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 6:03:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 6:03:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 5:16:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 5:16:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:04Z. Reason: GVLK.
Information	1/9/2019 5:11:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2019 5:11:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 5:11:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 5:11:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/9/2019 5:00:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2019 5:00:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:43Z. Reason: GVLK.
Information	1/9/2019 4:51:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2019 4:51:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 4:51:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 4:51:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/9/2019 4:19:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/9/2019 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 48443)(?)])(1 )(2 )]

"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 48443)(?)])(1 )(2 )]

"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 48443)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2019 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2019 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/9/2019 2:26:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 2:24:37 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/9/2019 2:23:00 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/9/2019 2:03:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 2:03:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 2:03:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 2:03:07 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/9/2019 2:03:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2019 1:56:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb185a0e-1383-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/9/2019 12:52:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2019 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/8/2019 11:17:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 10:03:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 10:03:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/8/2019 10:03:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 10:03:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2019 9:37:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 8:56:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d15cec9c-1359-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/8/2019 7:37:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 6:03:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 6:02:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2019 5:48:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/8/2019 4:17:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 3:56:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7afd7e1-132f-11e9-bb59-204747d02364
Report Status: 0"
Information	1/8/2019 2:55:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/8/2019 2:49:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49145)(?)])(1 )(2 )]

"
Information	1/8/2019 2:49:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/8/2019 2:49:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49145)(?)])(1 )(2 )]

"
Information	1/8/2019 2:49:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 2:49:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2019 2:49:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 2:49:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2019 2:49:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎01‎-‎08T09:19:43.868856500Z.
Information	1/8/2019 2:49:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎08T09:19:43.868856500Z.
Information	1/8/2019 2:39:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2019 2:39:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:49Z. Reason: GVLK.
Information	1/8/2019 2:34:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2019 2:34:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 2:34:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 2:34:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/8/2019 2:32:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 2:03:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 2:02:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 2:02:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 2:02:41 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/8/2019 2:02:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2019 12:33:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 12:31:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9129.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/8/2019 10:56:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fdeeaa74-1305-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/8/2019 10:49:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 10:06:56 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/8/2019 10:06:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/8/2019 10:05:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/8/2019 10:03:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 10:02:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 10:02:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2019 8:54:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/8/2019 6:53:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 6:02:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 6:02:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 6:02:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 5:56:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 10f5072d-12dc-11e9-bb59-204747d02364
Report Status: 0"
Warning	1/8/2019 4:57:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 4:28:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2019 4:28:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:20Z. Reason: GVLK.
Information	1/8/2019 4:23:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2019 4:23:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 4:23:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 4:23:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2019 4:14:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2019 4:14:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:54Z. Reason: GVLK.
Information	1/8/2019 4:05:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2019 4:05:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 4:05:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 4:05:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/8/2019 3:25:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 3:22:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2019 3:22:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:38Z. Reason: GVLK.
Information	1/8/2019 3:17:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2019 3:17:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 3:17:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 3:17:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2019 2:37:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/8/2019 2:32:12 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/8/2019 2:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49883)(?)])(1 )(2 )]

"
Information	1/8/2019 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/8/2019 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49883)(?)])(1 )(2 )]

"
Information	1/8/2019 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 49883)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2019 2:32:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2019 2:32:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2019 2:32:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2019 2:02:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2019 2:02:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/8/2019 2:02:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2019 1:27:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2019 12:56:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27316bec-12b2-11e9-bb59-204747d02364
Report Status: 0"
Information	1/8/2019 12:30:35 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/7/2019 11:42:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 10:02:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2019 10:02:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/7/2019 9:59:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2019 8:11:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 7:56:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d7ba14a-1288-11e9-bb59-204747d02364
Report Status: 0"
Information	1/7/2019 7:02:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 7:02:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:32:20Z. Reason: GVLK.
Information	1/7/2019 6:57:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2019 6:57:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 6:57:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 6:57:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/7/2019 6:36:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 6:04:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2019‎-‎01‎-‎07T12:34:37.833921500Z.
Information	1/7/2019 6:04:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2019‎-‎01‎-‎07T12:34:37.833921500Z.
Information	1/7/2019 6:03:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 6:02:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2019 5:58:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50397)(?)])(1 )(2 )]

"
Information	1/7/2019 5:58:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/7/2019 5:58:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50397)(?)])(1 )(2 )]

"
Information	1/7/2019 5:58:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50397)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 5:58:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/7/2019 5:58:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 5:58:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/7/2019 5:00:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2019 3:03:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 2:56:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53c7e8c5-125e-11e9-bb59-204747d02364
Report Status: 0"
Information	1/7/2019 2:02:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2019 2:02:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/7/2019 2:02:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2019 1:43:50 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/7/2019 1:41:52 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/7/2019 1:31:58 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 29489, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/7/2019 1:30:08 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	1/7/2019 1:15:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 12:30:12 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/7/2019 12:30:12 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/7/2019 11:45:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 11:45:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 11:42:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 11:39:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 11:35:41 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/7/2019 11:34:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	1/7/2019 11:27:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2019 11:11:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 11:11:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:04Z. Reason: GVLK.
Information	1/7/2019 11:08:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 11:06:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2019 11:06:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 11:06:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 11:06:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 11:05:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 11:01:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:56:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:55:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:41:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 10:41:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:04Z. Reason: GVLK.
Information	1/7/2019 10:40:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:39:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:37:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:37:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:36:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:36:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2019 10:36:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:36:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 10:36:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 10:35:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:34:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:34:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:27:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:26:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:25:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:24:09 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9127.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/7/2019 10:23:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:21:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:21:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:20:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 10:20:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:01Z. Reason: GVLK.
Information	1/7/2019 10:17:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:17:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:17:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:16:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:15:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2019 10:15:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:15:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 10:14:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 10:14:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:11:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:11:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 10:11:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-14T04:33:01Z. Reason: GVLK.
Information	1/7/2019 10:08:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:08:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:07:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 10:06:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:05:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:05:12 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/7/2019 10:05:12 AM	ESENT	102	General	Windows (10216) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/7/2019 10:05:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:04:43 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 7808.
Information	1/7/2019 10:04:43 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20069. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	1/7/2019 10:04:43 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	1/7/2019 10:04:43 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20069. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.010.20069). Installation success or error status: 0.
Information	1/7/2019 10:04:43 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.010.20069)' installed successfully.
Information	1/7/2019 10:04:33 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/7/2019 10:04:33 AM	ESENT	103	General	Windows (8896) Windows: The database engine stopped the instance (0).
Information	1/7/2019 10:04:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 7808.
Information	1/7/2019 10:04:13 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8604.
Information	1/7/2019 10:04:13 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20069. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	1/7/2019 10:04:13 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	1/7/2019 10:03:32 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8604.
Information	1/7/2019 10:03:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:03:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:03:11 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2019/01/07 04:33"
Information	1/7/2019 10:03:11 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 0, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/7/2019 10:03:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:03:09 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2019/01/07 04:33, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/7/2019 10:02:45 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1747

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 733

Information	1/7/2019 10:02:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/7/2019 10:02:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:02:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Error	1/7/2019 10:02:04 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/7/2019 10:02:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50873)(?)])(1 )(2 )]

"
Information	1/7/2019 10:02:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/7/2019 10:02:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50873)(?)])(1 )(2 )]

"
Information	1/7/2019 10:02:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50873)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:01:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/7/2019 10:01:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/7/2019 10:00:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50874)(?)])(1 )(2 )]

"
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50874)(?)])(1 )(2 )]

"
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50874)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/7/2019 10:00:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 10:00:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 10:00:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/7/2019 9:55:42 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	1/7/2019 9:55:07 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/7/2019 9:55:05 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/7/2019 9:55:04 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/7/2019 9:55:03 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	1/7/2019 9:54:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/7/2019 9:54:37 AM	ESENT	302	Logging/Recovery	Windows (8896) Windows: The database engine has successfully completed recovery steps.
Information	1/7/2019 9:54:27 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/7/2019 9:54:27 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	1/7/2019 9:54:27 AM	ESENT	301	Logging/Recovery	Windows (8896) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Error	1/7/2019 9:54:26 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/7/2019 9:54:17 AM	ESENT	301	Logging/Recovery	Windows (8896) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0143A.log.
Information	1/7/2019 9:54:17 AM	ESENT	300	Logging/Recovery	Windows (8896) Windows: The database engine is initiating recovery steps.
Information	1/7/2019 9:54:17 AM	ESENT	102	General	Windows (8896) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/7/2019 9:54:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2019 9:54:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 9:54:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2019 9:54:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 9:53:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50881)(?)])(1 )(2 )]

"
Information	1/7/2019 9:53:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/7/2019 9:53:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50881)(?)])(1 )(2 )]

"
Information	1/7/2019 9:53:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 50881)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2019 9:53:49 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/7/2019 9:53:49 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	1/7/2019 9:53:46 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	1/7/2019 9:53:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/7/2019 9:53:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9125.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/7/2019 9:52:49 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	1/7/2019 9:52:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/7/2019 9:52:12 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/7/2019 9:52:12 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/7/2019 9:51:55 AM	PostgreSQL	0	None	Server started and accepting connections

Information	1/7/2019 9:51:53 AM	PostgreSQL	0	None	"2019-01-07 09:51:53 IST LOG:  redirecting log output to logging collector process
2019-01-07 09:51:53 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/7/2019 9:51:44 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/7/2019 9:51:42 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/7/2019 9:51:27 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/7/2019 9:51:26 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/7/2019 9:51:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/7/2019 9:51:25 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4284 at 1/6/2019 9:22:39 AM (local) 1/6/2019 3:52:39 AM (UTC). This is an informational message only; no user action is required.
Information	1/7/2019 9:50:57 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/7/2019 9:50:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/7/2019 9:50:46 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	1/7/2019 9:50:46 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/7/2019 9:50:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/7/2019 9:50:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	1/7/2019 9:50:40 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/7/2019 9:50:39 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/7/2019 9:50:39 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/7/2019 9:50:39 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/7/2019 9:50:39 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4640.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/7/2019 9:50:28 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/7/2019 9:49:23 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/7/2019 9:48:57 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/7/2019 9:48:33 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/6/2019 9:22:46 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	1/7/2019 9:48:33 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/7/2019 9:48:33 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	1/6/2019 9:22:39 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	1/6/2019 9:22:37 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 16180 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/6/2019 9:22:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 2

"
Information	1/6/2019 9:22:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/6/2019 9:22:36 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	1/6/2019 9:20:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2019 9:20:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:57Z. Reason: GVLK.
Information	1/6/2019 9:20:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/6/2019 9:16:57 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:16:54 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:16:49 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:16:26 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:15:43 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:15:38 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/6/2019 9:15:32 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/4/2019 2:48:51 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 2:48:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 2:48:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 2:48:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 2:48:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/4/2019 2:48:42 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/4/2019 2:48:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 54906)(?)])(1 )(2 )]

"
Information	1/4/2019 2:48:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 2:48:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 54906)(?)])(1 )(2 )]

"
Information	1/4/2019 2:48:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 54906)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 2:48:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/4/2019 2:48:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 2:48:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 2:48:34 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/4/2019 2:48:34 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	1/4/2019 2:48:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 2

"
Information	1/4/2019 2:48:28 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/4/2019 2:48:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 2

"
Information	1/4/2019 2:48:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	1/4/2019 2:47:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	1/4/2019 2:47:56 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 13 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1560 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/4/2019 2:47:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	1/4/2019 2:47:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/4/2019 2:47:55 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Error	1/4/2019 2:47:46 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 2:47:43 PM	RasClient	20226	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - cincinnati-01-us.connectge.com which has terminated. The reason code returned on termination is 631.
Warning	1/4/2019 2:19:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2019 1:41:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 1:41:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:08Z. Reason: GVLK.
Information	1/4/2019 1:40:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9125.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	1/4/2019 1:36:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 1:36:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 1:36:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 1:36:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 1:30:48 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/4/2019 1:30:44 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 27, Compared: 29454, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/4/2019 1:29:07 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/4/2019 1:29:07 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/4/2019 1:28:59 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2336.
Information	1/4/2019 1:28:58 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/4/2019 1:11:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 1:11:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:07Z. Reason: GVLK.
Information	1/4/2019 1:06:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 1:06:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 1:06:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 1:06:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:59:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 12:59:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:44Z. Reason: GVLK.
Information	1/4/2019 12:54:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 12:54:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:54:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:54:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:41:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 12:41:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:07Z. Reason: GVLK.
Information	1/4/2019 12:40:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 12:36:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2019 12:36:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 12:36:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:36:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:36:06 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/4/2019 12:36:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/4/2019 12:36:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2019 12:35:42 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 437

Information	1/4/2019 12:35:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2019 12:34:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55041)(?)])(1 )(2 )]

"
Information	1/4/2019 12:34:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:34:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55041)(?)])(1 )(2 )]

"
Information	1/4/2019 12:34:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55041)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	1/4/2019 12:33:09 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 12:32:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]

"
Information	1/4/2019 12:32:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:32:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]

"
Information	1/4/2019 12:32:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:32:14 PM	RasClient	20225	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - cincinnati-01-us.connectge.com to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.238.195
TunnelIpv6Address = None
Dial-in User = .
Information	1/4/2019 12:32:09 PM	RasClient	20224	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	1/4/2019 12:32:09 PM	RasClient	20223	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	1/4/2019 12:32:09 PM	RasClient	20222	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - cincinnati-01-us.connectge.com using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	1/4/2019 12:32:08 PM	RasClient	20221	None	CoId={40780B15-7E7E-4B93-B9F8-422E60E33AD6}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - cincinnati-01-us.connectge.com. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	1/4/2019 12:31:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]

"
Information	1/4/2019 12:31:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:31:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]

"
Information	1/4/2019 12:31:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55043)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:31:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 12:31:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:42Z. Reason: GVLK.
Error	1/4/2019 12:31:35 PM	Microsoft Office 16	2001	None	Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Warning	1/4/2019 12:31:30 PM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	1/4/2019 12:31:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]

"
Information	1/4/2019 12:31:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:31:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]

"
Information	1/4/2019 12:31:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:30:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]

"
Information	1/4/2019 12:30:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:30:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]

"
Information	1/4/2019 12:30:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55044)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	1/4/2019 12:29:29 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/4/2019 12:29:15 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 12:26:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 12:26:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:26:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:26:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:26:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2019 12:26:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:23Z. Reason: GVLK.
Information	1/4/2019 12:25:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:59 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:25:59 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	1/4/2019 12:25:58 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/4/2019 12:25:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55049)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:25:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/4/2019 12:25:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/4/2019 12:25:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:25:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/4/2019 12:25:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:25:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:25:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/4/2019 12:25:32 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/4/2019 12:25:29 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	1/4/2019 12:25:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55049)(?)])(1 )(2 )]

"
Information	1/4/2019 12:25:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:25:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55049)(?)])(1 )(2 )]

"
Information	1/4/2019 12:25:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55049)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:25:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:26 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2336. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:25:26 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	1/4/2019 12:25:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:25:17 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Error	1/4/2019 12:25:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 12:25:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:25:05 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:25:05 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/4/2019 12:24:49 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/4/2019 12:24:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:24:48 PM	ESENT	102	General	Windows (8316) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/4/2019 12:24:47 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:24:47 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:24:47 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/4/2019 12:24:34 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/4/2019 12:24:34 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/4/2019 12:24:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:24:19 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/4/2019 12:24:19 PM	ESENT	103	General	Windows (5596) Windows: The database engine stopped the instance (0).
Information	1/4/2019 12:24:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:24:18 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/4/2019 12:24:18 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Error	1/4/2019 12:24:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/4/2019 12:24:00 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	1/4/2019 12:23:33 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {B0A1E133-582A-4D73-9B50-E4FAF0AFC082}
Error	1/4/2019 12:23:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/4/2019 12:22:33 PM	McLogEvent	257	None	The scan of C:\ProgramData\SquirrelMachineInstalls\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9122.0000.
Information	1/4/2019 12:22:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55052)(?)])(1 )(2 )]

"
Information	1/4/2019 12:22:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2019 12:22:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55052)(?)])(1 )(2 )]

"
Information	1/4/2019 12:22:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 55052)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:22:31 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/4/2019 12:22:31 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/4/2019 12:21:35 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	1/4/2019 12:21:35 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	1/4/2019 12:21:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7652.
Information	1/4/2019 12:20:49 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/4/2019 12:20:49 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/4/2019 12:20:49 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/4/2019 12:20:49 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	1/4/2019 12:20:40 PM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 132 second(s) to handle the notification event (CreateSession).
Information	1/4/2019 12:20:29 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/4/2019 12:20:29 PM	ESENT	102	General	Windows (5596) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/4/2019 12:20:25 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/4/2019 12:20:25 PM	ESENT	103	General	Windows (6436) Windows: The database engine stopped the instance (0).
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:24 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:23 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/4/2019 12:20:19 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:19 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/4/2019 12:20:19 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:19 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:19 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/4/2019 12:20:09 PM	ESENT	302	Logging/Recovery	Windows (6436) Windows: The database engine has successfully completed recovery steps.
Information	1/4/2019 12:20:07 PM	ESENT	301	Logging/Recovery	Windows (6436) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	1/4/2019 12:20:03 PM	ESENT	301	Logging/Recovery	Windows (6436) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS01425.log.
Information	1/4/2019 12:20:02 PM	ESENT	300	Logging/Recovery	Windows (6436) Windows: The database engine is initiating recovery steps.
Information	1/4/2019 12:20:02 PM	ESENT	102	General	Windows (6436) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/4/2019 12:20:02 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	1/4/2019 12:19:57 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/4/2019 12:19:55 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/4/2019 12:19:54 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	1/4/2019 12:19:29 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Warning	1/4/2019 12:19:28 PM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	1/4/2019 12:19:28 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	1/4/2019 12:19:27 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	1/4/2019 12:19:26 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	1/4/2019 12:19:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/4/2019 12:19:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:19:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:18:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2019 12:18:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2019 12:18:21 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	1/4/2019 12:18:20 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (WMPPlayer)
License Id=7d141cc8-75a1-5d14-1583-53c8065e7556"
Information	1/4/2019 12:18:20 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	1/4/2019 12:18:20 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	1/4/2019 12:18:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2019 12:18:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2019 12:18:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2019‎-‎01‎-‎04T06:48:01.934005900Z.
Error	1/4/2019 12:17:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	1/4/2019 12:17:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9122.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	1/4/2019 12:17:36 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/4/2019 12:17:34 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/4/2019 12:17:09 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Error	1/4/2019 12:16:43 PM	Service1	0	None	"Service cannot be started. System.Runtime.InteropServices.COMException (0x80010002): Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementScope.InitializeGuts(Object o)
   at System.Management.ManagementScope.Initialize()
   at System.Management.ManagementObjectSearcher.Initialize()
   at System.Management.ManagementObjectSearcher.Get()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)"
Information	1/4/2019 12:16:38 PM	PostgreSQL	0	None	Server started and accepting connections

Information	1/4/2019 12:16:36 PM	PostgreSQL	0	None	"2019-01-04 12:16:36 IST LOG:  redirecting log output to logging collector process
2019-01-04 12:16:36 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/4/2019 12:16:35 PM	PostgreSQL	0	None	Waiting for server startup...

Information	1/4/2019 12:15:39 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/4/2019 12:15:36 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/4/2019 12:15:35 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:35 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/4/2019 12:15:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/4/2019 12:15:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/4/2019 12:15:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/4/2019 12:15:34 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/4/2019 12:15:34 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/4/2019 12:15:34 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/4/2019 12:15:33 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:32 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/4/2019 12:15:32 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/4/2019 12:15:32 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/4/2019 12:15:32 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/4/2019 12:15:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/4/2019 12:15:27 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/4/2019 12:15:26 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:26 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/4/2019 12:15:26 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/4/2019 12:15:26 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/4/2019 12:15:26 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4668 at 12/31/2018 12:42:14 PM (local) 12/31/2018 7:12:14 AM (UTC). This is an informational message only; no user action is required.
Information	1/4/2019 12:15:22 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/4/2019 12:15:21 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/4/2019 12:15:21 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/4/2019 12:15:21 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/4/2019 12:15:21 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4284.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/4/2019 12:15:07 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/4/2019 12:14:35 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/4/2019 12:14:33 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/4/2019 12:14:24 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/4/2019 12:14:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/4/2019 12:14:24 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/31/2018 12:42:22 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	12/31/2018 12:42:14 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	12/31/2018 12:41:33 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1008 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	12/31/2018 12:41:32 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	12/31/2018 12:41:32 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	12/31/2018 12:41:32 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	12/31/2018 11:36:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/31/2018 11:16:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 11:16:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:07Z. Reason: GVLK.
Information	12/31/2018 11:11:18 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 6980) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11604) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 4296) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5684) cannot be restarted - Application SID does not match Conductor SID..
Information	12/31/2018 11:10:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T05:40:56.415789900Z.
Information	12/31/2018 11:10:54 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎31T05:40:54.761135700Z.
Information	12/31/2018 11:10:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/31/2018 11:10:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 11:10:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/31/2018 11:10:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 11:05:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎31T05:32:38.372635400Z.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 11220.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/31/2018 11:05:53 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4470640. Installation success or error status: 0.
Information	12/31/2018 11:05:53 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4470640' installed successfully.
Information	12/31/2018 11:04:36 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/31/2018 11:04:01 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:01 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:01 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:01 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:04:00 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:59 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:59 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:51 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 11:03:52 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00003.log
Information	12/31/2018 11:03:46 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 11:03:46 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:44 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	12/31/2018 11:03:42 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00002.log
Information	12/31/2018 11:03:42 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 11:03:38 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 11:03:38 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:36 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 11:03:36 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 11:03:31 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	12/31/2018 11:03:26 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:26 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 2852.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: MFPSecure_Tray , Id 5488.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4780.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 2852.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: MFPSecure_Tray , Id 5488.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4780.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4780.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5168.
Information	12/31/2018 11:03:14 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4780.
Information	12/31/2018 11:02:50 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/31/2018 11:02:50 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 6980) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:02:49 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\LRS\VPSX Printer Driver Management\MFPSecureTrayApp\MFPSecure_Tray.exe' (pid 5488) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:02:49 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5168) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 11:02:49 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4780) cannot be restarted - Application SID does not match Conductor SID..
Information	12/31/2018 11:02:38 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T05:32:38.372635400Z.
Information	12/31/2018 11:02:37 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 11220.
Information	12/31/2018 10:50:08 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/31/2018 10:49:50 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎31T05:18:24.445102700Z.
Information	12/31/2018 10:49:50 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎31T05:18:01.146200100Z.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 13148.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/31/2018 10:49:50 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4470500. Installation success or error status: 0.
Information	12/31/2018 10:49:50 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4470500' installed successfully.
Information	12/31/2018 10:49:12 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:49:12 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:49:12 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:49:12 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:49:08 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 10:49:08 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00001.log
Information	12/31/2018 10:49:04 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 10:49:04 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:49:00 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	12/31/2018 10:48:58 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 10:48:59 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00000.log
Information	12/31/2018 10:48:55 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 10:48:55 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:48:52 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/31/2018 10:48:52 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/31/2018 10:48:49 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	12/31/2018 10:48:46 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:48:46 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 6980) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11604) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 4296) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5684) cannot be restarted - Application SID does not match Conductor SID..
Information	12/31/2018 10:48:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T05:18:29.105243300Z.
Information	12/31/2018 10:48:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T05:18:24.445102700Z.
Information	12/31/2018 10:48:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎31T05:18:10.225884500Z.
Information	12/31/2018 10:48:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T05:18:01.146200100Z.
Information	12/31/2018 10:48:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 13148.
Information	12/31/2018 10:46:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9122.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/31/2018 10:46:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 10:45:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:42Z. Reason: GVLK.
Information	12/31/2018 10:35:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/31/2018 10:35:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:35:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/31/2018 10:35:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 10:30:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 10:30:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:32:15Z. Reason: GVLK.
Information	12/31/2018 10:25:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/31/2018 10:25:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:25:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/31/2018 10:25:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 10:24:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 320, Deleted: 0, Modified: 750, Compared: 29299, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/31/2018 10:19:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 10:19:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:33:00Z. Reason: GVLK.
Information	12/31/2018 10:18:42 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 10:16:07 AM	McLogEvent	257	None	The scan of C:\Users\212558710\Desktop\extra_matter\setup\issetupprerequisites\{40b3efee-ab85-46cb-8e97-b609bf8e681a}\jdk-8u77-windows-i586.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9106.0000.
Information	12/31/2018 10:13:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎31T04:43:45.089089200Z.
Information	12/31/2018 10:13:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleUpdateHelper.msi. Client Process Id: 5380.
Information	12/31/2018 10:13:53 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.23. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	12/31/2018 10:13:53 AM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	12/31/2018 10:13:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎31T04:43:45.089089200Z.
Information	12/31/2018 10:13:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleUpdateHelper.msi. Client Process Id: 5380.
Information	12/31/2018 10:13:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleUpdateHelper.msi. Client Process Id: 5380.
Information	12/31/2018 10:13:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.23. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 1638.
Information	12/31/2018 10:13:44 AM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	12/31/2018 10:13:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleUpdateHelper.msi. Client Process Id: 5380.
Error	12/31/2018 10:13:41 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/31/2018 10:13:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60941)(?)])(1 )(2 )]

"
Information	12/31/2018 10:13:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/31/2018 10:13:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60941)(?)])(1 )(2 )]

"
Information	12/31/2018 10:13:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60941)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:09:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/31/2018 10:09:33 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 15

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Information	12/31/2018 10:09:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	12/31/2018 10:08:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60946)(?)])(1 )(2 )]

"
Information	12/31/2018 10:08:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/31/2018 10:08:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60946)(?)])(1 )(2 )]

"
Information	12/31/2018 10:08:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60946)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:08:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/31/2018 10:08:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:08:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/31/2018 10:08:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 10:08:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/31/2018 10:08:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2019-01-07T04:33:04Z. Reason: GVLK.
Information	12/31/2018 10:07:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/31/2018 10:07:46 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/31/2018 10:06:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/31/2018 10:06:37 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/31/2018 10:06:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/31/2018 10:06:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/31/2018 10:05:59 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/31/2018 10:05:57 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 842

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 390

Information	12/31/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/31/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60949)(?)])(1 )(2 )]

"
Information	12/31/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60949)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:05:23 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 42 60949)(?)])(1 )(2 )]

"
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=104149  Grace type=8.
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=aeb14687-6722-49ee-a129-bb21281fc606"
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=5ced4bbe-db82-41bc-a958-c1bc5bc3d36a"
Information	12/31/2018 10:05:20 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/31/2018 10:04:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/31/2018 10:03:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:03:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:03:07 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/12/31 04:32"
Information	12/31/2018 10:02:59 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/12/31 04:32, 0, 1, 229020, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/31/2018 10:02:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14872)(?)])(1 )(2 )]

"
Information	12/31/2018 10:02:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/31/2018 10:02:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14872)(?)])(1 )(2 )]

"
Information	12/31/2018 10:02:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14872)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 10:01:27 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9106.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/31/2018 9:59:48 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/31/2018 9:58:36 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/31/2018 9:58:33 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/31/2018 9:58:33 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/31/2018 9:58:30 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	12/31/2018 9:58:26 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {EC56C813-DC7A-48EE-B457-634395E37D59}
Error	12/31/2018 9:58:26 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {EC56C813-DC7A-48EE-B457-634395E37D59}
Error	12/31/2018 9:58:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/31/2018 9:58:01 AM	ESENT	302	Logging/Recovery	Windows (7464) Windows: The database engine has successfully completed recovery steps.
Information	12/31/2018 9:58:00 AM	ESENT	301	Logging/Recovery	Windows (7464) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/31/2018 9:57:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14877)(?)])(1 )(2 )]

"
Information	12/31/2018 9:57:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/31/2018 9:57:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14877)(?)])(1 )(2 )]

"
Information	12/31/2018 9:57:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 14877)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 9:57:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/31/2018 9:57:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/31/2018 9:57:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 9:57:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/31/2018 9:57:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 229020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/31/2018 9:57:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	12/31/2018 9:57:50 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/31/2018 9:57:49 AM	ESENT	301	Logging/Recovery	Windows (7464) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS01400.log.
Information	12/31/2018 9:57:49 AM	ESENT	300	Logging/Recovery	Windows (7464) Windows: The database engine is initiating recovery steps.
Information	12/31/2018 9:57:47 AM	ESENT	102	General	Windows (7464) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/31/2018 9:57:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/31/2018 9:57:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: mfevtp
P2: mfevtps.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69f80eab-0cb4-11e9-a314-204747d02364
Report Status: 0"
Error	12/31/2018 9:56:29 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/31/2018 9:56:19 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	12/31/2018 9:56:18 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/31/2018 9:56:05 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/31/2018 9:56:04 AM	PostgreSQL	0	None	"2018-12-31 09:56:04 IST LOG:  redirecting log output to logging collector process
2018-12-31 09:56:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/31/2018 9:56:00 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/31/2018 9:55:58 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/31/2018 9:55:58 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/31/2018 9:55:40 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	12/31/2018 9:55:40 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	12/31/2018 9:55:26 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:23 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/31/2018 9:55:23 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/31/2018 9:55:23 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/31/2018 9:55:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/31/2018 9:55:22 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/31/2018 9:55:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/31/2018 9:55:21 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/31/2018 9:55:20 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:20 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/31/2018 9:55:19 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/31/2018 9:55:18 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/31/2018 9:55:13 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/31/2018 9:55:13 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4480 at 12/14/2018 3:43:22 PM (local) 12/14/2018 10:13:22 AM (UTC). This is an informational message only; no user action is required.
Information	12/31/2018 9:55:13 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/31/2018 9:55:01 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/31/2018 9:55:01 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/31/2018 9:55:01 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/31/2018 9:55:01 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/31/2018 9:55:01 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/31/2018 9:54:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/31/2018 9:54:55 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/31/2018 9:54:55 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/31/2018 9:54:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/31/2018 9:54:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4668.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/31/2018 9:54:48 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/31/2018 9:53:47 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/31/2018 9:53:32 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/31/2018 9:53:14 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/31/2018 9:53:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/31/2018 9:53:14 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/14/2018 3:43:25 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	12/14/2018 3:43:22 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	12/14/2018 3:42:47 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	12/14/2018 3:42:46 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 32 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 188 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2292 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4640 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4640 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2116 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	12/14/2018 3:42:46 PM	MTAService.OnSessionChange	0	None	3:42:46 PM - Logoff
Information	12/14/2018 3:42:46 PM	MTAService.OnSessionChange	0	None	3:42:46 PM - Session change notice received: SessionLogoff Session ID: 1
Information	12/14/2018 3:42:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	12/14/2018 3:42:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	12/14/2018 3:42:43 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	12/14/2018 3:42:35 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	12/14/2018 3:33:03 PM	MTAService.OnSessionChange	0	None	3:33:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 3:23:51 PM	MTAService.OnSessionChange	0	None	3:23:51 PM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 3:08:18 PM	MTAService.OnSessionChange	0	None	3:08:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 3:02:11 PM	MTAService.OnSessionChange	0	None	3:02:11 PM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 2:52:04 PM	MTAService.OnSessionChange	0	None	2:52:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 2:46:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	12/14/2018 2:44:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 2:42:16 PM	MTAService.OnSessionChange	0	None	2:42:16 PM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 2:41:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39073)(?)])(1 )(2 )]

"
Information	12/14/2018 2:41:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2018 2:41:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39073)(?)])(1 )(2 )]

"
Information	12/14/2018 2:41:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39073)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 2:41:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2018 2:41:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 2:41:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2018 2:06:18 PM	MTAService.OnSessionChange	0	None	2:06:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 1:47:48 PM	MTAService.OnSessionChange	0	None	1:47:48 PM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 1:46:56 PM	MTAService.OnSessionChange	0	None	1:46:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 1:32:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/14/2018 1:15:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4bd0efe2-ff74-11e8-996d-204747d02364
Report Status: 0"
Warning	12/14/2018 12:50:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 12:32:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9106.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/14/2018 12:04:44 PM	MTAService.OnSessionChange	0	None	12:04:44 PM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 11:48:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/14/2018 11:47:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/14/2018 11:44:07 AM	MTAService.OnSessionChange	0	None	11:44:07 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 11:34:50 AM	MTAService.OnSessionChange	0	None	11:34:50 AM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 11:14:58 AM	MTAService.OnSessionChange	0	None	11:14:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 11:07:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/14/2018 11:04:18 AM	MTAService.OnSessionChange	0	None	11:04:18 AM - Session change notice received: SessionLock Session ID: 1
Warning	12/14/2018 11:01:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 10:49:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2018 10:44:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39310)(?)])(1 )(2 )]

"
Information	12/14/2018 10:44:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2018 10:44:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39310)(?)])(1 )(2 )]

"
Information	12/14/2018 10:44:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39310)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 10:44:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2018 10:44:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 10:44:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2018 10:08:28 AM	MTAService.OnSessionChange	0	None	10:08:28 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/14/2018 9:37:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2018 9:36:04 AM	MTAService.OnSessionChange	0	None	9:36:04 AM - Session change notice received: SessionLock Session ID: 1
Information	12/14/2018 9:32:25 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 46

Information	12/14/2018 9:32:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/14/2018 9:32:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/14/2018 9:32:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39383)(?)])(1 )(2 )]

"
Information	12/14/2018 9:32:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2018 9:32:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39383)(?)])(1 )(2 )]

"
Information	12/14/2018 9:32:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39383)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 9:32:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2018 9:32:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 9:32:04 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2018 9:31:55 AM	MTAService.OnSessionChange	0	None	9:31:55 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/14/2018 9:27:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 8:15:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 620c15ee-ff4a-11e8-996d-204747d02364
Report Status: 0"
Warning	12/14/2018 7:51:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/14/2018 6:16:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 4:54:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2018 4:54:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:11Z. Reason: GVLK.
Information	12/14/2018 4:49:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2018 4:49:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 4:49:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 4:49:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2018 4:48:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2018 4:48:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:51Z. Reason: GVLK.
Information	12/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 4:43:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/14/2018 4:22:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 3:18:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2018 3:18:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:06Z. Reason: GVLK.
Information	12/14/2018 3:15:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 78471af8-ff20-11e8-996d-204747d02364
Report Status: 0"
Information	12/14/2018 3:13:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2018 3:13:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 3:13:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 3:13:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/14/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/14/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39803)(?)])(1 )(2 )]

"
Information	12/14/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39803)(?)])(1 )(2 )]

"
Information	12/14/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39803)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/14/2018 2:25:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/14/2018 12:34:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/13/2018 11:44:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 11:44:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:16Z. Reason: GVLK.
Information	12/13/2018 11:39:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2018 11:39:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 11:39:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 11:39:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/13/2018 11:00:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 10:15:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e8b7d17-fef6-11e8-996d-204747d02364
Report Status: 0"
Warning	12/13/2018 9:22:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/13/2018 7:38:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 6:51:36 PM	MTAService.OnSessionChange	0	None	6:51:36 PM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 5:57:39 PM	MTAService.OnSessionChange	0	None	5:57:39 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/13/2018 5:39:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 5:15:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4cde336-fecc-11e8-996d-204747d02364
Report Status: 0"
Information	12/13/2018 4:36:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 4:35:06 PM	MTAService.OnSessionChange	0	None	4:35:06 PM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 4:31:19 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 608

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 624

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	12/13/2018 4:31:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 4:30:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40404)(?)])(1 )(2 )]

"
Information	12/13/2018 4:30:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2018 4:30:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40404)(?)])(1 )(2 )]

"
Information	12/13/2018 4:30:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40404)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 4:30:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2018 4:30:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 4:30:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 4:28:57 PM	MTAService.OnSessionChange	0	None	4:28:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/13/2018 4:25:53 PM	MTAService.OnSessionChange	0	None	4:25:53 PM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 4:19:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 4:19:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:20Z. Reason: GVLK.
Information	12/13/2018 4:15:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 4:14:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2018 4:14:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 4:14:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 4:14:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 4:10:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2018 4:10:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 4:10:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 3:52:38 PM	MTAService.OnSessionChange	0	None	3:52:38 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/13/2018 3:42:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 3:13:52 PM	MTAService.OnSessionChange	0	None	3:13:52 PM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 2:55:33 PM	MTAService.OnSessionChange	0	None	2:55:33 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/13/2018 2:12:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 1:11:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 1:11:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 1:08:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 1:06:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 1:06:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 1:01:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 1:01:44 PM	MTAService.OnSessionChange	0	None	1:01:44 PM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 1:01:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 12:49:38 PM	MTAService.OnSessionChange	0	None	12:49:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/13/2018 12:46:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9105.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/13/2018 12:42:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 12:42:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/13/2018 12:22:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 12:15:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb10fa5d-fea2-11e8-996d-204747d02364
Report Status: 0"
Information	12/13/2018 11:49:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 11:49:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 11:45:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 11:45:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 11:42:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/13/2018 11:42:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/13/2018 11:32:36 AM	MTAService.OnSessionChange	0	None	11:32:36 AM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 11:29:54 AM	MTAService.OnSessionChange	0	None	11:29:54 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/13/2018 10:40:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 5948.
Information	12/13/2018 10:40:36 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20064. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	12/13/2018 10:40:36 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	12/13/2018 10:40:36 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20064. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.010.20064). Installation success or error status: 0.
Information	12/13/2018 10:40:36 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.010.20064)' installed successfully.
Information	12/13/2018 10:40:35 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/13/2018 10:40:28 AM	ESENT	102	General	Windows (9356) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/13/2018 10:39:58 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/13/2018 10:39:58 AM	ESENT	103	General	Windows (6924) Windows: The database engine stopped the instance (0).
Information	12/13/2018 10:39:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 5948.
Information	12/13/2018 10:38:28 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6716.
Information	12/13/2018 10:38:28 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.010.20064. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	12/13/2018 10:38:28 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	12/13/2018 10:38:13 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6716.
Warning	12/13/2018 10:29:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 10:27:26 AM	MTAService.OnSessionChange	0	None	10:27:26 AM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 9:59:02 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/13/2018 9:58:32 AM	MTAService.OnSessionChange	0	None	9:58:32 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/13/2018 9:34:36 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 17, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/13/2018 9:34:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/13/2018 9:34:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/13/2018 9:28:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 9:24:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/13/2018 9:24:15 AM	MTAService.OnSessionChange	0	None	9:24:15 AM - Session change notice received: SessionLock Session ID: 1
Information	12/13/2018 9:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40831)(?)])(1 )(2 )]

"
Information	12/13/2018 9:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2018 9:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40831)(?)])(1 )(2 )]

"
Information	12/13/2018 9:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40831)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 9:23:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2018 9:23:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 9:23:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 9:22:59 AM	MTAService.OnSessionChange	0	None	9:22:59 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/13/2018 9:08:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 9:08:14 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	12/13/2018 8:47:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 8:31:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/13/2018 8:31:59 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/13/2018 8:31:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 29054, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/13/2018 8:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/13/2018 7:15:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d14dcfcb-fe78-11e8-996d-204747d02364
Report Status: 0"
Warning	12/13/2018 7:07:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 6:43:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 6:43:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:38Z. Reason: GVLK.
Information	12/13/2018 6:38:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2018 6:38:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 6:38:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 6:38:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/13/2018 5:12:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 5:08:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 5:08:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 4:27:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 4:27:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:33Z. Reason: GVLK.
Information	12/13/2018 4:22:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2018 4:22:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 4:22:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 4:22:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 4:21:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2018 4:21:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:19Z. Reason: GVLK.
Information	12/13/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 4:16:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/13/2018 3:29:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 3:08:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/13/2018 3:05:59 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	12/13/2018 2:37:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/13/2018 2:32:09 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41243)(?)])(1 )(2 )]

"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41243)(?)])(1 )(2 )]

"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41243)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2018 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2018 2:15:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7723ac8-fe4e-11e8-996d-204747d02364
Report Status: 0"
Warning	12/13/2018 1:48:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2018 1:08:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 1:08:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 1:08:00 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/13/2018 1:08:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/12/2018 11:49:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/12/2018 10:10:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 9:15:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fda4af83-fe24-11e8-996d-204747d02364
Report Status: 0"
Information	12/12/2018 9:08:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 9:07:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 9:07:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/12/2018 8:43:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 8:43:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:01Z. Reason: GVLK.
Information	12/12/2018 8:38:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2018 8:38:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 8:38:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 8:38:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/12/2018 8:37:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 8:12:23 PM	MTAService.OnSessionChange	0	None	8:12:23 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 7:49:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T14:19:55.982561800Z.
Information	12/12/2018 7:49:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T14:19:55.982561800Z.
Information	12/12/2018 7:49:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T14:19:43.309294600Z.
Information	12/12/2018 7:49:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T14:19:43.309294600Z.
Information	12/12/2018 7:49:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T14:19:43.075271200Z.
Information	12/12/2018 7:49:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T14:19:43.075271200Z.
Information	12/12/2018 7:49:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T14:19:42.414205100Z.
Information	12/12/2018 7:49:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T14:19:42.414205100Z.
Information	12/12/2018 7:49:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T14:19:41.075071200Z.
Information	12/12/2018 7:49:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T14:19:41.075071200Z.
Warning	12/12/2018 7:01:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 6:20:20 PM	MTAService.OnSessionChange	0	None	6:20:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 6:07:45 PM	MTAService.OnSessionChange	0	None	6:07:45 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 6:05:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T12:35:03.268287500Z.
Information	12/12/2018 6:05:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T12:35:03.268287500Z.
Information	12/12/2018 6:05:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T12:35:02.812241900Z.
Information	12/12/2018 6:05:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T12:35:02.812241900Z.
Information	12/12/2018 6:05:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T12:35:02.659226600Z.
Information	12/12/2018 6:05:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T12:35:02.659226600Z.
Information	12/12/2018 6:05:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T12:35:01.746135300Z.
Information	12/12/2018 6:05:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T12:35:01.746135300Z.
Information	12/12/2018 6:05:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎12T12:35:00.140974800Z.
Information	12/12/2018 6:05:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎12T12:35:00.140974800Z.
Information	12/12/2018 5:56:45 PM	MTAService.OnSessionChange	0	None	5:56:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 5:51:46 PM	MTAService.OnSessionChange	0	None	5:51:46 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 5:51:05 PM	MTAService.OnSessionChange	0	None	5:51:05 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/12/2018 5:15:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 5:07:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 5:07:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 4:51:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 4:47:08 PM	MTAService.OnSessionChange	0	None	4:47:08 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41828)(?)])(1 )(2 )]

"
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41828)(?)])(1 )(2 )]

"
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41828)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2018 4:46:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 4:46:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/12/2018 4:45:55 PM	MTAService.OnSessionChange	0	None	4:45:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 4:15:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 13efdf05-fdfb-11e8-996d-204747d02364
Report Status: 0"
Information	12/12/2018 3:57:57 PM	MTAService.OnSessionChange	0	None	3:57:57 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 3:44:50 PM	MTAService.OnSessionChange	0	None	3:44:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/12/2018 3:25:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 2:35:11 PM	MTAService.OnSessionChange	0	None	2:35:11 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 2:22:19 PM	MTAService.OnSessionChange	0	None	2:22:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 2:13:18 PM	MTAService.OnSessionChange	0	None	2:13:18 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 2:08:29 PM	MTAService.OnSessionChange	0	None	2:08:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 2:07:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 2:06:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/12/2018 1:44:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 1:08:40 PM	MTAService.OnSessionChange	0	None	1:08:40 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 1:07:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/12/2018 1:07:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 1:07:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 1:05:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 1:05:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 1:01:07 PM	MTAService.OnSessionChange	0	None	1:01:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 12:45:12 PM	MTAService.OnSessionChange	0	None	12:45:12 PM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 12:41:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9104.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/12/2018 12:39:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:38:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:29:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:29:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:29:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:28:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:25:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:25:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:19:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:18:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:13:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:12:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 12:05:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 12:04:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/12/2018 11:56:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 11:48:04 AM	MTAService.OnSessionChange	0	None	11:48:04 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 11:43:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 11:43:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 11:41:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 11:41:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 11:34:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 11:34:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:38Z. Reason: GVLK.
Information	12/12/2018 11:33:13 AM	MTAService.OnSessionChange	0	None	11:33:13 AM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 11:29:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2018 11:29:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 11:29:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 11:29:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/12/2018 11:17:44 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎12T05:47:39.020083600Z.
Information	12/12/2018 11:17:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 22448.
Information	12/12/2018 11:17:44 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/12/2018 11:17:44 AM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	12/12/2018 11:17:39 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎12T05:47:39.020083600Z.
Information	12/12/2018 11:17:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 22448.
Information	12/12/2018 11:17:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎12T05:47:01.612343200Z.
Information	12/12/2018 11:17:10 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 22448.
Information	12/12/2018 11:17:10 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/12/2018 11:17:10 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	12/12/2018 11:17:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎12T05:47:01.612343200Z.
Information	12/12/2018 11:16:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 22448.
Information	12/12/2018 11:15:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 29debd01-fdd1-11e8-996d-204747d02364
Report Status: 0"
Information	12/12/2018 10:59:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 10:59:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 10:57:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/12/2018 10:57:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/12/2018 10:13:38 AM	MTAService.OnSessionChange	0	None	10:13:38 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/12/2018 10:05:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 9:25:04 AM	MTAService.OnSessionChange	0	None	9:25:04 AM - Session change notice received: SessionLock Session ID: 1
Information	12/12/2018 9:15:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/12/2018 9:14:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/12/2018 9:14:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/12/2018 9:14:29 AM	MTAService.OnSessionChange	0	None	9:14:29 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/12/2018 9:07:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 9:07:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/12/2018 9:07:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 9:07:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/12/2018 8:19:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 7:41:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 7:41:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:47:56Z. Reason: GVLK.
Information	12/12/2018 7:36:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2018 7:36:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 7:36:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 7:36:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/12/2018 6:20:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 6:15:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 401d676a-fda7-11e8-996d-204747d02364
Report Status: 0"
Information	12/12/2018 5:07:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 5:07:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/12/2018 4:41:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 4:03:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 4:03:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:47:56Z. Reason: GVLK.
Information	12/12/2018 3:58:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2018 3:58:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 3:58:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 3:58:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/12/2018 3:57:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2018 3:57:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:47:59Z. Reason: GVLK.
Information	12/12/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/12/2018 3:01:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/12/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42683)(?)])(1 )(2 )]

"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42683)(?)])(1 )(2 )]

"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42683)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2018 2:32:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/12/2018 1:15:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 565c86a8-fd7d-11e8-996d-204747d02364
Report Status: 0"
Warning	12/12/2018 1:12:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2018 1:07:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 1:07:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/11/2018 11:30:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/11/2018 9:32:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 9:07:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 9:07:32 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/11/2018 9:07:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 8:32:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2018 8:32:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:29Z. Reason: GVLK.
Information	12/11/2018 8:27:29 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	12/11/2018 8:27:29 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	12/11/2018 8:27:29 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	12/11/2018 8:27:29 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	12/11/2018 8:27:29 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	12/11/2018 8:27:29 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	12/11/2018 8:27:26 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	12/11/2018 8:27:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2018 8:27:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2018 8:27:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2018 8:27:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/11/2018 8:27:24 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	12/11/2018 8:15:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6c8c6684-fd53-11e8-996d-204747d02364
Report Status: 0"
Information	12/11/2018 8:02:45 PM	MTAService.OnSessionChange	0	None	8:02:45 PM - Session change notice received: SessionLock Session ID: 1
Information	12/11/2018 8:02:27 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	12/11/2018 7:56:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:34.610969700Z.
Information	12/11/2018 7:56:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:34.610969700Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:31.359644600Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:31.359644600Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:31.204629100Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:31.204629100Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:31.057614400Z.
Information	12/11/2018 7:56:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:31.057614400Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:30.902598900Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:30.902598900Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:30.648573500Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:30.648573500Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:30.299538600Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:30.299538600Z.
Information	12/11/2018 7:56:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:29.996508300Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:29.996508300Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:29.838492500Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:29.838492500Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:29.632471900Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:29.632471900Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:29.462454900Z.
Information	12/11/2018 7:56:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:29.462454900Z.
Information	12/11/2018 7:56:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:28.637372400Z.
Information	12/11/2018 7:56:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:28.637372400Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:20.940602800Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:20.940602800Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:20.767585500Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:20.767585500Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:20.593568100Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:20.593568100Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:20.413550100Z.
Information	12/11/2018 7:56:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:20.413550100Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:19.970505800Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:19.970505800Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:19.688477600Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:19.688477600Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:19.367445500Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:19.367445500Z.
Information	12/11/2018 7:56:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:18.992408000Z.
Information	12/11/2018 7:56:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:18.992408000Z.
Information	12/11/2018 7:56:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:18.542363000Z.
Information	12/11/2018 7:56:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:18.542363000Z.
Information	12/11/2018 7:56:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:17.970305800Z.
Information	12/11/2018 7:56:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:17.970305800Z.
Information	12/11/2018 7:56:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎11T14:26:16.396148400Z.
Information	12/11/2018 7:56:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎11T14:26:16.396148400Z.
Warning	12/11/2018 7:42:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/11/2018 5:48:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 5:40:51 PM	MTAService.OnSessionChange	0	None	5:40:51 PM - Session change notice received: SessionUnlock Session ID: 1
Error	12/11/2018 5:07:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/11/2018 5:07:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 5:07:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 5:02:48 PM	MTAService.OnSessionChange	0	None	5:02:48 PM - Session change notice received: SessionLock Session ID: 1
Information	12/11/2018 5:00:34 PM	MTAService.OnSessionChange	0	None	5:00:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/11/2018 4:50:42 PM	MTAService.OnSessionChange	0	None	4:50:42 PM - Session change notice received: SessionLock Session ID: 1
Error	12/11/2018 4:44:08 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/11/2018 4:35:55 PM	MTAService.OnSessionChange	0	None	4:35:55 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/11/2018 4:02:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 3:15:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 82c49846-fd29-11e8-996d-204747d02364
Report Status: 0"
Information	12/11/2018 2:33:54 PM	MTAService.OnSessionChange	0	None	2:33:53 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/11/2018 2:17:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 2:01:26 PM	MTAService.OnSessionChange	0	None	2:01:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/11/2018 1:30:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/11/2018 1:30:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/11/2018 1:27:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/11/2018 1:27:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/11/2018 1:07:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 1:07:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 12:51:24 PM	MTAService.OnSessionChange	0	None	12:51:24 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/11/2018 12:34:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 12:31:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/11/2018 12:31:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/11/2018 12:28:36 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/11/2018 12:28:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/11/2018 12:27:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/11/2018 12:27:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/11/2018 12:26:54 PM	MTAService.OnSessionChange	0	None	12:26:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/11/2018 12:16:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9103.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	12/11/2018 10:47:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 10:15:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9911d78f-fcff-11e8-996d-204747d02364
Report Status: 0"
Information	12/11/2018 9:43:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/11/2018 9:07:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 9:07:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 9:07:01 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/11/2018 9:06:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/11/2018 8:50:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 8:07:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2018 8:07:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:39Z. Reason: GVLK.
Information	12/11/2018 8:02:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2018 8:02:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2018 8:02:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2018 8:02:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/11/2018 7:11:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/11/2018 5:39:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 5:15:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: af57e52a-fcd5-11e8-996d-204747d02364
Report Status: 0"
Information	12/11/2018 5:07:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 5:06:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 4:34:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2018 4:34:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:46Z. Reason: GVLK.
Information	12/11/2018 4:29:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2018 4:29:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2018 4:29:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2018 4:29:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/11/2018 4:25:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2018 4:25:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:48:10Z. Reason: GVLK.
Information	12/11/2018 4:20:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2018 4:20:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2018 4:20:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2018 4:20:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/11/2018 4:02:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/11/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/11/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44123)(?)])(1 )(2 )]

"
Information	12/11/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44123)(?)])(1 )(2 )]

"
Information	12/11/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44123)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/11/2018 2:09:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 1:06:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2018 1:06:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/11/2018 12:34:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2018 12:15:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c5a8defe-fcab-11e8-996d-204747d02364
Report Status: 0"
Warning	12/10/2018 10:43:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 9:06:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 9:06:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 9:06:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/10/2018 9:06:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/10/2018 9:05:23 PM	VPSX Printer Driver Management	5	None	"VPSX Printer Driver Management Utility information:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          
Printer (GEPRINT on vpsx01) deleted
"
Warning	12/10/2018 8:50:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 8:46:00 PM	MTAService.OnSessionChange	0	None	8:46:00 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 8:32:35 PM	MTAService.OnSessionChange	0	None	8:32:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 8:29:13 PM	MTAService.OnSessionChange	0	None	8:29:13 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 8:26:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 8:21:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44493)(?)])(1 )(2 )]

"
Information	12/10/2018 8:21:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/10/2018 8:21:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44493)(?)])(1 )(2 )]

"
Information	12/10/2018 8:21:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44493)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 8:21:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2018 8:21:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 8:21:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	12/10/2018 8:11:36 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/10/2018 7:36:55 PM	MTAService.OnSessionChange	0	None	7:36:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 7:15:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dbbb48e1-fc81-11e8-996d-204747d02364
Report Status: 0"
Warning	12/10/2018 7:05:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 6:10:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 6:05:49 PM	MTAService.OnSessionChange	0	None	6:05:49 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 6:05:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44630)(?)])(1 )(2 )]

"
Information	12/10/2018 6:05:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/10/2018 6:05:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44630)(?)])(1 )(2 )]

"
Information	12/10/2018 6:05:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44630)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 6:05:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2018 6:05:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 6:05:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 6:03:58 PM	MTAService.OnSessionChange	0	None	6:03:58 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/10/2018 5:26:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 5:08:18 PM	MTAService.OnSessionChange	0	None	5:08:18 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 5:06:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 5:06:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/10/2018 3:34:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 3:18:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 3:13:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44801)(?)])(1 )(2 )]

"
Information	12/10/2018 3:13:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/10/2018 3:13:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44801)(?)])(1 )(2 )]

"
Information	12/10/2018 3:13:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44801)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 3:13:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2018 3:13:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 3:13:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 3:00:09 PM	MTAService.OnSessionChange	0	None	3:00:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 2:57:58 PM	MTAService.OnSessionChange	0	None	2:57:58 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 2:37:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:41.031544800Z.
Information	12/10/2018 2:37:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:41.031544800Z.
Information	12/10/2018 2:37:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:37.058147500Z.
Information	12/10/2018 2:37:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:37.058147500Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:36.874129100Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:36.874129100Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:36.675109200Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:36.675109200Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:36.250066700Z.
Information	12/10/2018 2:37:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:36.250066700Z.
Information	12/10/2018 2:37:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:35.417983500Z.
Information	12/10/2018 2:37:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:35.417983500Z.
Information	12/10/2018 2:37:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎10T09:07:34.119853700Z.
Information	12/10/2018 2:37:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎10T09:07:34.119853700Z.
Information	12/10/2018 2:34:02 PM	MTAService.OnSessionChange	0	None	2:34:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 2:15:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f1e252f8-fc57-11e8-996d-204747d02364
Report Status: 0"
Warning	12/10/2018 1:59:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 1:58:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:58:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 1:48:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:47:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 1:35:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:34:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 1:31:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:31:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 1:25:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:25:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 1:21:07 PM	MTAService.OnSessionChange	0	None	1:21:07 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 1:20:40 PM	MTAService.OnSessionChange	0	None	1:20:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 1:20:31 PM	MTAService.OnSessionChange	0	None	1:20:31 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 1:06:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 1:05:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 1:03:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 1:02:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 12:59:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 12:59:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 12:54:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 12:54:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 12:53:08 PM	MTAService.OnSessionChange	0	None	12:53:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 12:50:36 PM	MTAService.OnSessionChange	0	None	12:50:36 PM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 12:39:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 12:39:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/10/2018 12:25:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/10/2018 12:24:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/10/2018 12:13:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 11:53:37 AM	MTAService.OnSessionChange	0	None	11:53:37 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 11:34:44 AM	MTAService.OnSessionChange	0	None	11:34:44 AM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 10:38:31 AM	MTAService.OnSessionChange	0	None	10:38:31 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/10/2018 10:38:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 10:33:26 AM	MTAService.OnSessionChange	0	None	10:33:26 AM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 10:26:09 AM	MTAService.OnSessionChange	0	None	10:26:09 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 10:23:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 10:23:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-17T04:47:53Z. Reason: GVLK.
Information	12/10/2018 10:18:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 10:18:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 10:18:52 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/12/10 04:48"
Information	12/10/2018 10:18:51 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/12/10 04:48, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/10/2018 10:14:06 AM	MTAService.OnSessionChange	0	None	10:14:06 AM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 10:13:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/10/2018 10:13:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 10:13:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 10:13:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 10:03:00 AM	MTAService.OnSessionChange	0	None	10:03:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 9:46:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 9:46:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:48Z. Reason: GVLK.
Information	12/10/2018 9:41:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/10/2018 9:41:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 9:41:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 9:41:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 9:36:18 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9102.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/10/2018 9:34:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 17, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/10/2018 9:34:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/10/2018 9:24:33 AM	MTAService.OnSessionChange	0	None	9:24:33 AM - Session change notice received: SessionLock Session ID: 1
Information	12/10/2018 9:21:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/10/2018 9:21:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:25Z. Reason: GVLK.
Information	12/10/2018 9:21:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/10/2018 9:16:00 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/10/2018 9:16:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 45159)(?)])(1 )(2 )]

"
Information	12/10/2018 9:16:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/10/2018 9:15:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 45159)(?)])(1 )(2 )]

"
Information	12/10/2018 9:15:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 45159)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 9:15:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2018 9:15:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 9:15:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 9:15:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 083e78ee-fc2e-11e8-996d-204747d02364
Report Status: 0"
Information	12/10/2018 9:11:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/10/2018 9:10:59 AM	MTAService.OnSessionChange	0	None	9:10:59 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/10/2018 9:08:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/10/2018 9:08:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2018 9:08:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2018 9:08:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/10/2018 9:07:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/10/2018 9:07:37 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/10/2018 9:07:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 24, Deleted: 0, Modified: 97, Compared: 29228, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Warning	12/10/2018 9:07:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2018 9:06:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 9:06:14 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/10/2018 9:05:44 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Sunday, November 25, 2018 5:17:32 AM.
Information	12/10/2018 9:05:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=EC-ACC, OU=Jerarquia Entitats de Certificacio Catalanes, OU=Vegeu https://www.catcert.net/verarrel (c)03, OU=Serveis Publics de Certificacio, O=Agencia Catalana de Certificacio (NIF Q-0801176-I), C=ES> Sha1 thumbprint: <28903A635B5280FAE6774C0B6DA7D6BAA64AF2E8>.
Information	12/10/2018 9:05:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2018 9:05:25 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	12/10/2018 9:05:25 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/10/2018 9:05:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/10/2018 9:05:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Error	12/7/2018 3:53:57 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/7/2018 3:53:53 PM	MTAService.OnSessionChange	0	None	3:53:53 PM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 3:50:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 3:45:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 3:44:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 3:43:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 3:42:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 3:42:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 3:41:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 673490c1-fa08-11e8-996d-204747d02364
Report Status: 0"
Information	12/7/2018 3:40:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 3:40:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 3:36:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:47:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/7/2018 2:44:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:43:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:43:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:43:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:42:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:42:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:42:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:42:17 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 483

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 655

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 327

Information	12/7/2018 2:41:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/7/2018 2:41:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49153)(?)])(1 )(2 )]

"
Information	12/7/2018 2:41:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/7/2018 2:41:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49153)(?)])(1 )(2 )]

"
Information	12/7/2018 2:41:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49153)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 2:41:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/7/2018 2:41:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 2:41:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/7/2018 2:34:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:31:50 PM	MTAService.OnSessionChange	0	None	2:31:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/7/2018 2:26:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 2:16:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:14:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:10:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 2:08:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 2:07:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:45:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2018 1:45:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:21Z. Reason: GVLK.
Information	12/7/2018 1:40:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2018 1:40:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 1:40:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 1:40:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2018 1:31:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:26:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:25:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:23:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:23:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:18:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:17:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:15:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:14:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:12:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:12:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/7/2018 1:12:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 1:12:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 1:11:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:11:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:11:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:11:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:10:49 PM	MTAService.OnSessionChange	0	None	1:10:49 PM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 1:06:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:02:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 1:02:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 1:00:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9099.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/7/2018 12:59:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:59:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:57:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:57:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:55:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:54:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/7/2018 12:52:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 12:45:57 PM	MTAService.OnSessionChange	0	None	12:45:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 12:43:21 PM	MTAService.OnSessionChange	0	None	12:43:21 PM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 12:36:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:36:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:36:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:35:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:32:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:32:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:26:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:25:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:21:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:21:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:18:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:17:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:13:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:12:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:12:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:12:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:10:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 12:09:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 12:06:15 PM	MTAService.OnSessionChange	0	None	12:06:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 11:59:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:59:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 11:57:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:56:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 11:54:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:54:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 11:45:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:45:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 11:37:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:36:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 11:31:24 AM	MTAService.OnSessionChange	0	None	11:31:24 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 11:28:58 AM	MTAService.OnSessionChange	0	None	11:28:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 11:27:30 AM	MTAService.OnSessionChange	0	None	11:27:30 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 11:11:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 11:10:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/7/2018 11:04:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 11:01:17 AM	MTAService.OnSessionChange	0	None	11:01:17 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 10:55:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 10:55:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 10:52:10 AM	MTAService.OnSessionChange	0	None	10:52:10 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 10:49:22 AM	MTAService.OnSessionChange	0	None	10:49:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 10:47:33 AM	MTAService.OnSessionChange	0	None	10:47:33 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 10:46:55 AM	MTAService.OnSessionChange	0	None	10:46:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 10:45:20 AM	MTAService.OnSessionChange	0	None	10:45:20 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 10:43:13 AM	MTAService.OnSessionChange	0	None	10:43:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/7/2018 10:41:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/7/2018 10:41:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7d3b2249-f9de-11e8-996d-204747d02364
Report Status: 0"
Information	12/7/2018 10:40:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2018 10:38:47 AM	MTAService.OnSessionChange	0	None	10:38:47 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 10:01:32 AM	MTAService.OnSessionChange	0	None	10:01:32 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/7/2018 9:28:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 9:13:52 AM	MTAService.OnSessionChange	0	None	9:13:52 AM - Session change notice received: SessionLock Session ID: 1
Information	12/7/2018 9:12:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 9:12:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 9:12:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 9:11:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/7/2018 9:11:43 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/7/2018 9:11:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/7/2018 8:51:53 AM	MTAService.OnSessionChange	0	None	8:51:53 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/7/2018 7:55:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/7/2018 6:23:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 5:41:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9396a00f-f9b4-11e8-996d-204747d02364
Report Status: 0"
Information	12/7/2018 5:12:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 5:12:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 5:12:25 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/7/2018 5:12:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/7/2018 4:51:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 3:29:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2018 3:29:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:45Z. Reason: GVLK.
Information	12/7/2018 3:24:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2018 3:24:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 3:24:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 3:24:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2018 3:22:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2018 3:22:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:32Z. Reason: GVLK.
Warning	12/7/2018 3:19:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 3:17:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2018 3:17:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 3:17:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 3:17:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2018 3:15:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2018 3:15:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:40Z. Reason: GVLK.
Information	12/7/2018 3:10:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2018 3:10:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 3:10:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 3:10:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/7/2018 2:32:11 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/7/2018 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49883)(?)])(1 )(2 )]

"
Information	12/7/2018 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/7/2018 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49883)(?)])(1 )(2 )]

"
Information	12/7/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49883)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2018 2:32:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/7/2018 2:32:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2018 2:32:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/7/2018 1:42:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2018 1:12:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 1:12:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 1:11:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 1:11:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2018 12:40:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9e9e171-f98a-11e8-996d-204747d02364
Report Status: 0"
Information	12/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/6/2018 11:41:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 11:22:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2018 11:22:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:21Z. Reason: GVLK.
Information	12/6/2018 11:17:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2018 11:17:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2018 11:17:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2018 11:17:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/6/2018 9:52:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 9:12:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 9:12:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 9:11:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 9:11:55 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/6/2018 9:11:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 8:04:55 PM	MTAService.OnSessionChange	0	None	8:04:55 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/6/2018 7:53:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 7:40:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0453c6d-f960-11e8-996d-204747d02364
Report Status: 0"
Information	12/6/2018 7:26:19 PM	MTAService.OnSessionChange	0	None	7:26:19 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/6/2018 6:19:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 5:12:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:12:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:12:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:11:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/6/2018 5:11:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:05:06 PM	MTAService.OnSessionChange	0	None	5:05:06 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 4:53:44 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎12‎-‎06T11:23:44.067957200Z.
Information	12/6/2018 4:53:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎12‎-‎06T11:23:44.067957200Z.
Information	12/6/2018 4:53:25 PM	MTAService.OnSessionChange	0	None	4:53:25 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/6/2018 4:34:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 3:43:58 PM	MTAService.OnSessionChange	0	None	3:43:58 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 3:35:24 PM	MTAService.OnSessionChange	0	None	3:35:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 2:48:00 PM	MTAService.OnSessionChange	0	None	2:48:00 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 2:45:34 PM	MTAService.OnSessionChange	0	None	2:45:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 2:40:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d73186b0-f936-11e8-996d-204747d02364
Report Status: 0"
Warning	12/6/2018 2:33:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 2:23:34 PM	MTAService.OnSessionChange	0	None	2:23:34 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 2:20:27 PM	MTAService.OnSessionChange	0	None	2:20:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 1:16:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 1:15:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/6/2018 1:12:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 1:12:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 1:11:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 1:05:00 PM	MTAService.OnSessionChange	0	None	1:05:00 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 1:01:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 1:01:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/6/2018 12:59:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 12:48:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 12:46:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/6/2018 12:44:59 PM	MTAService.OnSessionChange	0	None	12:44:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 12:44:45 PM	MTAService.OnSessionChange	0	None	12:44:45 PM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 12:29:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 12:29:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/6/2018 12:21:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9098.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/6/2018 12:15:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 12:15:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/6/2018 12:13:48 PM	MTAService.OnSessionChange	0	None	12:13:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 11:31:34 AM	MTAService.OnSessionChange	0	None	11:31:34 AM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 11:21:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 11:21:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/6/2018 11:12:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/6/2018 11:12:36 AM	MTAService.OnSessionChange	0	None	11:12:36 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 11:12:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/6/2018 11:08:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 10:39:41 AM	MTAService.OnSessionChange	0	None	10:39:41 AM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 10:28:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2018 10:28:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:18Z. Reason: GVLK.
Information	12/6/2018 10:23:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2018 10:23:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2018 10:23:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2018 10:23:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/6/2018 10:06:59 AM	MTAService.OnSessionChange	0	None	10:06:59 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 10:00:55 AM	MTAService.OnSessionChange	0	None	10:00:55 AM - Session change notice received: SessionLock Session ID: 1
Error	12/6/2018 9:59:42 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/6/2018 9:40:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed77632f-f90c-11e8-996d-204747d02364
Report Status: 0"
Information	12/6/2018 9:35:54 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: PuTTY release 0.70 (64-bit). Product Version: 0.70.0.0. Product Language: 1033. Manufacturer: Simon Tatham. Installation success or error status: 0.
Information	12/6/2018 9:35:54 AM	MsiInstaller	11707	None	Product: PuTTY release 0.70 (64-bit) -- Installation completed successfully.
Information	12/6/2018 9:35:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎12‎-‎06T04:05:39.884181200Z.
Information	12/6/2018 9:35:49 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\Downloads\putty-64bit-0.70-installer.msi. Client Process Id: 20252.
Error	12/6/2018 9:35:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/6/2018 9:35:39 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎12‎-‎06T04:05:39.884181200Z.
Information	12/6/2018 9:35:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\Downloads\putty-64bit-0.70-installer.msi. Client Process Id: 20252.
Error	12/6/2018 9:34:30 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/6/2018 9:33:05 AM	MTAService.OnSessionChange	0	None	9:33:05 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/6/2018 9:14:15 AM	MTAService.OnSessionChange	0	None	9:14:15 AM - Session change notice received: SessionLock Session ID: 1
Information	12/6/2018 9:12:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2018 9:12:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 9:11:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 9:11:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	12/6/2018 9:05:04 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 9:04:29 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/6/2018 9:02:23 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/6/2018 9:02:23 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	12/6/2018 8:59:31 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:59:28 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:59:21 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:58:54 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:58:15 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:57:45 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:53:41 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	12/6/2018 8:53:22 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/6/2018 8:51:39 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/6/2018 8:51:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/6/2018 8:51:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/6/2018 8:51:19 AM	MTAService.OnSessionChange	0	None	8:51:19 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/6/2018 7:29:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/6/2018 5:35:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 5:12:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:12:00 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/6/2018 5:11:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 5:11:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 4:40:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03cdc88b-f8e3-11e8-996d-204747d02364
Report Status: 0"
Information	12/6/2018 4:33:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2018 4:33:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:31Z. Reason: GVLK.
Information	12/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2018 4:25:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/6/2018 3:35:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 3:17:47 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/6/2018 3:15:34 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	12/6/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/6/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/6/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51323)(?)])(1 )(2 )]

"
Information	12/6/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/6/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51323)(?)])(1 )(2 )]

"
Information	12/6/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51323)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/6/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/6/2018 2:01:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 1:11:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 1:11:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2018 1:11:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2018 12:07:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/5/2018 11:40:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a22776e-f8b9-11e8-996d-204747d02364
Report Status: 0"
Information	12/5/2018 11:03:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 11:03:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:10Z. Reason: GVLK.
Information	12/5/2018 10:58:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 10:58:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 10:58:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 10:58:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/5/2018 10:08:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 9:11:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 9:11:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/5/2018 8:17:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 7:57:07 PM	MTAService.OnSessionChange	0	None	7:57:07 PM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 7:32:40 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/5/2018 7:32:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/5/2018 7:32:22 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/5/2018 7:31:57 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 29134, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/5/2018 7:30:16 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/5/2018 7:30:16 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/5/2018 7:21:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 7:16:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2018 7:16:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2018 7:16:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51758)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 7:16:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2018 7:16:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 7:16:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 7:03:03 PM	MTAService.OnSessionChange	0	None	7:03:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/5/2018 6:40:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3093f72d-f88f-11e8-996d-204747d02364
Report Status: 0"
Information	12/5/2018 6:34:31 PM	MTAService.OnSessionChange	0	None	6:34:31 PM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 6:34:05 PM	MTAService.OnSessionChange	0	None	6:34:05 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/5/2018 6:23:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 6:23:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:58Z. Reason: GVLK.
Information	12/5/2018 6:18:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 6:18:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 6:18:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 6:18:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/5/2018 6:18:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 5:11:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 5:11:50 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/5/2018 5:11:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/5/2018 4:25:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 3:53:52 PM	MTAService.OnSessionChange	0	None	3:53:52 PM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 3:46:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:46:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:44Z. Reason: GVLK.
Information	12/5/2018 3:41:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 3:41:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:41:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:41:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 3:30:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:24:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51990)(?)])(1 )(2 )]

"
Information	12/5/2018 3:24:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2018 3:24:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51990)(?)])(1 )(2 )]

"
Information	12/5/2018 3:24:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 51990)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:24:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2018 3:24:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:24:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 3:24:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:24:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:14Z. Reason: GVLK.
Information	12/5/2018 3:19:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 3:19:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:19:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:19:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 3:14:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:14:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:11Z. Reason: GVLK.
Information	12/5/2018 3:12:01 PM	MTAService.OnSessionChange	0	None	3:12:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/5/2018 3:09:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 3:09:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:09:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:09:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 2:59:27 PM	MTAService.OnSessionChange	0	None	2:59:27 PM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 2:34:53 PM	MTAService.OnSessionChange	0	None	2:34:53 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/5/2018 2:30:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 1:40:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 467fd57e-f865-11e8-996d-204747d02364
Report Status: 0"
Information	12/5/2018 1:11:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 1:11:46 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/5/2018 1:11:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 1:06:53 PM	MTAService.OnSessionChange	0	None	1:06:53 PM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 1:05:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 1:04:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 12:54:46 PM	MTAService.OnSessionChange	0	None	12:54:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/5/2018 12:53:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 12:52:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 12:49:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 12:48:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 12:42:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 12:41:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/5/2018 12:36:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 12:27:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9097.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/5/2018 12:01:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 12:01:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 11:59:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 11:58:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 11:32:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 11:32:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 11:18:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/5/2018 11:17:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/5/2018 11:04:37 AM	MTAService.OnSessionChange	0	None	11:04:37 AM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 11:04:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/5/2018 11:03:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/5/2018 11:03:23 AM	MTAService.OnSessionChange	0	None	11:03:23 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/5/2018 10:59:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 10:34:27 AM	MTAService.OnSessionChange	0	None	10:34:27 AM - Session change notice received: SessionLock Session ID: 1
Information	12/5/2018 10:32:19 AM	MTAService.OnSessionChange	0	None	10:32:19 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/5/2018 9:25:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/5/2018 9:11:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/5/2018 9:03:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 8:40:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5cbaebb9-f83b-11e8-996d-204747d02364
Report Status: 0"
Warning	12/5/2018 7:13:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/5/2018 5:33:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 5:11:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 5:11:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 5:11:08 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/5/2018 5:11:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 3:45:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:45:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:18Z. Reason: GVLK.
Information	12/5/2018 3:40:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 722ccad5-f811-11e8-996d-204747d02364
Report Status: 0"
Warning	12/5/2018 3:40:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 3:40:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 3:40:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:40:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:40:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 3:34:21 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/5/2018 3:33:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 3:33:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:21Z. Reason: GVLK.
Information	12/5/2018 3:28:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 3:28:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 3:28:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 3:28:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 3:24:44 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Error	12/5/2018 2:40:30 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (8) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181203_083917.log
"
Error	12/5/2018 2:40:30 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181203_083917.log
"
Information	12/5/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/5/2018 2:32:11 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/5/2018 2:32:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52763)(?)])(1 )(2 )]

"
Information	12/5/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52763)(?)])(1 )(2 )]

"
Information	12/5/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52763)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 2:32:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2018 2:32:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/5/2018 2:05:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 1:32:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2018 1:32:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:56Z. Reason: GVLK.
Information	12/5/2018 1:27:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2018 1:27:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2018 1:27:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2018 1:27:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2018 1:11:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 1:11:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2018 12:28:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 996f4b4e-f7f6-11e8-996d-204747d02364
Report Status: 0"
Warning	12/5/2018 12:05:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/4/2018 10:09:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 9:11:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 9:10:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 9:10:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/4/2018 8:10:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 7:28:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b059eaf8-f7cc-11e8-996d-204747d02364
Report Status: 0"
Information	12/4/2018 7:20:21 PM	MTAService.OnSessionChange	0	None	7:20:21 PM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 7:16:31 PM	MTAService.OnSessionChange	0	None	7:16:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 6:39:10 PM	MTAService.OnSessionChange	0	None	6:39:10 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/4/2018 6:35:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 6:18:57 PM	MTAService.OnSessionChange	0	None	6:18:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 5:11:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 5:10:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 5:10:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 5:10:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	12/4/2018 4:44:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 2:50:33 PM	MTAService.OnSessionChange	0	None	2:50:33 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/4/2018 2:46:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 2:28:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c737e191-f7a2-11e8-996d-204747d02364
Report Status: 0"
Information	12/4/2018 2:14:42 PM	MTAService.OnSessionChange	0	None	2:14:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 1:28:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 1:28:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:20Z. Reason: GVLK.
Information	12/4/2018 1:23:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 1:23:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 1:23:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 1:23:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 1:17:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 1:17:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 1:11:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 1:10:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/4/2018 1:10:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/4/2018 1:03:48 PM	MTAService.OnSessionChange	0	None	1:03:48 PM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 1:02:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 1:02:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/4/2018 1:01:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 12:57:59 PM	MTAService.OnSessionChange	0	None	12:57:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 12:50:57 PM	MTAService.OnSessionChange	0	None	12:50:57 PM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 12:49:42 PM	MTAService.OnSessionChange	0	None	12:49:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 12:46:31 PM	MTAService.OnSessionChange	0	None	12:46:31 PM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 12:37:22 PM	MTAService.OnSessionChange	0	None	12:37:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 12:33:38 PM	MTAService.OnSessionChange	0	None	12:33:38 PM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 12:17:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9096.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/4/2018 12:16:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 12:15:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 11:49:10 AM	MTAService.OnSessionChange	0	None	11:49:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 11:47:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 11:47:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 11:34:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 11:33:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 11:31:29 AM	MTAService.OnSessionChange	0	None	11:31:29 AM - Session change notice received: SessionLock Session ID: 1
Warning	12/4/2018 11:25:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 10:55:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 10:54:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 10:52:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 10:52:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 10:51:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/4/2018 10:49:40 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/4/2018 10:48:31 AM	MTAService.OnSessionChange	0	None	10:48:31 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/4/2018 10:11:20 AM	MTAService.OnSessionChange	0	None	10:11:20 AM - Session change notice received: SessionLock Session ID: 1
Information	12/4/2018 10:11:13 AM	MTAService.OnSessionChange	0	None	10:11:13 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	12/4/2018 9:29:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 9:28:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de0bf636-f778-11e8-996d-204747d02364
Report Status: 0"
Information	12/4/2018 9:10:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 9:10:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 9:04:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 9:04:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:08Z. Reason: GVLK.
Information	12/4/2018 9:01:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/4/2018 9:01:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/4/2018 8:59:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 8:59:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 8:59:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 8:59:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 8:48:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/4/2018 7:57:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/4/2018 6:08:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 5:10:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 5:10:44 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/4/2018 5:10:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 4:51:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 4:51:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:26Z. Reason: GVLK.
Information	12/4/2018 4:46:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 4:46:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 4:46:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 4:46:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 4:44:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 4:44:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:28Z. Reason: GVLK.
Information	12/4/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 4:39:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 4:36:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 4:36:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:33Z. Reason: GVLK.
Information	12/4/2018 4:31:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 4:31:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 4:31:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 4:31:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 4:28:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4e28275-f74e-11e8-996d-204747d02364
Report Status: 0"
Warning	12/4/2018 4:19:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 3:25:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2018 3:25:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:18Z. Reason: GVLK.
Information	12/4/2018 3:20:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2018 3:20:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 3:20:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 3:20:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/4/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/4/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54203)(?)])(1 )(2 )]

"
Information	12/4/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/4/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54203)(?)])(1 )(2 )]

"
Information	12/4/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54203)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2018 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/4/2018 2:30:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 1:10:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2018 1:10:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/4/2018 12:45:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/3/2018 11:28:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bdf9fbe-f725-11e8-996d-204747d02364
Report Status: 0"
Information	12/3/2018 10:59:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Options\Packages\SAP_UEM_KnoaAgent_PRD_P39_4_V01\KnoaAgent-GE_PRD_P39-4.msi. Client Process Id: 12428.
Information	12/3/2018 10:59:33 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: KnoaAgent. Product Version: 71.35.4. Product Language: 1033. Manufacturer: Knoa Software, Inc.. Installation success or error status: 0.
Information	12/3/2018 10:59:33 PM	MsiInstaller	11707	None	Product: KnoaAgent -- Installation completed successfully.
Information	12/3/2018 10:59:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Options\Packages\SAP_UEM_KnoaAgent_PRD_P39_4_V01\KnoaAgent-GE_PRD_P39-4.msi. Client Process Id: 12428.
Information	12/3/2018 10:59:23 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: My Project Name-1. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: Your Company Name. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Oracle VM VirtualBox 4.3.4. Product Version: 4.3.4. Product Language: 1033. Manufacturer: Oracle Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: O2Micro Flash Memory Card Windows Driver. Product Version: 3.0.08.38. Product Language: 1033. Manufacturer: O2Micro International LTD.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Cloud Explorer - v1.0. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Management Objects . Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: PhishMe Reporter. Product Version: 3.0.1.4. Product Language: 1033. Manufacturer: PhishMe, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Cirrato Client 2013.1.3. Product Version: 2013.1.3. Product Language: 1033. Manufacturer: Cirrato Technologies. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual J# 2.0 Redistributable Package - SE (x64). Product Version: 2.0.50728. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2012 Native Client . Product Version: 11.2.5643.3. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Policies . Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Node.js. Product Version: 8.12.0. Product Language: 1033. Manufacturer: Node.js Foundation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Express LocalDB . Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Mobile App SDK V2.0. Product Version: 2.0.31124.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	12/3/2018 10:59:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft redistributable runtime DLLs VS2005 SP1(x86_x64). Product Version: 8.0.50727.4053. Product Language: 1033. Manufacturer: SAP. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17. Product Version: 9.0.30729. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Chrome. Product Version: 66.56.76. Product Language: 1033. Manufacturer: Google, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Report Viewer 2014 Runtime. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148. Product Version: 9.0.30729.4148. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: VMware vSphere Client 6.0. Product Version: 6.0.0.5505. Product Language: 1033. Manufacturer: VMware, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:18 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: 64 Bit HP CIO Components Installer. Product Version: 21.2.1. Product Language: 1033. Manufacturer: HP Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:18 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:18 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2005 Redistributable. Product Version: 8.0.61001. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Tools for Microsoft Visual Studio 2015 Core. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: BIG-IP Edge Client. Product Version: 71.2017.0404.2206. Product Language: 1033. Manufacturer: F5 Networks, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: GE Fonts 2015. Product Version: 1.0.1. Product Language: 1033. Manufacturer: General Electric. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2005 Redistributable. Product Version: 8.0.56336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2012 Transact-SQL ScriptDom . Product Version: 11.1.3000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee Drive Encryption Agent. Product Version: 7.1.3.547. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:14 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Help Viewer 2.2. Product Version: 2.2.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:14 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 T-SQL Language Service . Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:14 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Shared Components for Visual Studio 2015 - v1.7. Product Version: 1.7.40113.5. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:14 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: WebEx Recorder and Player. Product Version: 3.29.3210. Product Language: 1033. Manufacturer: Cisco WebEx LLC. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:14 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Cisco Jabber. Product Version: 10.6.2.59142. Product Language: 1033. Manufacturer: Cisco Systems, Inc. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.17. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.10.7310.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Tools for Microsoft Visual Studio 2015 - v2.8. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: myjava. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Digital Guardian Agent. Product Version: 6.0.4.0552. Product Language: 1033. Manufacturer: Verdasys Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.24.15. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Install Finalizer. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Hive ODBC Driver. Product Version: 1.0.5.5. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Japan Fonts. Product Version: 2.2. Product Language: 1033. Manufacturer: DynaComware. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft ASP.NET Core 2.1.2 Shared Framework (x86). Product Version: 2.1.13029.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610. Product Version: 11.0.60610. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2005 Redistributable (x64). Product Version: 8.0.56336. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Core Host FX Resolver - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:10 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:10 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft ASP.NET and Web Tools 2015.1 (RC1 Update 1) - Visual Studio 2015. Product Version: 14.1.11120.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Hive ODBC Driver. Product Version: 1.0.5.5. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 RsFx Driver. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Version Manager (x64) 1.0.0-rc1. Product Version: 1.0.11123.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Transact-SQL ScriptDom . Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Setup (English). Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Execution Environment (DNX) 1-rc1 (x64) for .NET Framework 4.6. Product Version: 1.0.11123.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual Studio 2010 Tools for Office Runtime (x64). Product Version: 10.0.40825. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161. Product Version: 9.0.30729.6161. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: AzureTools.Notifications. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Management Objects  (x64). Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:07 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee VirusScan Enterprise. Product Version: 8.8.09000. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Tanium Client Installer. Product Version: 1.0.0. Product Language: 1033. Manufacturer: Tanium Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Execution Environment (DNX) 1-rc1 (x64) for .NET Core. Product Version: 1.0.11123.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Libraries for .NET – v2.8. Product Version: 2.8.1111.221. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:05 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20081. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft redistributable runtime DLLs VS2005 SP1(x86). Product Version: 8.0.50727.4053. Product Language: 1033. Manufacturer: SAP. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Quickstarts. Product Version: 1.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161. Product Version: 9.0.30729.6161. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Tanium Client Installer. Product Version: 1.0.0. Product Language: 1033. Manufacturer: Tanium Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure App Service Tools v2.8.2 - Visual Studio 2015. Product Version: 14.0.20201.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Web Deploy 3.6. Product Version: 3.1238.1955. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Cisco PEAP Module. Product Version: 1.1.6. Product Language: 1033. Manufacturer: Cisco Systems, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610. Product Version: 11.0.60610. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Web Platform Installer 5.0. Product Version: 5.0.50430.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft System CLR Types for SQL Server 2014. Product Version: 12.0.2402.11. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:59:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2012 Command Line Utilities . Product Version: 11.1.3000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:58:59 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft ODBC Driver 11 for SQL Server. Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:58:59 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:58:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E592A253-1A6E-4977-AA3A-6C379806F82A}. Client Process Id: 7684.
Information	12/3/2018 10:58:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: KnoaAgent. Product Version: 71.14.0. Product Language: 1033. Manufacturer: Knoa Software, Inc.. Removal success or error status: 0.
Information	12/3/2018 10:58:59 PM	MsiInstaller	11724	None	Product: KnoaAgent -- Removal completed successfully.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E592A253-1A6E-4977-AA3A-6C379806F82A}. Client Process Id: 7684.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23026. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: KnoaAgent. Product Version: 71.14.0. Product Language: 1033. Manufacturer: Knoa Software, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee Drive Encryption. Product Version: 7.1.3.547. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2012 T-SQL Language Service . Product Version: 11.1.3000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2008 R2 Management Objects. Product Version: 10.51.2500.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Java SE Development Kit 8 Update 91 (64-bit). Product Version: 8.0.910.14. Product Language: 1033. Manufacturer: Oracle Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Java 8 Update 161 (64-bit). Product Version: 8.0.1610.12. Product Language: 1033. Manufacturer: Oracle Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Java 8 Update 161. Product Version: 8.0.1610.12. Product Language: 1033. Manufacturer: Oracle Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Juniper Odyssey Access Client. Product Version: 5.30.17847. Product Language: 1033. Manufacturer: Juniper Networks. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure HDInsight Tools for Visual Studio 2015. Product Version: 2.0.2900.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: MiniTab. Product Version: 12.23. Product Language: 1033. Manufacturer: Minitab, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.5.2 Multi-Targeting Pack. Product Version: 4.5.51209. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Shockwave Player 12.2. Product Version: 12.2.1.171. Product Language: 1033. Manufacturer: Adobe Systems, Inc. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:41 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual Studio 2010 Shell (Isolated) - ENU. Product Version: 10.0.40219. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Cloud Deployment Project for Microsoft Visual Studio 14 - v2.8. Product Version: 2.8.40112.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee Agent. Product Version: 5.05.1010. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Prerequisites for SSDT . Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610. Product Version: 11.0.60610. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Core Host - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2014 Transact-SQL Compiler Service . Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server 2008 Setup Support Files . Product Version: 10.3.5500.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Core Runtime - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:38 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	12/3/2018 10:55:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Data Factory Tools for Visual Studio 2015. Product Version: 0.9.3141.3. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610. Product Version: 11.0.60610. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: KnoaAgent. Product Version: 71.14.0. Product Language: 1033. Manufacturer: Knoa Software, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: psqlODBC. Product Version: 09.05.0300. Product Language: 1033. Manufacturer: PostgreSQL Global Development Group. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Realtek Audio COM Components. Product Version: 1.0.2. Product Language: 1033. Manufacturer: Realtek Semiconductor Corp.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219. Product Version: 10.0.40219. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:36 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee Host Intrusion Prevention. Product Version: 8.00.0900. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:36 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23026. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:35 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Visual Studio 2010 Prerequisites - English. Product Version: 10.0.40219. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:35 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU). Product Version: 4.5.50932. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:35 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Azure Resource Manager Tools (VS 14) - v2.8. Product Version: 2.8.0.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:35 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft System CLR Types for SQL Server 2014 (x64). Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Hive Streaming. Product Version: 17.1.308.308. Product Language: 1033. Manufacturer: Hive Streaming AB. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: VPSX Printer Driver Management. Product Version: 1.072.300. Product Language: 1033. Manufacturer: Levi, Ray & Shoup, Inc. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual Basic 6 SP6 - KB2708437 Update. Product Version: 1.0.0.0. Product Language: 1033. Manufacturer: Flexera Software. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology. Product Version: 2.6.1212.0302. Product Language: 1033. Manufacturer: Intel Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2005 Redistributable (x64). Product Version: 8.0.61000. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Sql Server Customer Experience Improvement Program. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Storage Tools - v5.0.0. Product Version: 5.0.0.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Uninstall Finalizer. Product Version: 2.8.40211.2. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Compute Emulator - v2.8. Product Version: 2.8.6485.4. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: CrowdStrike Device Control. Product Version: 4.11.7451.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:32 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft redistributable runtime DLLs VS2008 SP1(x86). Product Version: 9.0. Product Language: 1033. Manufacturer: SAP AG. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148. Product Version: 9.0.30729.4148. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.5 Multi-Targeting Pack. Product Version: 4.5.50710. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee GTI Proxy Agent. Product Version: 2.0.0.633. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Authoring Tools - v2.8. Product Version: 2.8.6485.4. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: IIS 10.0 Express. Product Version: 10.0.1735. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server Data Tools - enu (14.0.50616.0). Product Version: 14.0.50616.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft redistributable runtime DLLs VS2010 SP1 (x86). Product Version: 10.0.40219.1. Product Language: 1033. Manufacturer: SAP. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974. Product Version: 9.0.30729.4974. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Help Viewer 1.1. Product Version: 1.1.40219. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU). Product Version: 4.5.51209. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server Compact 4.0 SP1 x64 ENU. Product Version: 4.0.8876.1. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Azure Storage Emulator - v4.2. Product Version: 4.2.6848.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.5.1 Multi-Targeting Pack. Product Version: 4.5.50932. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft SQL Server System CLR Types. Product Version: 10.51.2500.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2315. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visio Viewer 2010. Product Version: 14.0.7015.1000. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/3/2018 10:55:28 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Application Error Reporting. Product Version: 12.0.6012.5000. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Warning	12/3/2018 10:46:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/3/2018 9:10:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 9:10:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 9:10:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/3/2018 9:10:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 8:19:07 PM	MTAService.OnSessionChange	0	None	8:19:07 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/3/2018 7:31:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 6:28:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 22bc07e7-f6fb-11e8-996d-204747d02364
Report Status: 0"
Information	12/3/2018 6:23:02 PM	MTAService.OnSessionChange	0	None	6:23:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 6:16:04 PM	MTAService.OnSessionChange	0	None	6:16:04 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/3/2018 5:42:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 5:26:57 PM	MTAService.OnSessionChange	0	None	5:26:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 5:09:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 5:09:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/3/2018 5:09:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 4:48:51 PM	MTAService.OnSessionChange	0	None	4:48:51 PM - Session change notice received: SessionLock Session ID: 1
Information	12/3/2018 4:09:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	12/3/2018 4:07:27 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 10516 did not respond and is being forcibly terminated {filter host process 12668}. 

Information	12/3/2018 4:02:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Error	12/3/2018 4:01:05 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/3/2018 3:06:53 PM	MTAService.OnSessionChange	0	None	3:06:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 2:58:27 PM	MTAService.OnSessionChange	0	None	2:58:27 PM - Session change notice received: SessionLock Session ID: 1
Information	12/3/2018 2:58:13 PM	MTAService.OnSessionChange	0	None	2:58:13 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 2:54:54 PM	MTAService.OnSessionChange	0	None	2:54:54 PM - Session change notice received: SessionLock Session ID: 1
Warning	12/3/2018 2:13:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 2:08:56 PM	MTAService.OnSessionChange	0	None	2:08:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 1:59:31 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/3/2018 1:36:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:28:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 39968e65-f6d1-11e8-996d-204747d02364
Report Status: 0"
Information	12/3/2018 1:21:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:21:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:16:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:16:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:16:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:16:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:16:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:16:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 1:12:31 PM	MTAService.OnSessionChange	0	None	1:12:31 PM - Session change notice received: SessionLock Session ID: 1
Information	12/3/2018 1:11:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:11:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 1:10:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 1:09:45 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 46

Information	12/3/2018 1:09:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2018 1:09:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55005)(?)])(1 )(2 )]

"
Information	12/3/2018 1:09:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2018 1:09:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55005)(?)])(1 )(2 )]

"
Information	12/3/2018 1:09:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55005)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 1:09:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2018 1:09:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 1:09:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 12:50:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2018 12:43:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9095.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	12/3/2018 12:23:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/3/2018 12:04:08 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/3/2018 11:49:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:49:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:48:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:46:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:46:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:45:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:43:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:41:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:35:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:34:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:34:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:30:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:30:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:29:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:29:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Error	12/3/2018 11:27:17 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/3/2018 11:19:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:16:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:13:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:11:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:10:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:09:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:04:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 11:02:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 11:00:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:58:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:58:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:56:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:55:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:53:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:49:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:47:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:44:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:43:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:42:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:40:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:39:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/3/2018 10:33:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 10:32:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:31:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:19:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:19:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 10:19:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-10T04:43:06Z. Reason: GVLK.
Information	12/3/2018 10:17:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:15:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:15:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:14:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 10:14:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 10:14:05 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/12/03 04:44"
Information	12/3/2018 10:14:04 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/12/03 04:44, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/3/2018 10:13:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:13:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:13:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:12:51 AM	MTAService.OnSessionChange	0	None	10:12:51 AM - Session change notice received: SessionUnlock Session ID: 1
Information	12/3/2018 10:12:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:11:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:10:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:10:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:09:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:08:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:03:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:02:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:01:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 10:00:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 10:00:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 10:00:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 10:00:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 10:00:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 9:58:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:55:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:35:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 9:35:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:22Z. Reason: GVLK.
Information	12/3/2018 9:32:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 9:30:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:29:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:26:19 AM	MTAService.OnSessionChange	0	None	9:26:19 AM - Session change notice received: SessionLock Session ID: 1
Information	12/3/2018 9:26:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:23:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:22:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:22:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:22:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:21:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:19:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:16:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:16:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:15:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:13:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:12:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:10:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 9:09:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 9:05:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 9:05:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:22Z. Reason: GVLK.
Information	12/3/2018 9:00:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 9:00:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 9:00:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 9:00:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 8:59:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 8:59:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:15Z. Reason: GVLK.
Information	12/3/2018 8:55:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 8:54:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 8:54:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 8:54:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 8:54:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 8:54:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 8:53:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 8:51:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	12/3/2018 8:50:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 8:50:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 8:50:48 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 171

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 203

Information	12/3/2018 8:50:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2018 8:50:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 8:50:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:25Z. Reason: GVLK.
Information	12/3/2018 8:49:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55265)(?)])(1 )(2 )]

"
Information	12/3/2018 8:49:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2018 8:49:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55265)(?)])(1 )(2 )]

"
Information	12/3/2018 8:49:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 8:47:43 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/3/2018 8:47:42 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	12/3/2018 8:47:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/3/2018 8:47:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55267)(?)])(1 )(2 )]

"
Information	12/3/2018 8:47:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2018 8:47:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55267)(?)])(1 )(2 )]

"
Information	12/3/2018 8:47:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 8:47:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2018 8:47:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 8:47:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 8:46:07 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	12/3/2018 8:46:07 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	12/3/2018 8:45:04 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/3/2018 8:45:04 AM	MTAService.OnSessionChange	0	None	8:45:04 AM - Logon : 212558710
Information	12/3/2018 8:45:04 AM	MTAService.OnSessionChange	0	None	8:45:04 AM - Session change notice received: SessionLogon Session ID: 1
Information	12/3/2018 8:45:04 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/3/2018 8:45:03 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/3/2018 8:45:03 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/3/2018 8:44:53 AM	MTAService.OnSessionChange	0	None	8:44:53 AM - Session change notice received: ConsoleConnect Session ID: 1
Warning	12/3/2018 8:44:52 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 147 second(s) to handle the notification event (CreateSession).
Warning	12/3/2018 8:44:26 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	12/3/2018 8:44:26 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/3/2018 8:44:12 AM	ESENT	302	Logging/Recovery	Windows (6924) Windows: The database engine has successfully completed recovery steps.
Information	12/3/2018 8:44:09 AM	ESENT	301	Logging/Recovery	Windows (6924) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/3/2018 8:44:08 AM	ESENT	300	Logging/Recovery	Windows (6924) Windows: The database engine is initiating recovery steps.
Information	12/3/2018 8:44:08 AM	ESENT	102	General	Windows (6924) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/3/2018 8:44:07 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/3/2018 8:44:00 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/3/2018 8:44:00 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/3/2018 8:43:59 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	12/3/2018 8:43:25 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	12/3/2018 8:42:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 8:42:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 8:42:20 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	12/3/2018 8:42:19 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	12/3/2018 8:42:19 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	12/3/2018 8:42:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 8:42:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	12/3/2018 8:42:06 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	12/3/2018 8:41:57 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9094.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/3/2018 8:41:04 AM	Service1	0	None	Service started successfully.
Error	12/3/2018 8:40:52 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/3/2018 8:40:52 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/3/2018 8:40:50 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/3/2018 8:40:48 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/3/2018 8:40:45 AM	PostgreSQL	0	None	"2018-12-03 08:40:45 IST LOG:  redirecting log output to logging collector process
2018-12-03 08:40:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/3/2018 8:40:42 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/3/2018 8:40:30 AM	MTAService	0	None	Service started successfully.
Information	12/3/2018 8:40:30 AM	MTAService.OnStart	0	None	8:40:30 AM - Waiting for user to Logon
Information	12/3/2018 8:40:25 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:25 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/3/2018 8:40:25 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/3/2018 8:40:25 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/3/2018 8:40:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/3/2018 8:40:23 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/3/2018 8:40:23 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/3/2018 8:40:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/3/2018 8:40:22 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:22 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:21 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/3/2018 8:40:21 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/3/2018 8:40:20 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/3/2018 8:40:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/3/2018 8:40:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/3/2018 8:40:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4488 at 12/3/2018 8:31:00 AM (local) 12/3/2018 3:01:00 AM (UTC). This is an informational message only; no user action is required.
Information	12/3/2018 8:40:15 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/3/2018 8:40:09 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/3/2018 8:40:09 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/3/2018 8:40:09 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/3/2018 8:40:09 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/3/2018 8:40:09 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4480.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/3/2018 8:39:59 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/3/2018 8:38:46 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/3/2018 8:38:41 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/3/2018 8:38:08 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/3/2018 8:38:08 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/3/2018 8:38:08 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/3/2018 8:31:03 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	12/3/2018 8:31:00 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	12/3/2018 8:30:10 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	12/3/2018 8:30:08 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1008 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2228 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	12/3/2018 8:30:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	12/3/2018 8:30:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	12/3/2018 8:30:06 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	12/3/2018 8:29:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 8:29:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 8:29:02 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 359

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	12/3/2018 8:28:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 8:28:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 508e5147-f6a7-11e8-b62b-0205857feb80
Report Status: 0"
Information	12/3/2018 8:28:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55286)(?)])(1 )(2 )]

"
Information	12/3/2018 8:28:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2018 8:28:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55286)(?)])(1 )(2 )]

"
Information	12/3/2018 8:28:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55287)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 8:28:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2018 8:28:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 8:28:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 8:28:01 AM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	12/3/2018 8:18:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 8:16:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/3/2018 8:08:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 7:53:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2018 7:52:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2018 7:47:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:47:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:47:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:46:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:46:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:46:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:40:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:39:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:36:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:36:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:27:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:26:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:24:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:24:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:21:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:21:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:17:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:17:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:17:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:16:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/3/2018 7:16:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/3/2018 7:16:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/3/2018 6:21:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 4:50:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 4:50:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:53Z. Reason: GVLK.
Information	12/3/2018 4:45:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 4:45:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 4:45:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 4:45:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 4:44:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2018 4:44:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:29Z. Reason: GVLK.
Warning	12/3/2018 4:42:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 4:39:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2018 3:53:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 3:52:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2018 3:28:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 672c962c-f67d-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/3/2018 2:48:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/3/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/3/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55643)(?)])(1 )(2 )]

"
Information	12/3/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55643)(?)])(1 )(2 )]

"
Information	12/3/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55643)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/3/2018 1:07:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/2/2018 11:52:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 11:52:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/2/2018 11:52:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/2/2018 11:36:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/2/2018 11:27:02 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (28) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181126_085951.log
"
Error	12/2/2018 11:27:02 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181126_085951.log
"
Information	12/2/2018 10:58:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 10:58:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:46Z. Reason: GVLK.
Information	12/2/2018 10:53:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 10:53:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 10:53:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 10:53:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2018 10:28:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7e0358a1-f653-11e8-b62b-0205857feb80
Report Status: 0"
Error	12/2/2018 10:15:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	12/2/2018 9:46:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/2/2018 8:06:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 7:52:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 7:52:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 7:32:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/2/2018 7:32:30 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/2/2018 7:32:30 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/2/2018 7:31:47 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/2/2018 7:31:47 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/2/2018 7:31:12 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 29059, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	12/2/2018 7:30:12 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/2/2018 7:30:12 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	12/2/2018 6:14:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 5:49:01 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/2/2018 5:28:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94e2c39e-f629-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/2/2018 4:20:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 3:52:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 3:52:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/2/2018 2:31:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 1:55:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 1:55:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:49Z. Reason: GVLK.
Information	12/2/2018 1:50:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 1:50:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 1:50:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 1:50:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/2/2018 12:54:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 12:41:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/2/2018 12:41:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/2/2018 12:29:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9094.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/2/2018 12:28:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: abdb980d-f5ff-11e8-b62b-0205857feb80
Report Status: 0"
Information	12/2/2018 11:52:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 11:52:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/2/2018 11:52:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/2/2018 11:14:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/2/2018 9:26:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 8:10:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 8:10:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:21Z. Reason: GVLK.
Information	12/2/2018 8:05:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 8:05:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 8:05:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 8:05:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2018 7:52:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 7:52:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/2/2018 7:41:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 7:28:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2ac256d-f5d5-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/2/2018 5:52:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/2/2018 4:16:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 3:52:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 3:52:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2018 3:42:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 3:42:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:02Z. Reason: GVLK.
Information	12/2/2018 3:37:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 3:37:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 3:37:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 3:37:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2018 3:34:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 3:34:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:56Z. Reason: GVLK.
Information	12/2/2018 3:29:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 3:29:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 3:29:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 3:29:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2018 3:28:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 3:28:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:47Z. Reason: GVLK.
Information	12/2/2018 3:23:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 3:23:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 3:23:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 3:23:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/2/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/2/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57083)(?)])(1 )(2 )]

"
Information	12/2/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/2/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57083)(?)])(1 )(2 )]

"
Information	12/2/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57083)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/2/2018 2:31:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 2:28:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9a3a0d1-f5ab-11e8-b62b-0205857feb80
Report Status: 0"
Information	12/2/2018 2:16:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/2/2018 2:16:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/2/2018 1:43:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2018 1:43:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:45Z. Reason: GVLK.
Information	12/2/2018 1:38:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2018 1:38:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2018 1:38:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2018 1:38:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/2/2018 12:45:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/1/2018 11:52:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:51:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:51:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/1/2018 11:51:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:12:07 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/1/2018 10:47:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 9:28:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f0810483-f581-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/1/2018 9:06:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 7:52:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 7:51:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/1/2018 7:22:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 5:41:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\mfe1A44.tmp\MFEagent_x64.msi. Client Process Id: 18700.
Information	12/1/2018 5:41:18 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: McAfee Agent. Product Version: 5.05.1010. Product Language: 1033. Manufacturer: McAfee, Inc.. Installation success or error status: 0.
Information	12/1/2018 5:41:18 PM	MsiInstaller	11707	None	Product: McAfee Agent -- Installation operation completed successfully.
Warning	12/1/2018 5:33:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 5:32:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\mfe1A44.tmp\MFEagent_x64.msi. Client Process Id: 18700.
Information	12/1/2018 4:28:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 076e6500-f558-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/1/2018 4:00:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 3:52:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 3:51:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/1/2018 2:16:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/1/2018 12:34:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 12:07:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9093.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/1/2018 11:51:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:51:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:51:39 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/1/2018 11:51:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 11:28:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1e4cda29-f52e-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/1/2018 10:42:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 9:19:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2018 9:19:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:04Z. Reason: GVLK.
Information	12/1/2018 9:14:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2018 9:14:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2018 9:14:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2018 9:14:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/1/2018 9:04:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 7:51:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 7:51:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 7:37:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/1/2018 7:36:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	12/1/2018 7:27:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 7:26:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2018 7:26:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:32Z. Reason: GVLK.
Information	12/1/2018 7:21:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2018 7:21:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2018 7:21:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2018 7:21:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2018 6:28:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35326b63-f504-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/1/2018 5:27:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 4:25:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2018 4:25:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:09Z. Reason: GVLK.
Information	12/1/2018 4:20:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2018 4:20:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2018 4:20:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2018 4:20:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2018 4:17:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2018 4:17:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:42Z. Reason: GVLK.
Information	12/1/2018 4:12:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2018 4:12:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2018 4:12:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2018 4:12:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2018 3:51:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2018 3:51:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/1/2018 3:35:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/1/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	12/1/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58523)(?)])(1 )(2 )]

"
Information	12/1/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/1/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58523)(?)])(1 )(2 )]

"
Information	12/1/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58523)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/1/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2018 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/1/2018 2:02:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 1:28:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c18cab3-f4da-11e8-b62b-0205857feb80
Report Status: 0"
Warning	12/1/2018 12:07:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2018 12:03:03 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/30/2018 11:51:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 11:51:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 11:51:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/30/2018 11:51:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/30/2018 10:12:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 8:28:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63259c10-f4b0-11e8-b62b-0205857feb80
Report Status: 0"
Warning	11/30/2018 8:20:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 7:51:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 7:51:27 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/30/2018 7:51:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/30/2018 6:41:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 6:06:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 6:06:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:42Z. Reason: GVLK.
Information	11/30/2018 6:01:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 6:01:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 6:01:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 6:01:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/30/2018 4:58:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/30/2018 4:01:55 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/30/2018 3:51:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 3:50:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 3:28:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79e1697a-f486-11e8-b62b-0205857feb80
Report Status: 0"
Warning	11/30/2018 3:00:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 2:43:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 2:38:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59237)(?)])(1 )(2 )]

"
Information	11/30/2018 2:38:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/30/2018 2:38:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59237)(?)])(1 )(2 )]

"
Information	11/30/2018 2:38:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59237)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 2:38:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2018 2:38:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 2:38:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/30/2018 1:26:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 1:06:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 1:01:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59333)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 1:01:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59333)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 1:01:55 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/30/2018 1:01:55 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/30/2018 1:01:54 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	11/30/2018 1:01:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2018 1:01:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 1:01:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/30/2018 12:59:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9092.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	11/30/2018 12:31:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/30/2018 11:51:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 11:51:02 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/30/2018 11:51:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 11:50:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/30/2018 11:32:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 10:47:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/30/2018 10:28:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 90bcf33c-f45c-11e8-b62b-0205857feb80
Report Status: 0"
Warning	11/30/2018 10:01:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 9:57:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/30/2018 9:31:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	11/30/2018 8:11:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 7:50:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 7:50:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 7:25:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 7:25:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:20Z. Reason: GVLK.
Information	11/30/2018 7:20:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 7:20:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 7:20:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 7:20:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/30/2018 6:33:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 5:28:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a7bc2eca-f432-11e8-b62b-0205857feb80
Report Status: 0"
Warning	11/30/2018 5:02:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 4:41:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 4:41:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:14Z. Reason: GVLK.
Information	11/30/2018 4:36:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 4:36:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 4:36:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 4:36:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2018 3:50:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 3:50:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2018 3:15:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 3:15:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:50Z. Reason: GVLK.
Warning	11/30/2018 3:11:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 3:10:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 3:10:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 3:10:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 3:10:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2018 3:09:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 3:09:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:05Z. Reason: GVLK.
Information	11/30/2018 3:04:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 3:04:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 3:04:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 3:04:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2018 2:37:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/30/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/30/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59963)(?)])(1 )(2 )]

"
Information	11/30/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/30/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59963)(?)])(1 )(2 )]

"
Information	11/30/2018 2:32:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59963)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 2:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/30/2018 1:19:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2018 1:08:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2018 1:08:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:49Z. Reason: GVLK.
Information	11/30/2018 1:03:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2018 1:03:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2018 1:03:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2018 1:03:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2018 12:28:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: be990c7c-f408-11e8-b62b-0205857feb80
Report Status: 0"
Information	11/30/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/29/2018 11:50:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 11:50:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/29/2018 11:50:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2018 11:45:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/29/2018 10:06:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/29/2018 8:32:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 7:51:53 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/29/2018 7:51:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 29090, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/29/2018 7:50:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 7:50:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 7:48:55 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/29/2018 7:48:55 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/29/2018 7:48:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/29/2018 7:48:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/29/2018 7:28:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d572d50d-f3de-11e8-b62b-0205857feb80
Report Status: 0"
Warning	11/29/2018 6:58:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/29/2018 5:10:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 3:50:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 3:50:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2018 3:13:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 2:28:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec47bd51-f3b4-11e8-b62b-0205857feb80
Report Status: 0"
Information	11/29/2018 2:27:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 2:27:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/29/2018 1:13:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 12:57:25 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9091.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/29/2018 12:48:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:48:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:47:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/29/2018 12:47:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:21Z. Reason: GVLK.
Information	11/29/2018 12:44:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:43:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:41:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/29/2018 12:41:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 12:41:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2018 12:41:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/29/2018 12:39:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:38:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:27:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:26:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:23:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:22:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:20:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 12:20:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 12:00:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/29/2018 11:55:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60839)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 11:55:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60839)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 11:55:52 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/29/2018 11:55:52 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/29/2018 11:55:51 AM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	11/29/2018 11:55:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/29/2018 11:55:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2018 11:55:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/29/2018 11:55:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/29/2018 11:50:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/29/2018 11:50:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 11:50:08 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 936

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1653

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 452

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 624

Information	11/29/2018 11:50:07 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/29/2018 11:50:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/29/2018 11:50:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 11:49:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60845)(?)])(1 )(2 )]

"
Information	11/29/2018 11:49:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/29/2018 11:49:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60845)(?)])(1 )(2 )]

"
Information	11/29/2018 11:49:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60845)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 11:49:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/29/2018 11:49:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2018 11:49:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/29/2018 11:16:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 9:41:33 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/29/2018 9:41:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/29/2018 9:28:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02d5bbd5-f38b-11e8-b62b-204747d02364
Report Status: 0"
Information	11/29/2018 9:21:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	11/29/2018 9:20:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/29/2018 7:40:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 6:26:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 6:26:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2018 6:00:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 4:47:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/29/2018 4:47:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:32Z. Reason: GVLK.
Information	11/29/2018 4:37:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/29/2018 4:37:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 4:37:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2018 4:37:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/29/2018 4:28:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 19860f8a-f361-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/29/2018 4:28:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 2:45:03 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/29/2018 2:42:34 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/29/2018 2:41:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 2:37:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/29/2018 2:32:17 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61402)(?)])(1 )(2 )]

"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61402)(?)])(1 )(2 )]

"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61402)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/29/2018 2:32:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2018 2:32:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/29/2018 2:26:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 2:26:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/29/2018 2:07:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6619e5c6-f34d-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/29/2018 1:07:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/28/2018 11:11:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 10:26:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 10:26:35 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/28/2018 10:26:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 10:23:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 10:23:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:41Z. Reason: GVLK.
Information	11/28/2018 10:18:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 10:18:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 10:18:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 10:18:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 9:34:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 9:07:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c4d916e-f323-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/28/2018 8:03:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 7:57:10 PM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Monday, November 19, 2018 11:25:37 PM.
Information	11/28/2018 7:26:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 7:26:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:38Z. Reason: GVLK.
Information	11/28/2018 7:21:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 7:21:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 7:21:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 7:21:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 6:35:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 6:29:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61885)(?)])(1 )(2 )]

"
Information	11/28/2018 6:29:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2018 6:29:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61885)(?)])(1 )(2 )]

"
Information	11/28/2018 6:29:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61885)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 6:29:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 6:29:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 6:29:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 6:27:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 6:26:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 5:11:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 5:06:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61968)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 5:06:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61968)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 5:06:44 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/28/2018 5:06:44 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/28/2018 5:06:44 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	11/28/2018 5:06:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 5:06:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 5:06:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 5:02:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 4:57:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61977)(?)])(1 )(2 )]

"
Information	11/28/2018 4:57:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2018 4:57:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61978)(?)])(1 )(2 )]

"
Information	11/28/2018 4:57:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61978)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 4:57:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 4:57:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 4:57:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 4:48:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 4:07:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 926a9aae-f2f9-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/28/2018 3:15:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 2:31:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 2:26:22 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 374

Information	11/28/2018 2:26:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 2:25:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]

"
Information	11/28/2018 2:25:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2018 2:25:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]

"
Information	11/28/2018 2:25:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 2:25:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 2:25:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 2:25:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 1:33:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 1:15:45 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 9220 milliseconds
Information	11/28/2018 1:11:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 1:11:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 1:01:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 1:01:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 12:48:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 12:47:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 12:34:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 12:33:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 12:33:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 12:33:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 12:32:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9090.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/28/2018 12:13:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 12:13:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 12:03:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/28/2018 12:01:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 11:59:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/28/2018 11:59:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/28/2018 11:58:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/28/2018 11:58:33 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/28/2018 11:58:33 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/28/2018 11:58:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 11:58:31 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 609

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 499

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	11/28/2018 11:58:28 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/28/2018 11:58:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2018 11:57:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62277)(?)])(1 )(2 )]

"
Information	11/28/2018 11:57:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2018 11:57:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62277)(?)])(1 )(2 )]

"
Information	11/28/2018 11:57:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62277)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 11:57:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 11:57:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 11:57:37 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 11:07:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a88b34db-f2cf-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/28/2018 10:05:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/28/2018 8:32:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/28/2018 6:51:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 6:09:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 6:09:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:42Z. Reason: GVLK.
Information	11/28/2018 6:07:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bea6fbd7-f2a5-11e8-b62b-204747d02364
Report Status: 0"
Information	11/28/2018 6:04:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 6:04:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 6:04:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 6:04:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 5:13:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/28/2018 3:41:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 3:18:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 3:18:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:56Z. Reason: GVLK.
Information	11/28/2018 3:13:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 3:13:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 3:13:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 3:13:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 3:13:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 3:13:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:42Z. Reason: GVLK.
Information	11/28/2018 3:08:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 3:08:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 3:08:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 3:08:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 2:37:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/28/2018 2:32:10 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/28/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62843)(?)])(1 )(2 )]

"
Information	11/28/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62843)(?)])(1 )(2 )]

"
Information	11/28/2018 2:32:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62843)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 2:32:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2018 2:32:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 2:32:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/28/2018 2:26:50 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/28/2018 2:24:22 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/28/2018 1:58:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 1:07:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d4ed14e4-f27b-11e8-b62b-204747d02364
Report Status: 0"
Information	11/28/2018 1:04:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2018 1:04:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:40Z. Reason: GVLK.
Information	11/28/2018 12:59:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2018 12:59:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2018 12:59:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2018 12:59:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/28/2018 12:04:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/27/2018 10:15:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/27/2018 8:36:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 8:07:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb2f71ec-f251-11e8-b62b-204747d02364
Report Status: 0"
Information	11/27/2018 7:05:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 7:05:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2018 6:46:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/27/2018 4:51:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 4:41:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2018 4:41:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:33Z. Reason: GVLK.
Information	11/27/2018 4:36:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2018 4:36:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 4:36:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 4:36:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/27/2018 3:20:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 3:07:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 01662ab3-f228-11e8-b62b-204747d02364
Report Status: 0"
Information	11/27/2018 3:05:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 3:05:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2018 1:27:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 12:39:24 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9089.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/27/2018 12:39:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:38:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:38:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:38:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:38:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:34:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:34:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:08:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:08:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:06:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:06:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 12:04:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 12:03:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/27/2018 11:42:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 11:05:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 11:05:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 11:05:06 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/27/2018 11:05:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 10:38:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 10:37:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/27/2018 10:09:32 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	11/27/2018 10:08:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 10:07:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1790bc0d-f1fe-11e8-b62b-204747d02364
Report Status: 0"
Information	11/27/2018 9:22:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/27/2018 9:21:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/27/2018 8:28:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/27/2018 8:27:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/27/2018 8:13:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 7:05:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 7:05:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2018 6:26:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 5:07:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2dbb136f-f1d4-11e8-b62b-204747d02364
Report Status: 0"
Information	11/27/2018 5:01:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2018 5:01:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:57Z. Reason: GVLK.
Information	11/27/2018 4:56:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2018 4:56:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 4:56:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 4:56:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2018 4:49:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2018 4:49:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:55Z. Reason: GVLK.
Information	11/27/2018 4:44:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2018 4:44:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 4:44:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 4:44:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/27/2018 4:26:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 3:53:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2018 3:53:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:34Z. Reason: GVLK.
Information	11/27/2018 3:48:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2018 3:48:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 3:48:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 3:48:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2018 3:38:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2018 3:38:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:27Z. Reason: GVLK.
Information	11/27/2018 3:33:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2018 3:33:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 3:33:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 3:33:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2018 3:05:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2018 3:04:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2018 2:43:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 2:37:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/27/2018 2:32:12 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/27/2018 2:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64282)(?)])(1 )(2 )]

"
Information	11/27/2018 2:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2018 2:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64283)(?)])(1 )(2 )]

"
Information	11/27/2018 2:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64283)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2018 2:32:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2018 2:32:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2018 2:32:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/27/2018 12:46:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2018 12:07:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43efcc7f-f1aa-11e8-b62b-204747d02364
Report Status: 0"
Information	11/27/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/26/2018 11:04:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/26/2018 11:04:53 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/26/2018 11:04:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/26/2018 10:54:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 10:05:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 10:05:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:10Z. Reason: GVLK.
Information	11/26/2018 10:00:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2018 10:00:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:00:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 10:00:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/26/2018 8:57:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 8:00:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/26/2018 8:00:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 28962, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/26/2018 7:57:46 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/26/2018 7:57:46 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/26/2018 7:57:31 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2315.
Information	11/26/2018 7:57:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	11/26/2018 7:17:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 7:09:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 7:07:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a2f1dcd-f180-11e8-b62b-204747d02364
Report Status: 0"
Information	11/26/2018 7:04:49 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 655

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 452

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1202

Information	11/26/2018 7:04:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/26/2018 7:03:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64731)(?)])(1 )(2 )]

"
Information	11/26/2018 7:03:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2018 7:03:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64731)(?)])(1 )(2 )]

"
Information	11/26/2018 7:03:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64731)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 7:03:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2018 7:03:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 7:03:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/26/2018 5:25:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/26/2018 3:48:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 2:07:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7060694d-f156-11e8-b62b-204747d02364
Report Status: 0"
Warning	11/26/2018 1:54:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 1:52:42 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/26/2018 12:22:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/26/2018 12:19:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65137)(?)])(1 )(2 )]

"
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65137)(?)])(1 )(2 )]

"
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65137)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2018 12:17:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 12:17:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/26/2018 10:45:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 10:34:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 10:34:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:22Z. Reason: GVLK.
Information	11/26/2018 10:29:30 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/26/2018 10:29:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2018 10:29:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:29:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 10:29:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 10:24:18 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/26/2018 10:19:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 10:19:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-12-03T04:43:02Z. Reason: GVLK.
Information	11/26/2018 10:15:25 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9088.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/26/2018 10:14:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 10:14:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:14:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:14:01 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/11/26 04:43"
Information	11/26/2018 10:13:54 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/11/26 04:43, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/26/2018 10:09:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/26/2018 10:09:44 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 624

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1373

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1108

Information	11/26/2018 10:09:43 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/26/2018 10:08:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/26/2018 10:07:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65267)(?)])(1 )(2 )]

"
Information	11/26/2018 10:07:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2018 10:07:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65267)(?)])(1 )(2 )]

"
Information	11/26/2018 10:07:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:07:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2018 10:07:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 10:07:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 10:00:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2018 10:00:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 10:00:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 10:00:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 9:28:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 9:28:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:16Z. Reason: GVLK.
Information	11/26/2018 9:26:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 9:21:40 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:40 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:21:40 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	11/26/2018 9:21:40 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/26/2018 9:21:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65313)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 9:21:39 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/26/2018 9:21:38 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/26/2018 9:21:38 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 9:21:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2018 9:21:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 9:21:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 9:21:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 9:21:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:16 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2315. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:21:16 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	11/26/2018 9:21:14 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:14 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:21:14 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	11/26/2018 9:21:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:12 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:21:12 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	11/26/2018 9:21:06 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/26/2018 9:21:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:06 AM	ESENT	102	General	Windows (10988) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/26/2018 9:21:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:21:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:21:06 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	11/26/2018 9:20:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:20:33 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	11/26/2018 9:20:33 AM	ESENT	103	General	Windows (6828) Windows: The database engine stopped the instance (0).
Information	11/26/2018 9:20:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:20:32 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2315. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	11/26/2018 9:20:32 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	11/26/2018 9:19:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9392.
Information	11/26/2018 9:19:26 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/26/2018 9:19:25 AM	ESENT	102	General	Windows (6828) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/26/2018 9:19:22 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	11/26/2018 9:19:22 AM	ESENT	103	General	Windows (8704) Windows: The database engine stopped the instance (0).
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:20 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:20 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	11/26/2018 9:19:20 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:20 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:19:20 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	11/26/2018 9:18:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	11/26/2018 9:18:54 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	11/26/2018 9:18:53 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	11/26/2018 9:18:52 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	11/26/2018 9:18:51 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Error	11/26/2018 9:18:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/26/2018 9:18:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2018 9:18:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 9:18:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 9:18:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 9:16:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2018 9:16:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:42:52Z. Reason: GVLK.
Warning	11/26/2018 9:07:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2018 9:06:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86a85f12-f12c-11e8-b62b-204747d02364
Report Status: 0"
Information	11/26/2018 9:06:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2018 9:06:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65328)(?)])(1 )(2 )]

"
Information	11/26/2018 9:06:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65328)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 9:06:17 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65328)(?)])(1 )(2 )]

"
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=108528  Grace type=8.
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=09ef403d-dba0-46c9-b860-5cae6f679d71"
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=ad2372d9-ffc2-465d-95d8-79af4e423b00"
Information	11/26/2018 9:06:12 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Error	11/26/2018 9:05:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/26/2018 9:05:54 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/26/2018 9:05:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19249)(?)])(1 )(2 )]

"
Information	11/26/2018 9:05:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2018 9:05:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19249)(?)])(1 )(2 )]

"
Information	11/26/2018 9:05:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19249)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 9:05:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2018 9:05:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 9:05:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 9:05:02 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/26/2018 9:05:01 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/26/2018 9:05:00 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/26/2018 9:04:58 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/26/2018 9:04:43 AM	ESENT	302	Logging/Recovery	Windows (8704) Windows: The database engine has successfully completed recovery steps.
Information	11/26/2018 9:04:34 AM	ESENT	301	Logging/Recovery	Windows (8704) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/26/2018 9:04:33 AM	ESENT	300	Logging/Recovery	Windows (8704) Windows: The database engine is initiating recovery steps.
Information	11/26/2018 9:04:33 AM	ESENT	102	General	Windows (8704) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/26/2018 9:04:29 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/26/2018 9:04:29 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	11/26/2018 9:03:57 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/26/2018 9:03:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2018 9:03:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2018 9:03:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2018 9:03:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/26/2018 9:03:41 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9085.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/26/2018 9:03:15 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/26/2018 9:02:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/26/2018 9:02:55 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/26/2018 9:02:55 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/26/2018 9:02:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/26/2018 9:02:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/26/2018 9:02:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/26/2018 9:02:47 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/26/2018 9:02:47 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/26/2018 9:02:47 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/26/2018 9:02:46 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/26/2018 9:02:45 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Error	11/26/2018 9:02:32 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/26/2018 9:02:31 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/26/2018 9:02:20 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/26/2018 9:02:19 AM	PostgreSQL	0	None	"2018-11-26 09:02:19 IST LOG:  redirecting log output to logging collector process
2018-11-26 09:02:19 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/26/2018 9:02:18 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/26/2018 9:02:16 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/26/2018 9:01:39 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/26/2018 9:01:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/26/2018 9:01:39 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4416 at 11/23/2018 3:29:17 PM (local) 11/23/2018 9:59:17 AM (UTC). This is an informational message only; no user action is required.
Information	11/26/2018 9:01:38 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/26/2018 9:01:15 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/26/2018 9:01:14 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/26/2018 9:01:14 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/26/2018 9:01:14 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/26/2018 9:01:14 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4488.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/26/2018 9:01:05 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/26/2018 8:59:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/26/2018 8:59:04 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/26/2018 8:58:34 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/26/2018 8:58:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/26/2018 8:58:34 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	11/23/2018 3:29:16 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 192 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
"
Information	11/23/2018 3:29:17 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	11/23/2018 3:29:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/23/2018 3:29:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/23/2018 3:29:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/23/2018 3:29:12 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/23/2018 3:29:07 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	11/23/2018 3:22:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 2:33:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 2:32:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 2:32:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 1:28:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 887072a4-eef5-11e8-b886-204747d02364
Report Status: 0"
Warning	11/23/2018 1:25:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 12:03:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9085.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	11/23/2018 11:39:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 10:32:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 10:32:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 10:32:30 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/23/2018 10:32:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	11/23/2018 10:04:47 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 10:03:35 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:56:59 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:55:43 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:53:03 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/23/2018 9:52:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/23/2018 9:52:32 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	11/23/2018 9:51:51 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:50:39 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:48:25 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/23/2018 9:46:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/23/2018 9:44:15 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:43:03 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/23/2018 9:41:39 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/23/2018 9:36:47 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/23/2018 8:28:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9eccc835-eecb-11e8-b886-204747d02364
Report Status: 0"
Warning	11/23/2018 7:51:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 6:32:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 6:32:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/23/2018 6:18:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/23/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23834)(?)])(1 )(2 )]

"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23834)(?)])(1 )(2 )]

"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23834)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/23/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2018 4:41:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/23/2018 4:30:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 4:29:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2018 4:29:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:28Z. Reason: GVLK.
Information	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13948) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 16188) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10560) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 8744) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 8552) cannot be restarted - Application SID does not match Conductor SID..
Information	11/23/2018 4:24:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎11‎-‎22T22:54:36.080469200Z.
Information	11/23/2018 4:24:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎11‎-‎22T22:54:34.039265100Z.
Information	11/23/2018 4:24:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2018 4:24:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2018 4:24:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2018 4:24:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2018 3:53:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2018 3:53:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:36Z. Reason: GVLK.
Information	11/23/2018 3:48:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2018 3:48:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2018 3:48:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2018 3:48:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2018 3:47:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2018 3:47:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:42:53Z. Reason: GVLK.
Information	11/23/2018 3:42:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2018 3:42:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2018 3:42:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2018 3:42:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2018 3:28:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b519578d-eea1-11e8-b886-204747d02364
Report Status: 0"
Warning	11/23/2018 2:41:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 2:32:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 2:32:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2018 2:32:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/23/2018 1:05:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2018 12:30:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2018 12:30:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:40Z. Reason: GVLK.
Information	11/23/2018 12:25:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2018 12:25:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2018 12:25:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2018 12:25:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/22/2018 11:18:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 10:32:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 10:32:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 10:32:13 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/22/2018 10:31:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 10:28:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ca5f0e06-ee77-11e8-b886-204747d02364
Report Status: 0"
Warning	11/22/2018 9:38:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/22/2018 7:44:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 6:32:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 6:31:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2018 6:13:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 5:28:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e09e6155-ee4d-11e8-b886-204747d02364
Report Status: 0"
Warning	11/22/2018 4:40:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/22/2018 3:13:51 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (14) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181119_092148.log
"
Error	11/22/2018 3:13:51 PM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181119_092148.log
"
Warning	11/22/2018 2:54:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 2:32:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 2:31:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2018 1:12:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 12:47:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/22/2018 12:47:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/22/2018 12:32:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/22/2018 12:32:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/22/2018 12:28:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9084.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/22/2018 12:28:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6c62c01-ee23-11e8-b886-204747d02364
Report Status: 0"
Information	11/22/2018 11:45:49 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/22/2018 11:45:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/22/2018 11:45:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/22/2018 11:44:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 7, Compared: 28997, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/22/2018 11:42:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/22/2018 11:42:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	11/22/2018 11:25:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 10:44:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/22/2018 10:36:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/22/2018 10:33:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/22/2018 10:31:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/22/2018 10:31:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 10:31:54 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 343

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	11/22/2018 10:31:53 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/22/2018 10:31:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2018 10:31:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24924)(?)])(1 )(2 )]

"
Information	11/22/2018 10:31:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/22/2018 10:31:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24924)(?)])(1 )(2 )]

"
Information	11/22/2018 10:31:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24924)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 10:31:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/22/2018 10:31:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 10:30:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/22/2018 9:38:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 9:36:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2018 9:36:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:05Z. Reason: GVLK.
Information	11/22/2018 9:31:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2018 9:31:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 9:31:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 9:31:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/22/2018 9:13:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/22/2018 9:08:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25007)(?)])(1 )(2 )]

"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25007)(?)])(1 )(2 )]

"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25007)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 9:08:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/22/2018 7:59:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 7:28:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d1193a5-edfa-11e8-b886-204747d02364
Report Status: 0"
Warning	11/22/2018 6:13:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/22/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25274)(?)])(1 )(2 )]

"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25274)(?)])(1 )(2 )]

"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25274)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/22/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 4:41:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/22/2018 4:32:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 3:25:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2018 3:25:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:17Z. Reason: GVLK.
Information	11/22/2018 3:17:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2018 3:17:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 3:17:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 3:17:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/22/2018 3:01:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 2:28:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2364bbbc-edd0-11e8-b886-204747d02364
Report Status: 0"
Information	11/22/2018 1:32:51 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/22/2018 1:30:52 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/22/2018 1:13:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2018 12:19:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2018 12:19:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:40Z. Reason: GVLK.
Information	11/22/2018 12:14:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2018 12:14:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2018 12:14:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2018 12:14:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/22/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/21/2018 11:42:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/21/2018 10:03:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 9:28:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 39a8e02c-eda6-11e8-b886-204747d02364
Report Status: 0"
Warning	11/21/2018 8:32:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/21/2018 6:54:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 6:44:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/21/2018 5:00:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 4:28:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4fd65f69-ed7c-11e8-b886-204747d02364
Report Status: 0"
Information	11/21/2018 3:49:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 3:49:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:41Z. Reason: GVLK.
Information	11/21/2018 3:44:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2018 3:44:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 3:44:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 3:44:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/21/2018 3:21:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 3:21:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:09Z. Reason: GVLK.
Warning	11/21/2018 3:16:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 3:12:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2018 3:12:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 3:12:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 3:12:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/21/2018 2:49:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 2:44:12 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	11/21/2018 2:44:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 2:43:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26111)(?)])(1 )(2 )]

"
Information	11/21/2018 2:43:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/21/2018 2:43:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26111)(?)])(1 )(2 )]

"
Information	11/21/2018 2:43:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26111)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 2:43:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2018 2:43:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 2:43:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/21/2018 1:36:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 1:01:33 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 15491 milliseconds
Information	11/21/2018 12:50:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/21/2018 12:49:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/21/2018 12:42:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9083.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/21/2018 12:31:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 12:26:11 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 359

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	11/21/2018 12:25:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 12:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26250)(?)])(1 )(2 )]

"
Information	11/21/2018 12:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/21/2018 12:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26250)(?)])(1 )(2 )]

"
Information	11/21/2018 12:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26250)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 12:25:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2018 12:25:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 12:25:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/21/2018 11:54:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 11:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 65f589a9-ed52-11e8-b886-204747d02364
Report Status: 0"
Warning	11/21/2018 10:21:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 10:18:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 10:13:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26382)(?)])(1 )(2 )]

"
Information	11/21/2018 10:13:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/21/2018 10:13:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26382)(?)])(1 )(2 )]

"
Information	11/21/2018 10:13:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26382)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 10:13:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2018 10:13:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 10:13:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/21/2018 10:09:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/21/2018 10:09:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/21/2018 9:58:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 9:57:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 9:57:54 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/21/2018 9:57:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 9:35:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/21/2018 9:09:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 9:09:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:10Z. Reason: GVLK.
Information	11/21/2018 9:04:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2018 9:04:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 9:04:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 9:04:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/21/2018 8:44:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 7:44:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 7:44:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:49Z. Reason: GVLK.
Information	11/21/2018 7:39:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2018 7:39:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 7:39:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 7:39:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/21/2018 6:44:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 6:27:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c4a3bc4-ed28-11e8-b886-204747d02364
Report Status: 0"
Information	11/21/2018 5:58:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 5:57:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 5:57:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 5:57:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/21/2018 4:53:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 4:51:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 4:51:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:23Z. Reason: GVLK.
Information	11/21/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 4:41:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/21/2018 4:41:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/21/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26714)(?)])(1 )(2 )]

"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26714)(?)])(1 )(2 )]

"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26714)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2018 4:41:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/21/2018 3:07:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 2:20:11 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/21/2018 2:17:01 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/21/2018 1:57:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 1:57:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 1:57:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2018 1:27:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 928293f8-ecfe-11e8-b886-204747d02364
Report Status: 0"
Warning	11/21/2018 1:14:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/20/2018 11:16:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 9:57:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2018 9:57:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/20/2018 9:57:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2018 9:42:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 8:27:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8d43047-ecd4-11e8-b886-204747d02364
Report Status: 0"
Warning	11/20/2018 8:01:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 6:51:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 6:46:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27308)(?)])(1 )(2 )]

"
Information	11/20/2018 6:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2018 6:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27308)(?)])(1 )(2 )]

"
Information	11/20/2018 6:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27308)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 6:45:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27310)(?)])(1 )(2 )]

"
Information	11/20/2018 6:45:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2018 6:45:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27310)(?)])(1 )(2 )]

"
Information	11/20/2018 6:45:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27310)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 6:45:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2018 6:45:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 6:45:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/20/2018 6:26:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 5:57:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2018 4:37:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 3:27:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bf1155a1-ecaa-11e8-b886-204747d02364
Report Status: 0"
Information	11/20/2018 3:09:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 3:04:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2018 3:04:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 3:04:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/20/2018 2:58:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 1:57:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2018 1:27:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 12:57:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9082.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/20/2018 12:45:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:44:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/20/2018 12:39:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27680)(?)])(1 )(2 )]

"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27680)(?)])(1 )(2 )]

"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27680)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2018 12:34:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 12:34:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 12:23:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:22:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/20/2018 12:20:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:20:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/20/2018 12:17:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:16:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/20/2018 12:13:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:13:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/20/2018 12:00:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/20/2018 12:00:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/20/2018 11:49:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 11:37:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 11:37:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:08Z. Reason: GVLK.
Information	11/20/2018 11:32:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 11:32:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 11:32:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 11:32:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 10:27:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5576bc3-ec80-11e8-b886-204747d02364
Report Status: 0"
Information	11/20/2018 10:24:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 10:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27815)(?)])(1 )(2 )]

"
Information	11/20/2018 10:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2018 10:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27815)(?)])(1 )(2 )]

"
Information	11/20/2018 10:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27815)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 10:19:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2018 10:19:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 10:19:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/20/2018 10:11:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 9:56:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2018 9:56:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2018 9:56:50 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/20/2018 9:36:39 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/20/2018 9:36:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/20/2018 9:36:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	11/20/2018 8:24:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 7:00:14 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	11/20/2018 7:00:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 16188) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/20/2018 7:00:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 10560) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/20/2018 7:00:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 2452) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/20/2018 7:00:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 8744) cannot be restarted - Application SID does not match Conductor SID..
Warning	11/20/2018 7:00:13 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 8552) cannot be restarted - Application SID does not match Conductor SID..
Information	11/20/2018 7:00:13 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎11‎-‎20T01:30:13.790199600Z.
Information	11/20/2018 7:00:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎11‎-‎20T01:30:11.812189100Z.
Information	11/20/2018 6:58:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 6:58:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:27Z. Reason: GVLK.
Information	11/20/2018 6:53:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 6:53:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 6:53:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 6:53:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/20/2018 6:28:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 6:00:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 6:00:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:24Z. Reason: GVLK.
Information	11/20/2018 5:56:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2018 5:55:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 5:55:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 5:55:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 5:55:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 5:27:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb5c4092-ec56-11e8-b886-204747d02364
Report Status: 0"
Warning	11/20/2018 4:55:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 4:47:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 4:47:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:35Z. Reason: GVLK.
Information	11/20/2018 4:46:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 4:42:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 4:42:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 4:42:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 4:42:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/20/2018 4:41:25 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/20/2018 4:41:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28154)(?)])(1 )(2 )]

"
Information	11/20/2018 4:41:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2018 4:41:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28154)(?)])(1 )(2 )]

"
Information	11/20/2018 4:41:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28154)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 4:41:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2018 4:41:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 4:41:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 4:39:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 4:39:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:17Z. Reason: GVLK.
Information	11/20/2018 4:34:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 4:34:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 4:34:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 4:34:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 3:04:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2018 3:04:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:47Z. Reason: GVLK.
Warning	11/20/2018 3:01:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 2:59:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2018 2:59:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2018 2:59:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2018 2:59:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2018 1:56:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2018 1:56:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2018 1:24:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2018 12:27:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 01577cb4-ec2d-11e8-b886-204747d02364
Report Status: 0"
Information	11/20/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/19/2018 11:33:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/19/2018 9:58:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 9:56:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/19/2018 9:56:38 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/19/2018 9:56:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/19/2018 9:56:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/19/2018 8:13:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 7:27:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17804856-ec03-11e8-b886-204747d02364
Report Status: 0"
Information	11/19/2018 6:31:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎11‎-‎19T13:01:58.184100100Z.
Information	11/19/2018 6:31:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎11‎-‎19T13:01:58.184100100Z.
Warning	11/19/2018 6:16:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 5:56:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/19/2018 5:56:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/19/2018 4:18:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/19/2018 3:18:47 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	11/19/2018 3:18:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	11/19/2018 2:47:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 2:34:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/19/2018 2:33:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/19/2018 2:27:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2dba2f93-ebd9-11e8-b886-204747d02364
Report Status: 0"
Information	11/19/2018 1:56:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/19/2018 1:55:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/19/2018 12:58:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 12:36:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/19/2018 12:36:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/19/2018 12:04:15 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/19/2018 11:36:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 11:31:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29183)(?)])(1 )(2 )]

"
Information	11/19/2018 11:31:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/19/2018 11:31:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29183)(?)])(1 )(2 )]

"
Information	11/19/2018 11:31:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29183)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 11:31:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/19/2018 11:31:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 11:31:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/19/2018 11:01:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/19/2018 10:50:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 10:50:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:42:52Z. Reason: GVLK.
Information	11/19/2018 10:50:07 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/19/2018 10:49:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/19/2018 10:49:35 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/19/2018 10:49:27 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 28794, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/19/2018 10:46:05 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/19/2018 10:46:05 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/19/2018 10:45:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/19/2018 10:45:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 10:45:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 10:45:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 10:43:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 10:43:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:43:47Z. Reason: GVLK.
Information	11/19/2018 10:38:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/19/2018 10:38:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 10:38:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 10:38:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 10:30:25 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9081.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/19/2018 10:18:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 10:18:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:42:51Z. Reason: GVLK.
Information	11/19/2018 10:13:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 10:13:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 10:13:50 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/11/19 04:43"
Information	11/19/2018 10:13:49 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/11/19 04:43, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/19/2018 10:08:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/19/2018 10:08:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 10:08:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 10:08:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 10:00:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 9:56:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/19/2018 9:56:10 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/19/2018 9:55:45 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 156

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 46

Information	11/19/2018 9:55:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29280)(?)])(1 )(2 )]

"
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29280)(?)])(1 )(2 )]

"
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29280)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/19/2018 9:55:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 9:55:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 9:49:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 9:49:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T04:12:49Z. Reason: GVLK.
Information	11/19/2018 9:44:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/19/2018 9:39:21 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/19/2018 9:39:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29296)(?)])(1 )(2 )]

"
Information	11/19/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/19/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29296)(?)])(1 )(2 )]

"
Information	11/19/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29296)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:39:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/19/2018 9:39:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 9:39:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/19/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 9:38:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 9:34:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 9:34:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-26T03:58:51Z. Reason: GVLK.
Information	11/19/2018 9:32:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/19/2018 9:29:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:29:51 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	11/19/2018 9:29:51 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/11/19 03:59, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Error	11/19/2018 9:27:19 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {3B135ED0-EC7D-4BBC-A0D6-9C9E2ABBB57E}
Error	11/19/2018 9:27:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/19/2018 9:26:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29308)(?)])(1 )(2 )]

"
Information	11/19/2018 9:26:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/19/2018 9:26:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29308)(?)])(1 )(2 )]

"
Information	11/19/2018 9:26:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29308)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:26:49 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/19/2018 9:26:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/19/2018 9:26:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 9:26:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 9:26:29 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/19/2018 9:26:26 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/19/2018 9:26:24 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/19/2018 9:26:18 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/19/2018 9:25:57 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/19/2018 9:25:57 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	11/19/2018 9:25:31 AM	ESENT	302	Logging/Recovery	Windows (8388) Windows: The database engine has successfully completed recovery steps.
Information	11/19/2018 9:25:29 AM	ESENT	301	Logging/Recovery	Windows (8388) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/19/2018 9:25:21 AM	ESENT	301	Logging/Recovery	Windows (8388) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS01337.log.
Information	11/19/2018 9:25:21 AM	ESENT	300	Logging/Recovery	Windows (8388) Windows: The database engine is initiating recovery steps.
Information	11/19/2018 9:25:21 AM	ESENT	102	General	Windows (8388) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	11/19/2018 9:24:51 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/19/2018 9:24:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/19/2018 9:24:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/19/2018 9:24:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/19/2018 9:24:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/19/2018 9:24:39 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9078.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/19/2018 9:24:23 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/19/2018 9:23:42 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/19/2018 9:23:34 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/19/2018 9:23:32 AM	PostgreSQL	0	None	"2018-11-19 09:23:32 IST LOG:  redirecting log output to logging collector process
2018-11-19 09:23:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/19/2018 9:23:32 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/19/2018 9:23:31 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/19/2018 9:23:31 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/19/2018 9:23:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/19/2018 9:23:30 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/19/2018 9:23:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/19/2018 9:23:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/19/2018 9:23:30 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Error	11/19/2018 9:23:29 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/19/2018 9:23:28 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/19/2018 9:23:28 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/19/2018 9:23:27 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/19/2018 9:23:26 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/19/2018 9:23:26 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/19/2018 9:23:26 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/19/2018 9:23:26 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/19/2018 9:23:23 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/19/2018 9:23:18 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/19/2018 9:23:18 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/19/2018 9:23:18 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/19/2018 9:23:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/19/2018 9:23:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/19/2018 9:22:40 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/19/2018 9:22:40 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/19/2018 9:22:40 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4700 at 11/16/2018 3:30:56 PM (local) 11/16/2018 10:00:56 AM (UTC). This is an informational message only; no user action is required.
Information	11/19/2018 9:22:39 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/19/2018 9:22:22 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/19/2018 9:22:20 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/19/2018 9:22:20 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/19/2018 9:22:20 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/19/2018 9:22:20 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4416.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/19/2018 9:22:09 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Error	11/19/2018 9:22:01 AM	McLogEvent	1006	None	Task Manager : Service Error : StartServiceCtrlDispatcher failed.
Warning	11/19/2018 9:20:52 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/19/2018 9:20:40 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/19/2018 9:20:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/19/2018 9:20:11 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/19/2018 9:20:11 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/16/2018 3:30:56 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	11/16/2018 3:30:50 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/16/2018 3:30:48 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1040 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/16/2018 3:30:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/16/2018 3:30:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/16/2018 3:30:46 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/16/2018 3:30:41 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/16/2018 3:30:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/16/2018 3:30:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 3:30:34 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/16/2018 2:11:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 1:19:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 1:19:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 1:15:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a449d2ef-e973-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/16/2018 12:51:51 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/16/2018 12:34:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9078.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/16/2018 12:29:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/16/2018 12:29:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/16/2018 12:19:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 11:23:23 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/16/2018 11:07:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	11/16/2018 10:19:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 9:19:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 9:19:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 9:19:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 9:19:25 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/16/2018 9:19:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/16/2018 8:23:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 8:15:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ba834a9d-e949-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/16/2018 7:53:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2018 7:53:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:56Z. Reason: GVLK.
Information	11/16/2018 7:48:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2018 7:48:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2018 7:48:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 7:48:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/16/2018 6:36:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 5:19:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 5:19:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 5:19:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 5:19:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 4:51:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2018 4:51:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:51Z. Reason: GVLK.
Warning	11/16/2018 4:51:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 4:46:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2018 4:46:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2018 4:46:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 4:46:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/16/2018 4:46:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/16/2018 4:41:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/16/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33914)(?)])(1 )(2 )]

"
Information	11/16/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/16/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33914)(?)])(1 )(2 )]

"
Information	11/16/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33914)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/16/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 4:41:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/16/2018 3:55:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2018 3:55:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:06Z. Reason: GVLK.
Information	11/16/2018 3:50:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2018 3:50:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2018 3:50:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 3:50:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/16/2018 3:48:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2018 3:48:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:40Z. Reason: GVLK.
Information	11/16/2018 3:43:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2018 3:43:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2018 3:43:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2018 3:43:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/16/2018 3:15:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d0cd2bb3-e91f-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/16/2018 2:58:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/16/2018 1:21:27 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8313E <$UTL$   > DRIVER UTILITY REQUEST (16) EXIT CODE (9)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181112_091020.log
"
Error	11/16/2018 1:21:27 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8304E <$UTL$   > DRIVER UTILITY TERMINATED; REASON (Utility not responding)
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181112_091020.log
"
Warning	11/16/2018 1:21:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2018 1:19:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 1:19:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 1:19:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/15/2018 11:34:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 10:15:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e727c5c3-e8f5-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/15/2018 9:53:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 9:19:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 9:19:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 9:19:11 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/15/2018 9:19:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/15/2018 8:19:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 8:14:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 8:14:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:33Z. Reason: GVLK.
Information	11/15/2018 8:09:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 8:09:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 8:09:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 8:09:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2018 6:30:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/15/2018 5:59:33 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/15/2018 5:19:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 5:19:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 5:15:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fd49c47f-e8cb-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/15/2018 4:24:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/15/2018 2:36:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 1:19:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 1:18:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 1:13:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/15/2018 1:13:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/15/2018 12:58:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 12:53:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 12:53:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:35Z. Reason: GVLK.
Information	11/15/2018 12:52:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/15/2018 12:52:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/15/2018 12:48:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 12:48:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 12:48:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 12:48:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2018 12:25:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 12:25:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:53Z. Reason: GVLK.
Information	11/15/2018 12:20:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 12:20:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 12:20:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 12:20:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2018 12:15:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 13172ff6-e8a2-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/15/2018 12:08:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9077.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	11/15/2018 10:59:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 10:58:07 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/15/2018 10:58:04 AM	ESENT	102	General	Windows (9500) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/15/2018 10:57:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13552.
Information	11/15/2018 10:57:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20081. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	11/15/2018 10:57:44 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	11/15/2018 10:57:44 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20081. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.008.20081). Installation success or error status: 0.
Information	11/15/2018 10:57:44 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.008.20081)' installed successfully.
Information	11/15/2018 10:57:25 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	11/15/2018 10:57:25 AM	ESENT	103	General	Windows (8756) Windows: The database engine stopped the instance (0).
Information	11/15/2018 10:57:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13552.
Information	11/15/2018 10:56:03 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4448.
Information	11/15/2018 10:56:03 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20081. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	11/15/2018 10:56:03 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	11/15/2018 10:55:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4448.
Information	11/15/2018 9:30:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/15/2018 9:30:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/15/2018 9:30:26 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/15/2018 9:19:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 9:19:05 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/15/2018 9:18:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 9:18:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/15/2018 9:14:06 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	11/15/2018 9:02:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 9:01:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/15/2018 9:01:10 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 28808, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/15/2018 8:57:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/15/2018 8:57:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	11/15/2018 7:22:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 7:15:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 28e003f0-e878-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/15/2018 5:50:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 5:18:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 4:48:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 4:48:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:28Z. Reason: GVLK.
Information	11/15/2018 4:46:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 4:43:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 4:43:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 4:43:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 4:43:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/15/2018 4:41:22 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35354)(?)])(1 )(2 )]

"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35354)(?)])(1 )(2 )]

"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35354)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/15/2018 4:41:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 4:41:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/15/2018 4:40:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 4:40:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:59Z. Reason: GVLK.
Information	11/15/2018 4:34:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 4:34:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 4:34:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 4:34:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2018 3:56:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 2:15:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3e76318c-e84e-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/15/2018 2:02:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2018 2:02:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:06Z. Reason: GVLK.
Information	11/15/2018 2:00:42 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Warning	11/15/2018 1:59:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 1:57:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2018 1:57:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2018 1:57:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2018 1:57:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2018 1:56:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/15/2018 1:18:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2018 1:18:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/15/2018 12:08:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/14/2018 11:28:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 11:28:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:22Z. Reason: GVLK.
Information	11/14/2018 11:23:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2018 11:23:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 11:23:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 11:23:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/14/2018 10:33:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 9:18:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 9:18:34 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/14/2018 9:18:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 9:15:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 545afe11-e824-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/14/2018 8:55:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/14/2018 7:17:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/14/2018 5:45:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 5:18:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 4:15:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a221c59-e7fa-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/14/2018 4:06:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 3:09:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36171)(?)])(1 )(2 )]

"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36171)(?)])(1 )(2 )]

"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36171)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/14/2018 3:03:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 3:03:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/14/2018 2:12:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 1:57:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 1:57:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 1:18:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 1:18:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 1:17:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 1:17:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 1:15:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 1:15:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 12:45:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 12:44:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 12:27:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 12:27:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/14/2018 12:18:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 12:12:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 12:11:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 12:07:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 12:07:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/14/2018 12:05:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9076.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/14/2018 11:15:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 800ff975-e7d0-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/14/2018 11:11:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 11:07:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 11:07:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:16Z. Reason: GVLK.
Information	11/14/2018 11:06:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36408)(?)])(1 )(2 )]

"
Information	11/14/2018 11:06:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/14/2018 11:06:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36408)(?)])(1 )(2 )]

"
Information	11/14/2018 11:06:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36408)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 11:06:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/14/2018 11:06:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 11:06:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/14/2018 11:02:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2018 11:02:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 11:02:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 11:02:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/14/2018 10:45:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/14/2018 10:45:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/14/2018 10:41:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 9:18:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 9:18:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/14/2018 9:18:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 9:13:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/14/2018 9:13:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/14/2018 9:13:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	11/14/2018 8:57:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/14/2018 7:22:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 6:15:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95f6e480-e7a6-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/14/2018 5:31:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 5:18:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 5:17:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/14/2018 4:41:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/14/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36794)(?)])(1 )(2 )]

"
Information	11/14/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/14/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36794)(?)])(1 )(2 )]

"
Information	11/14/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36794)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/14/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 4:41:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/14/2018 3:48:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 3:39:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 3:39:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:22Z. Reason: GVLK.
Information	11/14/2018 3:29:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2018 3:29:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 3:29:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 3:29:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/14/2018 2:30:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/14/2018 2:28:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/14/2018 2:01:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2018 1:18:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 1:17:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2018 1:15:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: abda2622-e77c-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/14/2018 1:04:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2018 1:04:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:29Z. Reason: GVLK.
Information	11/14/2018 12:59:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2018 12:59:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2018 12:59:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2018 12:59:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/14/2018 12:01:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/13/2018 10:02:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 9:17:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 9:17:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 9:17:41 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/13/2018 9:17:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2018 8:16:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 8:15:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1ca5915-e752-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/13/2018 6:40:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 5:17:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 5:17:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2018 4:56:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 3:15:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7ceff33-e728-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/13/2018 3:06:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 3:06:37 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 3:01:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37613)(?)])(1 )(2 )]

"
Information	11/13/2018 3:01:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 3:01:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37613)(?)])(1 )(2 )]

"
Information	11/13/2018 3:01:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37613)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 3:01:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37614)(?)])(1 )(2 )]

"
Information	11/13/2018 3:01:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 3:01:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37614)(?)])(1 )(2 )]

"
Information	11/13/2018 3:01:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37614)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37616)(?)])(1 )(2 )]

"
Information	11/13/2018 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37616)(?)])(1 )(2 )]

"
Information	11/13/2018 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37616)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 2:58:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2018 2:58:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 2:58:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 2:12:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 2:12:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:02Z. Reason: GVLK.
Information	11/13/2018 2:07:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 2:07:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 2:07:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 2:07:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 1:22:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 1:19:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/13/2018 1:19:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/13/2018 1:17:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 1:17:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37717)(?)])(1 )(2 )]

"
Information	11/13/2018 1:17:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 1:17:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37717)(?)])(1 )(2 )]

"
Information	11/13/2018 1:17:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37717)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 1:17:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2018 1:17:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 1:17:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 1:17:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 1:17:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2018 1:11:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 1:04:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 12:59:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37736)(?)])(1 )(2 )]

"
Information	11/13/2018 12:59:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 12:59:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37736)(?)])(1 )(2 )]

"
Information	11/13/2018 12:58:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37736)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 12:58:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2018 12:58:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 12:58:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 12:37:03 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9075.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/13/2018 12:25:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/13/2018 12:25:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/13/2018 11:55:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/13/2018 11:55:16 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/13/2018 11:42:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/13/2018 11:42:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/13/2018 11:24:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 10:15:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed94910e-e6fe-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/13/2018 9:37:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 9:35:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 9:35:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:34Z. Reason: GVLK.
Information	11/13/2018 9:30:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 9:30:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 9:30:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 9:30:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 9:19:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/13/2018 9:19:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/13/2018 9:17:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 9:17:43 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/13/2018 9:17:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 9:13:25 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	11/13/2018 7:39:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 6:05:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 6:05:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:09Z. Reason: GVLK.
Information	11/13/2018 6:00:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 6:00:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 6:00:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 6:00:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/13/2018 5:43:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 5:17:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2018 5:15:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 037efa22-e6d5-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/13/2018 5:10:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 5:10:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:03Z. Reason: GVLK.
Information	11/13/2018 5:05:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 5:05:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 5:05:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 5:05:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 5:02:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 5:02:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:24Z. Reason: GVLK.
Information	11/13/2018 4:57:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 4:57:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 4:57:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 4:57:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/13/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/13/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38234)(?)])(1 )(2 )]

"
Information	11/13/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38234)(?)])(1 )(2 )]

"
Information	11/13/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38234)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 4:41:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2018 4:41:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 4:41:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/13/2018 4:10:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 3:21:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2018 3:21:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:11Z. Reason: GVLK.
Information	11/13/2018 3:16:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2018 3:16:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2018 3:16:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2018 3:16:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/13/2018 2:29:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 1:17:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2018 12:55:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2018 12:15:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1956a2b8-e6ab-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/12/2018 11:18:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/12/2018 9:23:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 9:17:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 9:17:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 9:16:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/12/2018 9:16:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 8:55:24 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/12/2018 8:50:53 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/12/2018 8:39:25 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/12/2018 7:28:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 7:15:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2f4f6888-e681-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/12/2018 6:21:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 6:16:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38858)(?)])(1 )(2 )]

"
Information	11/12/2018 6:16:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 6:16:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38858)(?)])(1 )(2 )]

"
Information	11/12/2018 6:16:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38858)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 6:16:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/12/2018 6:16:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 6:16:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/12/2018 5:35:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 5:19:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 5:17:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 5:16:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 5:14:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38921)(?)])(1 )(2 )]

"
Information	11/12/2018 5:14:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 5:14:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38921)(?)])(1 )(2 )]

"
Information	11/12/2018 5:14:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38921)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 5:14:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/12/2018 5:14:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 5:14:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 4:29:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 4:24:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38970)(?)])(1 )(2 )]

"
Information	11/12/2018 4:24:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 4:24:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38970)(?)])(1 )(2 )]

"
Information	11/12/2018 4:24:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38970)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 4:24:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/12/2018 4:24:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 4:24:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/12/2018 3:43:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 2:15:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 2:15:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 2:15:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 452259bb-e657-11e8-a1d4-204747d02364
Report Status: 0"
Warning	11/12/2018 2:06:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 1:48:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 1:47:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 1:17:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 1:16:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 1:07:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 1:06:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 1:05:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 1:04:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 12:29:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 12:28:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/12/2018 12:20:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 11:53:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 11:52:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 11:32:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/12/2018 11:32:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/12/2018 11:21:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 11:21:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:57Z. Reason: GVLK.
Information	11/12/2018 11:16:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/12/2018 11:16:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 11:16:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 11:16:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/12/2018 10:47:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 10:43:20 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, October 12, 2018 10:24:48 PM.
Information	11/12/2018 10:43:20 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UTN-USERFirst-Hardware, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US> Sha1 thumbprint: <0483ED3399AC3608058722EDBC5E4600E3BEF9D7>.
Information	11/12/2018 10:43:20 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Global Chambersign Root, OU=http://www.chambersign.org, O=AC Camerfirma SA CIF A82743287, C=EU> Sha1 thumbprint: <339B6B1450249B557A01877284D9E02FC3D2D8E9>.
Information	11/12/2018 10:43:20 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=TC TrustCenter Class 3 CA II, OU=TC TrustCenter Class 3 CA, O=TC TrustCenter GmbH, C=DE> Sha1 thumbprint: <8025EFF46E70C8D472246584FE403B8A8D6ADBF5>.
Information	11/12/2018 10:31:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 10:31:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:58Z. Reason: GVLK.
Information	11/12/2018 10:26:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/12/2018 10:26:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 10:26:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 10:26:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 10:12:50 AM	GE Software	0	(1)	++Installation complete
Information	11/12/2018 10:12:50 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++Started the installation of Cisco Jabber For Windows - Disable Presence V01 with the following commandline: /Q
Information	11/12/2018 10:12:32 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	11/12/2018 10:12:31 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	11/12/2018 10:05:45 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9074.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/12/2018 10:01:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 10:01:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:47:57Z. Reason: GVLK.
Information	11/12/2018 9:56:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/12/2018 9:56:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:56:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 9:56:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 9:36:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 9:36:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-19T03:48:08Z. Reason: GVLK.
Information	11/12/2018 9:33:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/12/2018 9:33:56 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/12/2018 9:30:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/12/2018 9:25:07 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/12/2018 9:25:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39390)(?)])(1 )(2 )]

"
Information	11/12/2018 9:25:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 9:25:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39390)(?)])(1 )(2 )]

"
Information	11/12/2018 9:25:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39390)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:25:06 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/12/2018 9:25:06 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 9:25:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 9:22:47 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 152, Deleted: 0, Modified: 242, Compared: 24670, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/12/2018 9:21:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/12/2018 9:18:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:18:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:18:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/11/12 03:48"
Information	11/12/2018 9:18:16 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/11/12 03:48, 0, 1, 241980, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/12/2018 9:17:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 9:16:59 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/12/2018 9:16:59 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9068.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/12/2018 9:16:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/12/2018 9:16:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/12/2018 9:16:37 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 655

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	11/12/2018 9:16:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/12/2018 9:15:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39400)(?)])(1 )(2 )]

"
Information	11/12/2018 9:15:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 9:15:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39400)(?)])(1 )(2 )]

"
Information	11/12/2018 9:15:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39400)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:15:14 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/12/2018 9:15:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5afd70b9-e62d-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/12/2018 9:14:11 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/12/2018 9:14:10 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/12/2018 9:14:09 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/12/2018 9:14:08 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	11/12/2018 9:13:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/12/2018 9:13:31 AM	ESENT	302	Logging/Recovery	Windows (8756) Windows: The database engine has successfully completed recovery steps.
Information	11/12/2018 9:13:25 AM	ESENT	301	Logging/Recovery	Windows (8756) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Warning	11/12/2018 9:13:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/12/2018 9:13:24 AM	ESENT	300	Logging/Recovery	Windows (8756) Windows: The database engine is initiating recovery steps.
Information	11/12/2018 9:13:24 AM	ESENT	102	General	Windows (8756) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/12/2018 9:13:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39402)(?)])(1 )(2 )]

"
Information	11/12/2018 9:13:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/12/2018 9:13:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/12/2018 9:13:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 241980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:13:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 9:13:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39402)(?)])(1 )(2 )]

"
Information	11/12/2018 9:13:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39402)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/12/2018 9:13:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/12/2018 9:13:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/12/2018 9:13:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 9:13:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/12/2018 9:13:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: mfevtp
P2: mfevtps.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 114a1592-e62d-11e8-a1d4-204747d02364
Report Status: 0"
Information	11/12/2018 9:13:07 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/12/2018 9:13:07 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	11/12/2018 9:11:52 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/12/2018 9:11:47 AM	Service1	0	None	Service started successfully.
Error	11/12/2018 9:11:40 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/12/2018 9:11:39 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/12/2018 9:11:35 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/12/2018 9:11:34 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/12/2018 9:11:33 AM	PostgreSQL	0	None	"2018-11-12 09:11:33 IST LOG:  redirecting log output to logging collector process
2018-11-12 09:11:33 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/12/2018 9:11:32 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/12/2018 9:11:30 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/12/2018 9:11:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/12/2018 9:11:05 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/12/2018 9:11:05 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/12/2018 9:11:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/12/2018 9:11:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/12/2018 9:10:59 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/12/2018 9:10:56 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:56 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/12/2018 9:10:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/12/2018 9:10:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/12/2018 9:10:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/12/2018 9:10:54 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4840 at 11/6/2018 7:07:19 PM (local) 11/6/2018 1:37:19 PM (UTC). This is an informational message only; no user action is required.
Information	11/12/2018 9:10:52 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/12/2018 9:10:51 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/12/2018 9:10:50 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/12/2018 9:10:50 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/12/2018 9:10:50 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/12/2018 9:10:50 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4700.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/12/2018 9:10:39 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	11/12/2018 9:09:39 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/12/2018 9:09:09 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/12/2018 9:09:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/12/2018 9:09:09 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/6/2018 7:07:30 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/6/2018 7:07:19 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/6/2018 7:07:09 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 892 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2188 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/6/2018 7:07:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/6/2018 7:07:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/6/2018 7:07:08 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/6/2018 7:07:02 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/6/2018 7:06:35 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 7:06:35 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 7:06:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 7:06:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 7:06:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 7:06:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 7:06:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/6/2018 6:26:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 5:46:02 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 5:41:07 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 515

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	11/6/2018 5:41:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2018 5:41:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/6/2018 5:40:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47534)(?)])(1 )(2 )]

"
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47534)(?)])(1 )(2 )]

"
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47534)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 5:40:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 5:40:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/6/2018 4:33:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 3:55:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 3:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47645)(?)])(1 )(2 )]

"
Information	11/6/2018 3:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 3:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47645)(?)])(1 )(2 )]

"
Information	11/6/2018 3:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47645)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 3:50:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 3:50:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 3:50:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 3:36:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b14eb080-e1ab-11e8-b18c-204747d02364
Report Status: 0"
Information	11/6/2018 3:30:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 3:30:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:07Z. Reason: GVLK.
Information	11/6/2018 3:25:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 3:25:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 3:25:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 3:25:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 3:19:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 3:14:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47681)(?)])(1 )(2 )]

"
Information	11/6/2018 3:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 3:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47681)(?)])(1 )(2 )]

"
Information	11/6/2018 3:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47681)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 3:14:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 3:14:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 3:14:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 3:14:05 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 297

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Warning	11/6/2018 2:47:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 2:31:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/6/2018 2:27:15 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x8144081f). If this error continues, contact Microsoft Support.
Information	11/6/2018 2:26:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/6/2018 2:26:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47728)(?)])(1 )(2 )]

"
Information	11/6/2018 2:26:48 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47728)(?)])(1 )(2 )]

"
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47728)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 2:26:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 2:26:47 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/6/2018 2:26:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 2:26:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 2122

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Warning	11/6/2018 12:49:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 12:46:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9068.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/6/2018 12:07:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 12:07:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:32Z. Reason: GVLK.
Information	11/6/2018 12:02:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 12:02:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 12:02:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 12:02:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 11:37:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 11:37:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:31Z. Reason: GVLK.
Information	11/6/2018 11:32:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 11:32:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 11:32:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 11:32:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 11:07:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 11:07:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:32Z. Reason: GVLK.
Information	11/6/2018 11:02:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 11:02:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 11:02:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 11:02:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:06Z. Reason: GVLK.
Information	11/6/2018 10:57:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 10:53:33 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	11/6/2018 10:51:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/6/2018 10:51:49 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	11/6/2018 10:51:49 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/6/2018 10:51:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47943)(?)])(1 )(2 )]

"
Information	11/6/2018 10:51:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 10:51:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47943)(?)])(1 )(2 )]

"
Information	11/6/2018 10:51:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47943)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 10:51:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 10:51:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 10:51:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:51:22 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2018 10:51:21 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2018 10:51:20 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2018 10:51:18 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/6/2018 10:50:37 AM	ESENT	302	Logging/Recovery	Windows (9140) Windows: The database engine has successfully completed recovery steps.
Information	11/6/2018 10:50:24 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/6/2018 10:50:24 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	11/6/2018 10:50:19 AM	ESENT	301	Logging/Recovery	Windows (9140) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/6/2018 10:50:18 AM	ESENT	300	Logging/Recovery	Windows (9140) Windows: The database engine is initiating recovery steps.
Information	11/6/2018 10:50:17 AM	ESENT	102	General	Windows (9140) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Warning	11/6/2018 10:50:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 10:49:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 10:49:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 10:49:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 10:49:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:49:36 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9067.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/6/2018 10:49:10 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	11/6/2018 10:48:43 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/6/2018 10:48:42 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/6/2018 10:48:17 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/6/2018 10:48:17 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/6/2018 10:48:13 AM	PostgreSQL	0	None	"2018-11-06 10:48:13 IST LOG:  redirecting log output to logging collector process
2018-11-06 10:48:13 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/6/2018 10:48:11 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/6/2018 10:47:33 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/6/2018 10:47:32 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/6/2018 10:47:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/6/2018 10:47:30 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/6/2018 10:47:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/6/2018 10:47:15 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/6/2018 10:47:15 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/6/2018 10:47:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/6/2018 10:47:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4304 at 11/6/2018 10:42:21 AM (local) 11/6/2018 5:12:21 AM (UTC). This is an informational message only; no user action is required.
Information	11/6/2018 10:47:13 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/6/2018 10:47:06 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/6/2018 10:47:05 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/6/2018 10:47:05 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/6/2018 10:47:05 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/6/2018 10:47:05 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4840.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/6/2018 10:46:54 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	11/6/2018 10:45:12 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2018 10:44:40 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/6/2018 10:44:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/6/2018 10:44:40 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/6/2018 10:42:31 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/6/2018 10:42:22 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	11/6/2018 10:42:21 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/6/2018 10:42:16 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 20 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 15640 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4340 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/6/2018 10:42:17 AM	MTAService.OnSessionChange	0	None	10:42:17 AM - Logoff
Information	11/6/2018 10:42:17 AM	MTAService.OnSessionChange	0	None	10:42:17 AM - Session change notice received: SessionLogoff Session ID: 2
Information	11/6/2018 10:42:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 2

"
Information	11/6/2018 10:42:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/6/2018 10:42:15 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/6/2018 10:42:05 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/6/2018 10:36:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c7f192dd-e181-11e8-a7f9-0205857feb80
Report Status: 0"
Information	11/6/2018 10:32:51 AM	MTAService.OnSessionChange	0	None	10:32:51 AM - Session change notice received: SessionUnlock Session ID: 2
Information	11/6/2018 10:27:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 10:27:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:18Z. Reason: GVLK.
Information	11/6/2018 10:22:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 10:22:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 10:22:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 10:22:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:15:42 AM	MTAService.OnSessionChange	0	None	10:15:42 AM - Session change notice received: SessionLock Session ID: 2
Information	11/6/2018 10:12:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 10:12:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 10:12:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:19Z. Reason: GVLK.
Information	11/6/2018 10:10:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	11/6/2018 10:07:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/6/2018 10:07:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	11/6/2018 10:07:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47987)(?)])(1 )(2 )]

"
Information	11/6/2018 10:07:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 10:07:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47987)(?)])(1 )(2 )]

"
Information	11/6/2018 10:07:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47987)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 10:07:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 10:07:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 10:07:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:07:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 10:07:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 10:07:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 10:07:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 10:07:16 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/6/2018 10:07:16 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	11/6/2018 10:07:01 AM	MTAService.OnSessionChange	0	None	10:07:01 AM - Logon : 212558710
Information	11/6/2018 10:07:01 AM	MTAService.OnSessionChange	0	None	10:07:01 AM - Session change notice received: SessionLogon Session ID: 2
Information	11/6/2018 10:07:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 2

"
Information	11/6/2018 10:07:00 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/6/2018 10:06:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 2

"
Information	11/6/2018 10:06:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	11/6/2018 9:06:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/6/2018 7:07:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 6:48:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 6:48:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:17Z. Reason: GVLK.
Information	11/6/2018 6:43:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 6:43:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 6:43:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 6:43:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 5:43:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 5:43:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:17Z. Reason: GVLK.
Information	11/6/2018 5:38:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 5:38:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 5:38:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 5:38:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 5:36:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de334569-e157-11e8-a7f9-0205857feb80
Report Status: 0"
Warning	11/6/2018 5:26:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/6/2018 4:41:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/6/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48314)(?)])(1 )(2 )]

"
Information	11/6/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48314)(?)])(1 )(2 )]

"
Information	11/6/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48314)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 4:41:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 4:31:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 4:31:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:48Z. Reason: GVLK.
Information	11/6/2018 4:26:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 4:26:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 4:26:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 4:26:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 4:26:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2018 4:26:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:27Z. Reason: GVLK.
Information	11/6/2018 4:21:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2018 4:21:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2018 4:21:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2018 4:21:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2018 4:14:57 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/6/2018 3:30:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/6/2018 1:48:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/6/2018 12:36:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f46edafb-e12d-11e8-a7f9-0205857feb80
Report Status: 0"
Warning	11/6/2018 12:09:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/5/2018 10:13:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 8:47:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 8:43:26 PM	MTAService.OnSessionChange	0	None	8:43:26 PM - Session change notice received: ConsoleConnect Session ID: 2
Information	11/5/2018 8:42:58 PM	MTAService.OnSessionChange	0	None	8:42:58 PM - Session change notice received: ConsoleDisconnect Session ID: 1
Information	11/5/2018 8:42:58 PM	MTAService.OnSessionChange	0	None	8:42:58 PM - Logoff
Information	11/5/2018 8:42:58 PM	MTAService.OnSessionChange	0	None	8:42:58 PM - Session change notice received: SessionLogoff Session ID: 1
Warning	11/5/2018 8:42:57 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 34 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1056 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 192 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 192 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 192 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 192 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 192 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2148 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/5/2018 8:42:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/5/2018 8:42:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/5/2018 8:42:55 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/5/2018 8:42:51 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	11/5/2018 8:42:35 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/5/2018 8:42:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 8:42:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 8:42:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/5/2018 8:42:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 8:33:51 PM	MTAService.OnSessionChange	0	None	8:33:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	11/5/2018 8:29:45 PM	MTAService.OnSessionChange	0	None	8:29:45 PM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 7:36:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0aa5c81e-e104-11e8-a7f9-0205857feb80
Report Status: 0"
Warning	11/5/2018 6:52:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 6:31:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/5/2018 5:52:03 PM	MTAService.OnSessionChange	0	None	5:52:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	11/5/2018 5:05:21 PM	MTAService.OnSessionChange	0	None	5:05:21 PM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 5:02:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 4:57:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49018)(?)])(1 )(2 )]

"
Information	11/5/2018 4:57:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 4:57:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49018)(?)])(1 )(2 )]

"
Information	11/5/2018 4:57:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49018)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 4:57:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 4:57:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 4:57:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/5/2018 4:57:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/5/2018 3:01:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 2:36:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 20fc83d7-e0da-11e8-a7f9-0205857feb80
Report Status: 0"
Information	11/5/2018 2:36:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 2:31:20 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 328

Information	11/5/2018 2:30:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/5/2018 2:30:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49164)(?)])(1 )(2 )]

"
Information	11/5/2018 2:30:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 2:30:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49164)(?)])(1 )(2 )]

"
Information	11/5/2018 2:30:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49164)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 2:30:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 2:30:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 2:30:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 2:30:22 PM	MTAService.OnSessionChange	0	None	2:30:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	11/5/2018 1:58:44 PM	MTAService.OnSessionChange	0	None	1:58:44 PM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 1:56:13 PM	MTAService.OnSessionChange	0	None	1:56:13 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	11/5/2018 1:10:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 1:10:03 PM	MTAService.OnSessionChange	0	None	1:10:03 PM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 12:29:46 PM	MTAService.OnSessionChange	0	None	12:29:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	11/5/2018 12:09:16 PM	MTAService.OnSessionChange	0	None	12:09:16 PM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 11:48:25 AM	MTAService.OnSessionChange	0	None	11:48:25 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	11/5/2018 11:30:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 11:28:47 AM	MTAService.OnSessionChange	0	None	11:28:47 AM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 11:12:42 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 11:07:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49367)(?)])(1 )(2 )]

"
Information	11/5/2018 11:07:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 11:07:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49367)(?)])(1 )(2 )]

"
Information	11/5/2018 11:07:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49367)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 11:07:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 11:07:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 11:07:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 10:54:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 10:54:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:06Z. Reason: GVLK.
Information	11/5/2018 10:49:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/5/2018 10:49:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 10:49:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 10:49:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 10:24:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 10:24:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:08Z. Reason: GVLK.
Information	11/5/2018 10:19:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/5/2018 10:19:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 10:19:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 10:19:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 10:14:39 AM	MTAService.OnSessionChange	0	None	10:14:39 AM - Session change notice received: SessionUnlock Session ID: 1
Information	11/5/2018 10:04:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9067.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/5/2018 10:04:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 10:04:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:30Z. Reason: GVLK.
Information	11/5/2018 10:01:23 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/5/2018 10:01:23 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/5/2018 9:58:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/5/2018 9:58:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:58:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 9:58:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 9:57:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 9, Deleted: 0, Modified: 0, Compared: 28395, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/5/2018 9:55:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 9:54:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 9:54:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:03Z. Reason: GVLK.
Information	11/5/2018 9:54:01 AM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9066.0000.
Information	11/5/2018 9:52:16 AM	McLogEvent	257	None	The scan of C:\Users\212558710\Desktop\Share\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9066.0000.
Information	11/5/2018 9:50:58 AM	MTAService.OnSessionChange	0	None	9:50:58 AM - Session change notice received: SessionLock Session ID: 1
Information	11/5/2018 9:50:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/5/2018 9:50:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/5/2018 9:50:17 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 187

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	11/5/2018 9:50:17 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/5/2018 9:48:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/5/2018 9:48:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49447)(?)])(1 )(2 )]

"
Information	11/5/2018 9:48:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 9:48:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49447)(?)])(1 )(2 )]

"
Information	11/5/2018 9:48:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49447)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:44:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/5/2018 9:44:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:44:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 9:44:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/5/2018 9:43:57 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49451)(?)])(1 )(2 )]

"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49451)(?)])(1 )(2 )]

"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49451)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 9:43:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 9:43:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 9:41:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 9:41:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:39Z. Reason: GVLK.
Information	11/5/2018 9:40:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/5/2018 9:39:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Warning	11/5/2018 9:38:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/5/2018 9:36:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37a4ec08-e0b0-11e8-a7f9-204747d02364
Report Status: 0"
Information	11/5/2018 9:35:55 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	11/5/2018 9:35:13 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {8C401E05-17D4-4443-A3FA-CA74F7811060}
Information	11/5/2018 9:35:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	11/5/2018 9:35:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49460)(?)])(1 )(2 )]

"
Error	11/5/2018 9:35:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/5/2018 9:35:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/5/2018 9:35:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49460)(?)])(1 )(2 )]

"
Information	11/5/2018 9:35:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:35:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/5/2018 9:35:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 9:35:01 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/5/2018 9:35:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 9:34:58 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/5/2018 9:34:58 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/5/2018 9:34:57 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/5/2018 9:34:44 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/5/2018 9:34:44 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	11/5/2018 9:34:20 AM	ESENT	302	Logging/Recovery	Windows (9260) Windows: The database engine has successfully completed recovery steps.
Information	11/5/2018 9:34:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/5/2018 9:34:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/5/2018 9:34:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/5/2018 9:34:15 AM	ESENT	301	Logging/Recovery	Windows (9260) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/5/2018 9:34:15 AM	ESENT	300	Logging/Recovery	Windows (9260) Windows: The database engine is initiating recovery steps.
Information	11/5/2018 9:34:14 AM	ESENT	102	General	Windows (9260) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	11/5/2018 9:34:11 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/5/2018 9:34:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/5/2018 9:33:51 AM	Service1	0	None	Service started successfully.
Information	11/5/2018 9:33:47 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/5/2018 9:33:47 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/5/2018 9:33:47 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/5/2018 9:33:46 AM	MTAService.OnSessionChange	0	None	9:33:46 AM - Logon : 212558710
Information	11/5/2018 9:33:46 AM	MTAService.OnSessionChange	0	None	9:33:46 AM - Session change notice received: SessionLogon Session ID: 1
Information	11/5/2018 9:33:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/5/2018 9:33:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/5/2018 9:33:40 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9066.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	11/5/2018 9:33:40 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/5/2018 9:33:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/5/2018 9:33:39 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/5/2018 9:33:35 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/5/2018 9:33:35 AM	MTAService	0	None	Service started successfully.
Information	11/5/2018 9:33:35 AM	MTAService.OnStart	0	None	9:33:35 AM - Waiting for user to Logon
Information	11/5/2018 9:33:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/5/2018 9:33:34 AM	PostgreSQL	0	None	"2018-11-05 09:33:34 IST LOG:  redirecting log output to logging collector process
2018-11-05 09:33:34 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/5/2018 9:33:34 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/5/2018 9:33:32 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/5/2018 9:33:31 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Warning	11/5/2018 9:33:27 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4244 at 11/4/2018 10:31:54 PM (local) 11/4/2018 5:01:54 PM (UTC). This is an informational message only; no user action is required.
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/5/2018 9:33:27 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/5/2018 9:33:26 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/5/2018 9:33:26 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/5/2018 9:33:26 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/5/2018 9:33:26 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4304.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/5/2018 9:33:25 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	11/5/2018 9:33:16 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/5/2018 9:33:11 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/5/2018 9:33:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/5/2018 9:33:11 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/4/2018 10:32:01 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	11/4/2018 10:31:48 PM	McLogEvent	257	None	The scan of C:\Windows\System32\en-US\KERNELBASE.dll.mui has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9066.0000.
Error	11/4/2018 10:31:47 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/4/2018 10:31:45 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 756 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4352 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4352 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2100 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/4/2018 10:31:45 PM	MTAService.OnSessionChange	0	None	10:31:45 PM - Logoff
Information	11/4/2018 10:31:45 PM	MTAService.OnSessionChange	0	None	10:31:45 PM - Session change notice received: SessionLogoff Session ID: 1
Information	11/4/2018 10:31:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/4/2018 10:31:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/4/2018 10:31:43 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/4/2018 10:31:34 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Error	11/4/2018 10:31:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 10:31:31 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/4/2018 10:30:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/4/2018 10:30:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:15Z. Reason: GVLK.
Information	11/4/2018 10:28:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/4/2018 10:24:29 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	11/4/2018 10:23:24 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B0E57862-C48A-4FEF-B579-3709352004CF}
Error	11/4/2018 10:23:24 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B0E57862-C48A-4FEF-B579-3709352004CF}
Error	11/4/2018 10:23:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/4/2018 10:23:17 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 10:23:15 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 10:23:13 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 10:23:10 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/4/2018 10:22:50 PM	ESENT	302	Logging/Recovery	Windows (9288) Windows: The database engine has successfully completed recovery steps.
Information	11/4/2018 10:22:49 PM	ESENT	301	Logging/Recovery	Windows (9288) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/4/2018 10:22:49 PM	ESENT	300	Logging/Recovery	Windows (9288) Windows: The database engine is initiating recovery steps.
Information	11/4/2018 10:22:49 PM	ESENT	102	General	Windows (9288) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/4/2018 10:22:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/4/2018 10:22:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 10:22:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	11/4/2018 10:22:36 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/4/2018 10:22:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/4/2018 10:22:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50132)(?)])(1 )(2 )]

"
Information	11/4/2018 10:22:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/4/2018 10:22:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50132)(?)])(1 )(2 )]

"
Information	11/4/2018 10:22:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50132)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 10:22:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/4/2018 10:22:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/4/2018 10:22:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/4/2018 10:22:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9066.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/4/2018 10:21:32 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/4/2018 10:21:32 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	11/4/2018 10:20:53 PM	PostgreSQL	0	None	Server started and accepting connections

Information	11/4/2018 10:20:49 PM	Service1	0	None	Service started successfully.
Error	11/4/2018 10:20:43 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/4/2018 10:20:43 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	11/4/2018 10:20:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/4/2018 10:20:35 PM	MTAService	0	None	Service started successfully.
Information	11/4/2018 10:20:28 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	11/4/2018 10:20:03 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/4/2018 10:20:03 PM	PostgreSQL	0	None	"2018-11-04 22:20:03 IST LOG:  redirecting log output to logging collector process
2018-11-04 22:20:03 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/4/2018 10:20:01 PM	PostgreSQL	0	None	Waiting for server startup...

Information	11/4/2018 10:19:49 PM	MTAService.OnStart	0	None	10:19:47 PM - User is already logged in : 212558710
Information	11/4/2018 10:19:49 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/4/2018 10:19:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/4/2018 10:19:33 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/4/2018 10:19:33 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/4/2018 10:19:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/4/2018 10:19:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/4/2018 10:19:28 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4524 at 11/4/2018 5:40:55 PM (local) 11/4/2018 12:10:55 PM (UTC). This is an informational message only; no user action is required.
Information	11/4/2018 10:19:26 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/4/2018 10:19:25 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/4/2018 10:19:25 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/4/2018 10:19:25 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/4/2018 10:19:25 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/4/2018 10:19:25 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4244.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/4/2018 10:19:24 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/4/2018 10:19:14 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/4/2018 10:19:08 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 10:18:57 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/4/2018 10:18:57 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/4/2018 10:18:57 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/4/2018 9:59:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/4/2018 9:59:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:51Z. Reason: GVLK.
Information	11/4/2018 9:54:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/4/2018 9:54:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 9:54:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/4/2018 9:54:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/4/2018 9:29:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/4/2018 9:29:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:57Z. Reason: GVLK.
Information	11/4/2018 9:24:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/4/2018 9:24:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 9:24:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/4/2018 9:24:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/4/2018 9:24:51 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 9:24:48 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 9:24:44 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 9:24:37 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 9:24:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 6:11:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 6:03:04 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/4/2018 6:02:50 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/4/2018 6:01:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/4/2018 6:01:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:47Z. Reason: GVLK.
Information	11/4/2018 5:56:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/4/2018 5:51:25 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/4/2018 5:51:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50404)(?)])(1 )(2 )]

"
Information	11/4/2018 5:51:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/4/2018 5:51:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50404)(?)])(1 )(2 )]

"
Information	11/4/2018 5:51:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50404)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 5:50:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0dabf701-e02c-11e8-bc48-204747d02364
Report Status: 0"
Error	11/4/2018 5:46:38 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {08DC22DC-DD2D-409C-99E6-475A24894C7C}
Information	11/4/2018 5:46:25 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	11/4/2018 5:45:30 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/4/2018 5:44:57 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 5:44:54 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 5:44:53 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 5:44:49 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/4/2018 5:44:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50410)(?)])(1 )(2 )]

"
Information	11/4/2018 5:44:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/4/2018 5:44:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50410)(?)])(1 )(2 )]

"
Information	11/4/2018 5:44:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50410)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 5:44:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/4/2018 5:44:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/4/2018 5:44:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/4/2018 5:44:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/4/2018 5:44:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/4/2018 5:44:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	11/4/2018 5:44:32 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/4/2018 5:44:31 PM	ESENT	302	Logging/Recovery	Windows (9164) Windows: The database engine has successfully completed recovery steps.
Information	11/4/2018 5:44:26 PM	ESENT	301	Logging/Recovery	Windows (9164) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/4/2018 5:44:26 PM	ESENT	300	Logging/Recovery	Windows (9164) Windows: The database engine is initiating recovery steps.
Information	11/4/2018 5:44:26 PM	ESENT	102	General	Windows (9164) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/4/2018 5:44:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/4/2018 5:44:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9066.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/4/2018 5:43:11 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/4/2018 5:43:11 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	11/4/2018 5:42:01 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/4/2018 5:42:00 PM	Service1	0	None	Service started successfully.
Error	11/4/2018 5:41:51 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/4/2018 5:41:38 PM	PostgreSQL	0	None	Server started and accepting connections

Information	11/4/2018 5:41:36 PM	PostgreSQL	0	None	"2018-11-04 17:41:36 IST LOG:  redirecting log output to logging collector process
2018-11-04 17:41:36 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/4/2018 5:41:33 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/4/2018 5:41:32 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/4/2018 5:41:31 PM	PostgreSQL	0	None	Waiting for server startup...

Information	11/4/2018 5:41:14 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/4/2018 5:41:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/4/2018 5:41:02 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/4/2018 5:41:02 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/4/2018 5:41:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/4/2018 5:41:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/4/2018 5:41:00 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/4/2018 5:41:00 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/4/2018 5:41:00 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/4/2018 5:41:00 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/4/2018 5:41:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/4/2018 5:40:59 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/4/2018 5:40:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/4/2018 5:40:59 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/4/2018 5:40:57 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4500 at 11/3/2018 11:28:13 PM (local) 11/3/2018 5:58:13 PM (UTC). This is an informational message only; no user action is required.
Information	11/4/2018 5:40:55 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/4/2018 5:40:53 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/4/2018 5:40:53 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/4/2018 5:40:53 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/4/2018 5:40:53 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/4/2018 5:40:53 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4524.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/4/2018 5:40:43 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/4/2018 5:40:23 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/4/2018 5:40:14 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/4/2018 5:40:03 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/4/2018 5:40:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/4/2018 5:40:03 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/3/2018 11:28:21 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/3/2018 11:28:13 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	11/3/2018 11:28:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/3/2018 11:28:04 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 308 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2300 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/3/2018 11:28:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/3/2018 11:28:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/3/2018 11:28:02 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/3/2018 11:27:57 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	11/3/2018 11:27:56 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/3/2018 11:12:25 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9066.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/3/2018 10:54:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2018 10:54:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:08Z. Reason: GVLK.
Information	11/3/2018 10:49:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2018 10:49:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 10:49:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 10:49:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 10:24:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2018 10:24:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:08Z. Reason: GVLK.
Information	11/3/2018 10:19:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2018 10:19:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 10:19:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 10:19:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 9:55:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2018 9:55:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:33Z. Reason: GVLK.
Information	11/3/2018 9:55:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/3/2018 9:50:19 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/3/2018 9:50:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51605)(?)])(1 )(2 )]

"
Information	11/3/2018 9:50:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/3/2018 9:50:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51605)(?)])(1 )(2 )]

"
Information	11/3/2018 9:50:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51605)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 9:50:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/3/2018 9:50:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 9:50:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 9:49:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2018 9:49:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 9:49:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 9:49:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 9:43:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2018 9:43:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:09Z. Reason: GVLK.
Information	11/3/2018 9:42:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/3/2018 9:41:08 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/3/2018 9:41:01 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/3/2018 9:37:22 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	11/3/2018 9:37:18 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {658F5D03-D89F-449B-8D6C-7B8DBABEF99C}
Error	11/3/2018 9:37:18 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {658F5D03-D89F-449B-8D6C-7B8DBABEF99C}
Information	11/3/2018 9:37:08 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/3/2018 9:37:07 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/3/2018 9:37:05 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	11/3/2018 9:37:04 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/3/2018 9:37:02 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/3/2018 9:36:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51618)(?)])(1 )(2 )]

"
Information	11/3/2018 9:36:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/3/2018 9:36:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51618)(?)])(1 )(2 )]

"
Information	11/3/2018 9:36:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51618)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 9:36:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/3/2018 9:36:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 9:36:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 9:36:28 PM	ESENT	302	Logging/Recovery	Windows (9056) Windows: The database engine has successfully completed recovery steps.
Information	11/3/2018 9:36:17 PM	ESENT	301	Logging/Recovery	Windows (9056) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/3/2018 9:36:17 PM	ESENT	300	Logging/Recovery	Windows (9056) Windows: The database engine is initiating recovery steps.
Information	11/3/2018 9:36:17 PM	ESENT	102	General	Windows (9056) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/3/2018 9:36:13 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	11/3/2018 9:36:13 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	11/3/2018 9:35:33 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/3/2018 9:35:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2018 9:35:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2018 9:35:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2018 9:35:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2018 9:35:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9064.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/3/2018 9:35:03 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/3/2018 9:34:08 PM	PostgreSQL	0	None	Server started and accepting connections

Error	11/3/2018 9:34:08 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/3/2018 9:34:07 PM	PostgreSQL	0	None	"2018-11-03 21:34:07 IST LOG:  redirecting log output to logging collector process
2018-11-03 21:34:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/3/2018 9:34:07 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/3/2018 9:34:06 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/3/2018 9:34:03 PM	PostgreSQL	0	None	Waiting for server startup...

Information	11/3/2018 9:33:53 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:52 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/3/2018 9:33:52 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/3/2018 9:33:52 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/3/2018 9:33:52 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/3/2018 9:33:52 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/3/2018 9:33:52 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/3/2018 9:33:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/3/2018 9:33:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/3/2018 9:33:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/3/2018 9:33:51 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/3/2018 9:33:50 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/3/2018 9:33:24 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:24 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:24 PM	MSSQL$SQLEXPRESS	3406	Server	3 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4364 at 11/2/2018 9:04:42 PM (local) 11/2/2018 3:34:42 PM (UTC). This is an informational message only; no user action is required.
Information	11/3/2018 9:33:23 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/3/2018 9:33:14 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/3/2018 9:33:13 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/3/2018 9:33:13 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/3/2018 9:33:13 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/3/2018 9:33:13 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4500.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/3/2018 9:33:04 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/3/2018 9:31:57 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/3/2018 9:31:34 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/3/2018 9:31:01 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/3/2018 9:31:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/3/2018 9:31:02 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/2/2018 9:04:57 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/2/2018 9:04:42 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	11/2/2018 9:04:39 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/2/2018 9:04:37 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 548 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2044 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/2/2018 9:04:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/2/2018 9:04:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/2/2018 9:04:35 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/2/2018 9:04:31 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	11/2/2018 7:46:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/2/2018 7:09:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c5fe581d-dea4-11e8-9b6a-204747d02364
Report Status: 0"
Information	11/2/2018 7:04:50 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 46629 milliseconds
Warning	11/2/2018 7:00:07 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 18020 did not respond and is being forcibly terminated {filter host process 16208}. 

Warning	11/2/2018 5:49:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/2/2018 5:00:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2018 4:59:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/2/2018 4:00:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/2/2018 2:23:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/2/2018 2:09:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dbc4f9b9-de7a-11e8-9b6a-204747d02364
Report Status: 0"
Information	11/2/2018 1:31:46 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 28507, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/2/2018 1:30:00 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/2/2018 1:00:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2018 12:59:57 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/2/2018 12:59:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/2/2018 12:34:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/2/2018 12:28:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9064.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/2/2018 12:22:46 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/2/2018 12:22:37 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/2/2018 12:22:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	11/2/2018 10:38:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/2/2018 9:44:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2018 9:39:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53775)(?)])(1 )(2 )]

"
Information	11/2/2018 9:39:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2018 9:39:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53775)(?)])(1 )(2 )]

"
Information	11/2/2018 9:39:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53775)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2018 9:39:40 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2018 9:39:40 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2018 9:39:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2018 9:15:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2018 9:15:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/2/2018 9:15:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:03Z. Reason: GVLK.
Error	11/2/2018 9:10:16 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/2/2018 9:10:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53805)(?)])(1 )(2 )]

"
Information	11/2/2018 9:10:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2018 9:10:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53805)(?)])(1 )(2 )]

"
Information	11/2/2018 9:10:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53805)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2018 9:10:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2018 9:10:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2018 9:10:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2018 9:09:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/2/2018 9:09:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2018 9:09:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2018 9:09:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f1c302eb-de50-11e8-9b6a-204747d02364
Report Status: 0"
Information	11/2/2018 9:09:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/2/2018 9:09:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/2/2018 9:09:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:08Z. Reason: GVLK.
Information	11/2/2018 9:02:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/2/2018 9:02:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2018 9:02:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2018 9:02:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/2/2018 9:01:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/2/2018 8:59:51 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	11/2/2018 8:59:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	11/2/2018 8:59:47 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/2/2018 8:59:44 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	11/2/2018 8:59:38 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	11/1/2018 8:23:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 8:19:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2018 8:19:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:26Z. Reason: GVLK.
Information	11/1/2018 8:14:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2018 8:14:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2018 8:14:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2018 8:14:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/1/2018 7:59:05 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 11568 did not respond and is being forcibly terminated {filter host process 15352}. 

Information	11/1/2018 7:50:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b1d897e-dde1-11e8-9b6a-204747d02364
Report Status: 0"
Warning	11/1/2018 6:41:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 5:38:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 5:38:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/1/2018 4:47:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/1/2018 3:28:57 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 16084 did not respond and is being forcibly terminated {filter host process 14472}. 

Information	11/1/2018 2:59:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2018 2:59:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:22Z. Reason: GVLK.
Warning	11/1/2018 2:58:43 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 11848 did not respond and is being forcibly terminated {filter host process 17068}. 

Information	11/1/2018 2:54:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2018 2:54:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2018 2:54:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2018 2:54:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2018 2:50:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6120f536-ddb7-11e8-9b6a-204747d02364
Report Status: 0"
Warning	11/1/2018 2:49:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 1:59:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2018 1:59:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:25:07Z. Reason: GVLK.
Information	11/1/2018 1:54:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2018 1:54:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2018 1:54:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2018 1:54:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2018 1:38:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 1:38:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/1/2018 1:38:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/1/2018 1:01:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 12:26:35 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/1/2018 12:24:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9063.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/1/2018 12:11:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/1/2018 12:11:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/1/2018 11:35:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/1/2018 11:35:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	11/1/2018 11:08:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 9:50:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 771701a2-dd8d-11e8-9b6a-204747d02364
Report Status: 0"
Information	11/1/2018 9:38:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 9:38:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/1/2018 9:38:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 9:30:30 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	11/1/2018 9:30:27 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	11/1/2018 9:19:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/1/2018 7:36:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/1/2018 5:41:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 5:41:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2018 5:41:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:51Z. Reason: GVLK.
Information	11/1/2018 5:38:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 5:38:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 5:36:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2018 5:36:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2018 5:36:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2018 5:36:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2018 4:50:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8d03102c-dd63-11e8-9b6a-204747d02364
Report Status: 0"
Information	11/1/2018 4:46:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/1/2018 4:41:20 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	11/1/2018 4:41:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55514)(?)])(1 )(2 )]

"
Information	11/1/2018 4:41:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/1/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55514)(?)])(1 )(2 )]

"
Information	11/1/2018 4:41:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55514)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2018 4:41:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/1/2018 4:41:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2018 4:41:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/1/2018 3:45:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/1/2018 1:58:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/1/2018 1:38:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2018 1:38:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/1/2018 12:11:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 11:50:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2f8a9e3-dd39-11e8-9b6a-204747d02364
Report Status: 0"
Warning	10/31/2018 10:26:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 9:38:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 9:38:15 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/31/2018 9:38:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 9:37:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/31/2018 8:29:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/31/2018 6:57:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 6:50:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b8c60295-dd0f-11e8-9b6a-204747d02364
Report Status: 0"
Information	10/31/2018 6:49:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2018 6:43:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56112)(?)])(1 )(2 )]

"
Information	10/31/2018 6:43:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 6:43:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56112)(?)])(1 )(2 )]

"
Information	10/31/2018 6:43:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56112)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 6:43:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2018 6:43:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 6:43:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/31/2018 6:24:32 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/31/2018 6:20:09 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/31/2018 5:55:36 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/31/2018 5:38:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 5:37:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/31/2018 5:11:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 5:03:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/31/2018 5:01:25 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 5:00:42 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 5:00:10 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 4:59:39 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/31/2018 4:58:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56216)(?)])(1 )(2 )]

"
Information	10/31/2018 4:58:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 4:58:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56216)(?)])(1 )(2 )]

"
Information	10/31/2018 4:58:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56216)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 4:58:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2018 4:58:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 4:58:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/31/2018 3:31:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/31/2018 3:00:03 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	10/31/2018 1:51:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 1:50:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ce7ee7b3-dce5-11e8-9b6a-204747d02364
Report Status: 0"
Information	10/31/2018 1:37:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 1:37:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 1:31:11 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/31/2018 1:30:50 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Error	10/31/2018 1:27:03 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/31/2018 1:02:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 1:02:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:45:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:43:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:41:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:40:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:39:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:38:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:32:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:32:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:32:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:31:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:29:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:28:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:28:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:28:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:24:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:24:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:18:37 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/31/2018 12:08:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:08:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 12:07:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 12:07:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9062.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	10/31/2018 11:58:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 11:38:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 11:37:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 11:10:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2018 11:05:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56570)(?)])(1 )(2 )]

"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56570)(?)])(1 )(2 )]

"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56570)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 11:05:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/31/2018 11:00:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 10:59:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2018 10:47:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2018 10:46:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/31/2018 10:17:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 10:00:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2018 10:00:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-11-07T04:24:44Z. Reason: GVLK.
Information	10/31/2018 9:55:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 9:55:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 9:55:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/10/31 04:25"
Information	10/31/2018 9:55:42 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/10/31 04:25, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/31/2018 9:50:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2018 9:50:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 9:50:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 9:50:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2018 9:42:42 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2018 9:37:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 9:37:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/31/2018 9:37:44 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 405

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 32

Error	10/31/2018 9:37:31 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/31/2018 9:37:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56658)(?)])(1 )(2 )]

"
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56658)(?)])(1 )(2 )]

"
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56658)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2018 9:37:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 9:37:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/31/2018 9:32:15 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 9:32:12 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 9:07:04 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/31/2018 9:01:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2018 8:56:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56698)(?)])(1 )(2 )]

"
Information	10/31/2018 8:56:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:56:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56698)(?)])(1 )(2 )]

"
Information	10/31/2018 8:56:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56698)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]

"
Information	10/31/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]

"
Information	10/31/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:55:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56699)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:55:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]

"
Information	10/31/2018 8:55:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:54:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]

"
Information	10/31/2018 8:54:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:54:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]

"
Information	10/31/2018 8:54:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56700)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56702)(?)])(1 )(2 )]

"
Information	10/31/2018 8:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56702)(?)])(1 )(2 )]

"
Information	10/31/2018 8:53:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56702)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	10/31/2018 8:52:15 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/31/2018 8:52:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56703)(?)])(1 )(2 )]

"
Information	10/31/2018 8:52:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:52:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56703)(?)])(1 )(2 )]

"
Information	10/31/2018 8:52:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56703)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:50:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e40ef8f7-dcbb-11e8-9b6a-204747d02364
Report Status: 0"
Information	10/31/2018 8:50:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]

"
Information	10/31/2018 8:50:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:50:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]

"
Information	10/31/2018 8:50:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:49:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]

"
Information	10/31/2018 8:49:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2018 8:49:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]

"
Information	10/31/2018 8:49:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2018 8:49:50 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2018 8:49:50 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2018 8:49:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/31/2018 8:42:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/31/2018 8:40:24 AM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Wednesday, September 26, 2018 3:44:15 AM.
Error	10/31/2018 8:40:14 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8100E <$DDNS$          > TCP/IP CONNECT REQUEST FAILED, ERROR(A socket operation was attempted to an unreachable host.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/31/2018 8:40:11 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 7:30:55 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	10/30/2018 6:13:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 6:12:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	10/30/2018 6:12:10 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 5:07:06 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	10/30/2018 3:36:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 3:10:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccf01723-dc27-11e8-9b6a-204747d02364
Report Status: 0"
Information	10/30/2018 2:26:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 2:26:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:38Z. Reason: GVLK.
Information	10/30/2018 2:21:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 2:21:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 2:21:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 2:21:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/30/2018 2:12:57 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 2:09:38 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 2:06:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/30/2018 2:06:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/30/2018 2:00:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 1:57:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 13, Deleted: 1, Modified: 0, Compared: 28437, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/30/2018 1:55:52 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	10/30/2018 1:55:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57840)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 1:55:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2018 1:55:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 1:55:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/30/2018 1:53:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/30/2018 1:51:27 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 1:51:24 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 1:51:20 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 12:43:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 12:43:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:02Z. Reason: GVLK.
Information	10/30/2018 12:38:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 12:38:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 12:38:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 12:37:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/30/2018 12:30:32 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 12:13:48 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 12:13:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 12:13:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:03Z. Reason: GVLK.
Information	10/30/2018 12:08:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 12:08:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 12:08:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 12:08:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 12:07:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9061.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	10/30/2018 12:05:51 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 12:04:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 12:04:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:12Z. Reason: GVLK.
Information	10/30/2018 12:00:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	10/30/2018 11:56:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/30/2018 11:55:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/30/2018 11:55:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/30/2018 11:55:00 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/30/2018 11:54:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57960)(?)])(1 )(2 )]

"
Information	10/30/2018 11:54:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 11:54:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57960)(?)])(1 )(2 )]

"
Information	10/30/2018 11:54:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57960)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 11:54:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2018 11:54:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 11:54:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 11:54:19 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/30/2018 11:54:17 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/30/2018 11:54:16 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/30/2018 11:54:14 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/30/2018 11:54:06 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	10/30/2018 11:54:06 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	10/30/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 11:53:51 AM	ESENT	302	Logging/Recovery	Windows (8604) Windows: The database engine has successfully completed recovery steps.
Error	10/30/2018 11:53:42 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 11:53:39 AM	ESENT	301	Logging/Recovery	Windows (8604) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/30/2018 11:53:38 AM	ESENT	300	Logging/Recovery	Windows (8604) Windows: The database engine is initiating recovery steps.
Information	10/30/2018 11:53:37 AM	ESENT	102	General	Windows (8604) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/30/2018 11:53:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/30/2018 11:52:53 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	10/30/2018 11:52:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/30/2018 11:52:43 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/30/2018 11:52:42 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/30/2018 11:52:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/30/2018 11:52:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/30/2018 11:52:31 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	10/30/2018 11:52:19 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/30/2018 11:52:18 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9060.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/30/2018 11:52:15 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/30/2018 11:52:02 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/30/2018 11:52:02 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/30/2018 11:52:02 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/30/2018 11:52:02 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/30/2018 11:52:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/30/2018 11:52:00 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/30/2018 11:52:00 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:52:00 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:52:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/30/2018 11:51:59 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/30/2018 11:51:58 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/30/2018 11:51:57 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/30/2018 11:51:49 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/30/2018 11:51:39 AM	PostgreSQL	0	None	"2018-10-30 11:51:39 IST LOG:  redirecting log output to logging collector process
2018-10-30 11:51:39 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/30/2018 11:51:38 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/30/2018 11:51:35 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/30/2018 11:50:56 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/30/2018 11:50:55 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/30/2018 11:50:55 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4588 at 10/29/2018 9:06:13 AM (local) 10/29/2018 3:36:13 AM (UTC). This is an informational message only; no user action is required.
Information	10/30/2018 11:50:55 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/30/2018 11:50:36 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/30/2018 11:50:35 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/30/2018 11:50:35 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/30/2018 11:50:35 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/30/2018 11:50:35 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4364.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/30/2018 11:50:23 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/30/2018 11:50:22 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/30/2018 11:48:28 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/30/2018 11:48:25 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/30/2018 11:48:06 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/30/2018 11:48:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/30/2018 11:48:06 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/30/2018 11:41:35 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/30/2018 11:41:34 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/30/2018 11:41:33 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/30/2018 11:41:33 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/30/2018 11:41:21 AM	PostgreSQL	0	None	"2018-10-30 11:41:21 IST LOG:  redirecting log output to logging collector process
2018-10-30 11:41:21 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/30/2018 11:41:19 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/30/2018 11:41:17 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/30/2018 11:41:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/30/2018 11:41:10 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/30/2018 11:41:10 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/30/2018 11:41:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/30/2018 11:41:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/30/2018 11:40:36 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/30/2018 11:40:36 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:40:36 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4588 at 10/29/2018 9:06:13 AM (local) 10/29/2018 3:36:13 AM (UTC). This is an informational message only; no user action is required.
Information	10/30/2018 11:40:35 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/30/2018 11:40:14 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/30/2018 11:40:14 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/30/2018 11:40:14 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/30/2018 11:40:14 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/30/2018 11:40:14 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4456.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/30/2018 11:40:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/30/2018 11:38:41 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/30/2018 11:38:16 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/30/2018 11:37:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/30/2018 11:37:42 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/30/2018 11:37:38 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/30/2018 11:35:13 AM	MTAService.OnSessionChange	0	None	11:35:13 AM - Session change notice received: SessionUnlock Session ID: 1
Error	10/30/2018 11:35:11 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 11:35:02 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 11:27:11 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 11:19:50 AM	MTAService.OnSessionChange	0	None	11:19:50 AM - Session change notice received: SessionLock Session ID: 1
Error	10/30/2018 11:12:42 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	10/30/2018 11:09:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 10:10:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e375fb6a-dbfd-11e8-b486-204747d02364
Report Status: 0"
Information	10/30/2018 9:50:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 9:45:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 9:45:18 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 15

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 32

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	10/30/2018 9:45:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58090)(?)])(1 )(2 )]

"
Information	10/30/2018 9:45:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 9:45:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58090)(?)])(1 )(2 )]

"
Information	10/30/2018 9:45:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58090)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 9:45:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2018 9:45:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 9:45:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 9:36:58 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	10/30/2018 9:32:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 9:32:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 9:32:01 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/30/2018 9:32:01 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 500

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 328

Information	10/30/2018 9:31:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 9:31:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58104)(?)])(1 )(2 )]

"
Information	10/30/2018 9:31:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 9:31:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58104)(?)])(1 )(2 )]

"
Information	10/30/2018 9:31:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58104)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 9:31:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2018 9:31:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 9:31:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/30/2018 9:25:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/30/2018 9:25:21 AM	Desktop Window Manager	9013	None	The Desktop Window Manager was unable to start because composition was disabled by a running application
Information	10/30/2018 9:25:21 AM	Desktop Window Manager	9010	None	A request to disable the Desktop Window Manager was made by process (WebEx)
Error	10/30/2018 9:25:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/30/2018 9:24:54 AM	MTAService.OnSessionChange	0	None	9:24:54 AM - Session change notice received: SessionUnlock Session ID: 1
Error	10/30/2018 9:24:17 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 9:24:03 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 9:24:00 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/30/2018 8:54:02 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/30/2018 8:53:59 AM	MTAService.OnSessionChange	0	None	8:53:59 AM - Session change notice received: SessionLock Session ID: 1
Information	10/30/2018 8:23:11 AM	MTAService.OnSessionChange	0	None	8:23:11 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/30/2018 7:38:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 6:43:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 6:43:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:16Z. Reason: GVLK.
Information	10/30/2018 6:38:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 6:38:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 6:38:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 6:38:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 6:16:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 6:16:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:46Z. Reason: GVLK.
Information	10/30/2018 6:13:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 6:13:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 6:11:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 6:11:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 6:11:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 6:11:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/30/2018 5:40:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 5:10:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f9aca584-dbd3-11e8-b486-204747d02364
Report Status: 0"
Information	10/30/2018 4:59:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 4:59:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:24Z. Reason: GVLK.
Information	10/30/2018 4:49:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 4:49:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 4:49:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 4:49:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 4:46:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 4:44:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2018 4:44:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:36Z. Reason: GVLK.
Error	10/30/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58394)(?)])(1 )(2 )]

"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58394)(?)])(1 )(2 )]

"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58394)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2018 4:41:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 4:41:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 4:39:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2018 4:39:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2018 4:39:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2018 4:39:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2018 4:05:37 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/30/2018 3:51:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 2:13:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 2:13:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2018 2:12:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/30/2018 1:56:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/30/2018 12:10:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0fc06845-dbaa-11e8-b486-204747d02364
Report Status: 0"
Warning	10/30/2018 12:07:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/29/2018 10:24:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 10:13:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 10:13:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 10:13:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/29/2018 10:12:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/29/2018 8:52:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 8:20:59 PM	MTAService.OnSessionChange	0	None	8:20:59 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 7:21:00 PM	MTAService.OnSessionChange	0	None	7:21:00 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/29/2018 7:20:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 7:10:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2579b88d-db80-11e8-b486-204747d02364
Report Status: 0"
Information	10/29/2018 7:05:08 PM	MTAService.OnSessionChange	0	None	7:05:08 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 6:13:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 6:12:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 6:12:24 PM	MTAService.OnSessionChange	0	None	6:12:24 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/29/2018 5:30:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 5:06:34 PM	MTAService.OnSessionChange	0	None	5:06:34 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 3:52:39 PM	MTAService.OnSessionChange	0	None	3:52:39 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/29/2018 3:46:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 3:34:40 PM	MTAService.OnSessionChange	0	None	3:34:40 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 3:02:19 PM	MTAService.OnSessionChange	0	None	3:02:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 3:00:22 PM	MTAService.OnSessionChange	0	None	3:00:22 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 2:29:26 PM	MTAService.OnSessionChange	0	None	2:29:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 2:25:46 PM	MTAService.OnSessionChange	0	None	2:25:46 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 2:13:45 PM	MTAService.OnSessionChange	0	None	2:13:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 2:13:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 2:12:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 2:10:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3bcc1f5e-db56-11e8-b486-204747d02364
Report Status: 0"
Warning	10/29/2018 1:59:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 1:43:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 1:43:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 1:30:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 1:29:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 1:27:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 1:27:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 1:23:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 1:23:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:20Z. Reason: GVLK.
Information	10/29/2018 1:18:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2018 1:18:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 1:18:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 1:18:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 1:00:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 1:00:28 PM	MTAService.OnSessionChange	0	None	1:00:28 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 12:59:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 12:55:06 PM	MTAService.OnSessionChange	0	None	12:55:06 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 12:46:24 PM	MTAService.OnSessionChange	0	None	12:46:24 PM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 12:44:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎29T07:11:55.729551200Z.
Error	10/29/2018 12:44:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/29/2018 12:41:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎29T07:11:55.729551200Z.
Information	10/29/2018 12:40:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 12:39:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎29T07:07:51.498130500Z.
Information	10/29/2018 12:39:58 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Node.js. Product Version: 8.12.0. Product Language: 1033. Manufacturer: Node.js Foundation. Installation success or error status: 0.
Information	10/29/2018 12:39:58 PM	MsiInstaller	11707	None	Product: Node.js -- Installation completed successfully.
Information	10/29/2018 12:39:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎29T07:08:11.850165500Z.
Information	10/29/2018 12:39:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎29T07:07:47.697750500Z.
Information	10/29/2018 12:39:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\Downloads\node-v8.12.0-x64.msi. Client Process Id: 15020.
Error	10/29/2018 12:39:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/29/2018 12:39:47 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the {793c9b44-3d6b-4f57-b5d7-4ff80adcf9a2} (NULL) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	10/29/2018 12:39:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 12:38:23 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the {793c9b44-3d6b-4f57-b5d7-4ff80adcf9a2} (NULL) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	10/29/2018 12:38:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎29T07:08:11.850165500Z.
Error	10/29/2018 12:37:55 PM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Node.js: Server-side JavaScript' could not be shut down.
Information	10/29/2018 12:37:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎29T07:07:51.498130500Z.
Information	10/29/2018 12:37:51 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	10/29/2018 12:37:51 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\nodejs\node.exe' (pid 14616) cannot be restarted - Application SID does not match Conductor SID..
Information	10/29/2018 12:37:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎29T07:07:47.697750500Z.
Information	10/29/2018 12:37:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\Downloads\node-v8.12.0-x64.msi. Client Process Id: 15020.
Information	10/29/2018 12:37:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 12:36:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 12:33:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 12:33:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 12:31:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 12:30:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/29/2018 12:26:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 11:53:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 11:53:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 11:47:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 11:47:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 11:44:40 AM	MTAService.OnSessionChange	0	None	11:44:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 11:42:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 11:41:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 11:40:11 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/29/2018 11:39:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 28380, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/29/2018 11:38:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/29/2018 11:38:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/29/2018 11:27:57 AM	MTAService.OnSessionChange	0	None	11:27:57 AM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 11:02:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 11:02:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/29/2018 10:59:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/29/2018 10:59:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/29/2018 10:43:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 10:26:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 10:26:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:52Z. Reason: GVLK.
Information	10/29/2018 10:21:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2018 10:21:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 10:21:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 10:21:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 10:17:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 10:13:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/29/2018 10:13:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/29/2018 10:13:01 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/29/2018 10:13:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/29/2018 10:13:00 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 452

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 93

Information	10/29/2018 10:12:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 10:12:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/29/2018 10:12:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2018 10:12:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59503)(?)])(1 )(2 )]

"
Information	10/29/2018 10:12:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/29/2018 10:12:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59503)(?)])(1 )(2 )]

"
Information	10/29/2018 10:12:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59503)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 10:01:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59514)(?)])(1 )(2 )]

"
Information	10/29/2018 10:01:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/29/2018 10:01:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59514)(?)])(1 )(2 )]

"
Information	10/29/2018 10:01:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59514)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 10:01:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/29/2018 10:01:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 10:01:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 9:56:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 9:56:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:52Z. Reason: GVLK.
Information	10/29/2018 9:51:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2018 9:51:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 9:51:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 9:51:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 9:47:48 AM	MTAService.OnSessionChange	0	None	9:47:48 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/29/2018 9:43:20 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9060.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/29/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:21Z. Reason: GVLK.
Information	10/29/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 9:21:12 AM	MTAService.OnSessionChange	0	None	9:21:12 AM - Session change notice received: SessionLock Session ID: 1
Information	10/29/2018 9:17:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2018 9:17:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:49Z. Reason: GVLK.
Information	10/29/2018 9:17:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/29/2018 9:12:29 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/29/2018 9:12:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59562)(?)])(1 )(2 )]

"
Information	10/29/2018 9:12:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/29/2018 9:12:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59562)(?)])(1 )(2 )]

"
Information	10/29/2018 9:12:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59562)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 9:11:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	10/29/2018 9:11:01 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/29/2018 9:10:34 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/29/2018 9:10:32 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/29/2018 9:10:27 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/29/2018 9:10:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 51b18d6c-db2c-11e8-b486-204747d02364
Report Status: 0"
Information	10/29/2018 9:09:56 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/29/2018 9:09:44 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9059.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	10/29/2018 9:09:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/29/2018 9:09:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2018 9:09:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 9:09:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2018 9:09:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59566)(?)])(1 )(2 )]

"
Information	10/29/2018 9:09:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/29/2018 9:09:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59566)(?)])(1 )(2 )]

"
Information	10/29/2018 9:09:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59566)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2018 9:09:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/29/2018 9:09:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	10/29/2018 9:09:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/29/2018 9:09:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 9:09:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2018 9:08:51 AM	ESENT	302	Logging/Recovery	Windows (8092) Windows: The database engine has successfully completed recovery steps.
Information	10/29/2018 9:08:43 AM	ESENT	301	Logging/Recovery	Windows (8092) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/29/2018 9:08:43 AM	ESENT	300	Logging/Recovery	Windows (8092) Windows: The database engine is initiating recovery steps.
Information	10/29/2018 9:08:41 AM	ESENT	102	General	Windows (8092) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/29/2018 9:08:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: McShield
P2: mcshield.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1dbcfa2f-db2c-11e8-b486-204747d02364
Report Status: 0"
Information	10/29/2018 9:07:39 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	10/29/2018 9:07:39 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	10/29/2018 9:06:46 AM	Service1	0	None	Service started successfully.
Error	10/29/2018 9:06:41 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/29/2018 9:06:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/29/2018 9:06:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/29/2018 9:06:35 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/29/2018 9:06:35 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/29/2018 9:06:35 AM	MTAService.OnSessionChange	0	None	9:06:35 AM - Logon : 212558710
Information	10/29/2018 9:06:35 AM	MTAService.OnSessionChange	0	None	9:06:35 AM - Session change notice received: SessionLogon Session ID: 1
Information	10/29/2018 9:06:34 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/29/2018 9:06:34 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/29/2018 9:06:27 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/29/2018 9:06:26 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/29/2018 9:06:25 AM	PostgreSQL	0	None	"2018-10-29 09:06:25 IST LOG:  redirecting log output to logging collector process
2018-10-29 09:06:25 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/29/2018 9:06:23 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:22 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/29/2018 9:06:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/29/2018 9:06:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/29/2018 9:06:22 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/29/2018 9:06:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/29/2018 9:06:21 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/29/2018 9:06:21 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:20 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/29/2018 9:06:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/29/2018 9:06:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/29/2018 9:06:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/29/2018 9:06:18 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4896 at 10/28/2018 9:23:26 PM (local) 10/28/2018 3:53:26 PM (UTC). This is an informational message only; no user action is required.
Information	10/29/2018 9:06:13 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/29/2018 9:06:12 AM	MTAService	0	None	Service started successfully.
Information	10/29/2018 9:06:12 AM	MTAService.OnStart	0	None	9:06:12 AM - Waiting for user to Logon
Information	10/29/2018 9:06:07 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/29/2018 9:06:06 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/29/2018 9:06:06 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/29/2018 9:06:06 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/29/2018 9:06:06 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4588.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/29/2018 9:05:47 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/29/2018 9:05:46 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/29/2018 9:02:19 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/29/2018 9:01:45 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/29/2018 9:01:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/29/2018 9:01:45 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/28/2018 9:23:37 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/28/2018 9:23:26 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	10/28/2018 9:23:16 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Warning	10/28/2018 9:23:13 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 984 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1284 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1284 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2104 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/28/2018 9:23:13 PM	MTAService.OnSessionChange	0	None	9:23:13 PM - Logoff
Information	10/28/2018 9:23:13 PM	MTAService.OnSessionChange	0	None	9:23:13 PM - Session change notice received: SessionLogoff Session ID: 1
Information	10/28/2018 9:23:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/28/2018 9:23:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/28/2018 9:23:12 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/28/2018 9:23:03 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	10/28/2018 9:22:58 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/28/2018 9:19:38 PM	MTAService.OnSessionChange	0	None	9:19:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/28/2018 5:33:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 80b4bd03-daa9-11e8-b5ef-08002700381d
Report Status: 0"
Error	10/28/2018 4:52:51 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:52:38 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:37:11 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:36:58 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:34:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:34:21 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:21:52 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:21:39 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:17:26 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 4:17:12 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/28/2018 4:11:06 PM	MTAService.OnSessionChange	0	None	4:11:06 PM - Session change notice received: SessionLock Session ID: 1
Information	10/28/2018 4:07:51 PM	MTAService.OnSessionChange	0	None	4:07:51 PM - Session change notice received: SessionUnlock Session ID: 1
Error	10/28/2018 3:47:13 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/28/2018 3:47:02 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Error	10/28/2018 3:46:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/28/2018 3:07:32 PM	MTAService.OnSessionChange	0	None	3:07:32 PM - Session change notice received: SessionLock Session ID: 1
Error	10/28/2018 2:38:41 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 2:38:27 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 2:08:13 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 2:07:59 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 1:53:19 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 1:53:05 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 1:20:57 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 1:20:42 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/28/2018 12:51:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9059.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/28/2018 12:39:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2018 12:39:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:03Z. Reason: GVLK.
Information	10/28/2018 12:38:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/28/2018 12:33:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2018 12:33:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2018 12:33:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2018 12:33:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/28/2018 12:33:21 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/28/2018 12:33:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60802)(?)])(1 )(2 )]

"
Information	10/28/2018 12:33:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/28/2018 12:33:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60802)(?)])(1 )(2 )]

"
Information	10/28/2018 12:33:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60802)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2018 12:33:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/28/2018 12:33:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2018 12:33:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/28/2018 12:33:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8386325c-da7f-11e8-b5ef-08002700381d
Report Status: 0"
Information	10/28/2018 12:22:39 PM	MTAService.OnSessionChange	0	None	12:22:39 PM - Session change notice received: SessionUnlock Session ID: 1
Error	10/28/2018 12:22:34 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 12:22:28 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 12:22:23 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/28/2018 12:22:19 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 11:41:05 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 11:41:02 PM	MTAService.OnSessionChange	0	None	11:41:02 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 10:55:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 10:50:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a17cbfc3-da0c-11e8-b5ef-08002700381d
Report Status: 0"
Information	10/27/2018 10:50:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61624)(?)])(1 )(2 )]

"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61624)(?)])(1 )(2 )]

"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61624)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 10:50:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 10:23:26 PM	MTAService.OnSessionChange	0	None	10:23:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/27/2018 10:02:06 PM	MTAService.OnSessionChange	0	None	10:02:06 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 9:56:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 9:56:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:10Z. Reason: GVLK.
Information	10/27/2018 9:51:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2018 9:51:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 9:51:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 9:51:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 9:41:10 PM	MTAService.OnSessionChange	0	None	9:41:10 PM - Session change notice received: SessionUnlock Session ID: 1
Error	10/27/2018 9:41:00 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 9:40:56 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 9:40:52 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 9:18:22 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 6:50:35 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/27/2018 5:50:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a52a7844-d9e2-11e8-b5ef-08002700381d
Report Status: 0"
Information	10/27/2018 5:22:56 PM	MTAService.OnSessionChange	0	None	5:22:56 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 5:07:11 PM	MTAService.OnSessionChange	0	None	5:07:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/27/2018 4:59:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9058.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/27/2018 4:42:55 PM	MTAService.OnSessionChange	0	None	4:42:55 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 3:33:40 PM	MTAService.OnSessionChange	0	None	3:33:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/27/2018 3:16:11 PM	MTAService.OnSessionChange	0	None	3:16:11 PM - Session change notice received: SessionLock Session ID: 1
Error	10/27/2018 3:12:40 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 3:12:37 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 3:12:29 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 2:27:53 PM	MTAService.OnSessionChange	0	None	2:27:53 PM - Session change notice received: SessionUnlock Session ID: 1
Error	10/27/2018 2:27:52 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 2:27:45 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 2:27:42 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 2:06:22 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 2:04:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 2:04:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:45Z. Reason: GVLK.
Information	10/27/2018 2:01:14 PM	MTAService.OnSessionChange	0	None	2:01:14 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 1:59:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2018 1:59:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 1:59:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 1:59:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/27/2018 1:36:40 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 1:36:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 1:36:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:31Z. Reason: GVLK.
Error	10/27/2018 1:35:55 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 1:35:54 PM	MTAService.OnSessionChange	0	None	1:35:54 PM - Session change notice received: SessionUnlock Session ID: 1
Error	10/27/2018 1:35:47 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 1:35:44 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/27/2018 1:33:54 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 1:29:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2018 1:29:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 1:29:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 1:29:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 1:13:47 PM	MTAService.OnSessionChange	0	None	1:13:47 PM - Session change notice received: SessionLock Session ID: 1
Information	10/27/2018 1:05:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 1:04:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 1:04:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:45Z. Reason: GVLK.
Error	10/27/2018 1:00:51 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/27/2018 1:00:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62214)(?)])(1 )(2 )]

"
Information	10/27/2018 1:00:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/27/2018 1:00:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62214)(?)])(1 )(2 )]

"
Information	10/27/2018 1:00:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62214)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 1:00:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/27/2018 1:00:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 1:00:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 12:59:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2018 12:59:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 12:59:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 12:59:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 12:54:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 12:54:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:31Z. Reason: GVLK.
Information	10/27/2018 12:52:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/27/2018 12:48:43 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	10/27/2018 12:47:35 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {F18DB805-3F92-42CA-B277-1A3CA188BFD0}
Error	10/27/2018 12:47:35 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {F18DB805-3F92-42CA-B277-1A3CA188BFD0}
Error	10/27/2018 12:47:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/27/2018 12:47:29 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/27/2018 12:47:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2018 12:47:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 12:47:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 12:47:27 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/27/2018 12:47:26 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/27/2018 12:47:25 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/27/2018 12:47:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62228)(?)])(1 )(2 )]

"
Information	10/27/2018 12:47:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/27/2018 12:47:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62228)(?)])(1 )(2 )]

"
Information	10/27/2018 12:47:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62228)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2018 12:47:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/27/2018 12:47:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2018 12:47:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/27/2018 12:47:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/27/2018 12:47:12 PM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$SNMP$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/27/2018 12:46:57 PM	ESENT	302	Logging/Recovery	Windows (8856) Windows: The database engine has successfully completed recovery steps.
Information	10/27/2018 12:46:48 PM	ESENT	301	Logging/Recovery	Windows (8856) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/27/2018 12:46:48 PM	ESENT	300	Logging/Recovery	Windows (8856) Windows: The database engine is initiating recovery steps.
Information	10/27/2018 12:46:48 PM	ESENT	102	General	Windows (8856) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/27/2018 12:46:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9057.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	10/27/2018 12:46:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	10/27/2018 12:46:29 PM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Error	10/27/2018 12:44:58 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/27/2018 12:44:57 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/27/2018 12:44:55 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Error	10/27/2018 12:44:39 PM	Service1	0	None	"Service cannot be started. System.Runtime.InteropServices.COMException (0x80010002): Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementScope.InitializeGuts(Object o)
   at System.Management.ManagementScope.Initialize()
   at System.Management.ManagementObjectSearcher.Initialize()
   at System.Management.ManagementObjectSearcher.Get()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)"
Information	10/27/2018 12:44:30 PM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	10/27/2018 12:44:30 PM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Information	10/27/2018 12:44:30 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/27/2018 12:44:26 PM	PostgreSQL	0	None	"2018-10-27 12:44:26 IST LOG:  redirecting log output to logging collector process
2018-10-27 12:44:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/27/2018 12:44:09 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/27/2018 12:43:50 PM	MTAService	0	None	Service started successfully.
Information	10/27/2018 12:43:29 PM	MTAService.OnStart	0	None	12:43:29 PM - User is already logged in : 212558710
Information	10/27/2018 12:43:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/27/2018 12:43:29 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/27/2018 12:43:29 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/27/2018 12:43:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/27/2018 12:43:27 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/27/2018 12:43:26 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/27/2018 12:43:25 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/27/2018 12:43:23 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4992 at 10/26/2018 3:37:50 PM (local) 10/26/2018 10:07:50 AM (UTC). This is an informational message only; no user action is required.
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/27/2018 12:43:21 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/27/2018 12:43:20 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/27/2018 12:43:20 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/27/2018 12:43:20 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/27/2018 12:43:20 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/27/2018 12:43:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/27/2018 12:43:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4896.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/27/2018 12:43:08 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/27/2018 12:42:32 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/27/2018 12:42:11 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/27/2018 12:41:40 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/27/2018 12:41:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/27/2018 12:41:40 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/26/2018 3:38:03 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/26/2018 3:37:50 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/26/2018 3:37:47 PM	McLogEvent	257	None	The scan of C:\Windows\System32\en-US\tzres.dll.mui has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9057.0000.
Warning	10/26/2018 3:37:45 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Warning	10/26/2018 3:37:44 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 49 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 528 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 5212 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows NT\CurrentVersion
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 5604 (\Device\HarddiskVolume1\Program Files (x86)\Knoa\KnoaAgent\tKnoa.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 5212 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2220 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/26/2018 3:37:44 PM	MTAService.OnSessionChange	0	None	3:37:44 PM - Logoff
Information	10/26/2018 3:37:44 PM	MTAService.OnSessionChange	0	None	3:37:44 PM - Session change notice received: SessionLogoff Session ID: 1
Information	10/26/2018 3:37:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/26/2018 3:37:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/26/2018 3:37:43 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/26/2018 3:37:39 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	10/26/2018 3:37:27 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	10/26/2018 3:20:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/26/2018 3:13:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cabcf15-d903-11e8-afa4-204747d02364
Report Status: 0"
Information	10/26/2018 2:20:05 PM	MTAService.OnSessionChange	0	None	2:20:05 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/26/2018 2:19:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/26/2018 2:19:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/26/2018 2:03:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2018 2:03:55 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/26/2018 2:03:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2018 2:03:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2018 1:52:31 PM	MTAService.OnSessionChange	0	None	1:52:31 PM - Session change notice received: SessionLock Session ID: 1
Information	10/26/2018 1:49:23 PM	MTAService.OnSessionChange	0	None	1:49:23 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/26/2018 1:32:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/26/2018 1:20:44 PM	MTAService.OnSessionChange	0	None	1:20:44 PM - Session change notice received: SessionLock Session ID: 1
Information	10/26/2018 1:19:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/26/2018 1:19:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/26/2018 12:47:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/26/2018 12:47:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/26/2018 12:35:11 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9057.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/26/2018 12:07:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/26/2018 12:07:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/26/2018 12:04:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/26/2018 12:04:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/26/2018 11:53:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2018 11:53:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:04Z. Reason: GVLK.
Information	10/26/2018 11:48:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2018 11:48:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2018 11:48:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2018 11:48:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/26/2018 11:44:34 AM	MTAService.OnSessionChange	0	None	11:44:34 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/26/2018 11:37:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/26/2018 11:29:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2018 11:29:27 AM	MTAService.OnSessionChange	0	None	11:29:27 AM - Session change notice received: SessionLock Session ID: 1
Information	10/26/2018 10:59:38 AM	MTAService.OnSessionChange	0	None	10:59:38 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/26/2018 10:58:42 AM	MTAService.OnSessionChange	0	None	10:58:42 AM - Session change notice received: SessionLock Session ID: 1
Information	10/26/2018 10:46:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/26/2018 10:45:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 28377, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/26/2018 10:43:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/26/2018 10:43:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/26/2018 10:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63809)(?)])(1 )(2 )]

"
Information	10/26/2018 10:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/26/2018 10:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63809)(?)])(1 )(2 )]

"
Information	10/26/2018 10:25:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63809)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2018 10:19:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2018 10:19:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:57Z. Reason: GVLK.
Information	10/26/2018 10:14:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2018 10:14:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2018 10:14:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2018 10:14:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/26/2018 10:13:57 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/26/2018 10:13:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63821)(?)])(1 )(2 )]

"
Information	10/26/2018 10:13:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/26/2018 10:13:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63821)(?)])(1 )(2 )]

"
Information	10/26/2018 10:13:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63821)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2018 10:13:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b2dee94e-d8d9-11e8-afa4-204747d02364
Report Status: 0"
Information	10/26/2018 10:11:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2018 10:11:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:51Z. Reason: GVLK.
Information	10/26/2018 10:08:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/26/2018 10:06:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2018 10:06:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2018 10:06:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2018 10:06:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/26/2018 10:05:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/26/2018 10:04:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/26/2018 10:04:28 AM	MTAService.OnSessionChange	0	None	10:04:28 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/26/2018 10:04:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/26/2018 10:03:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/25/2018 7:57:07 PM	MTAService.OnSessionChange	0	None	7:57:07 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 7:56:07 PM	MTAService.OnSessionChange	0	None	7:56:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 7:53:16 PM	MTAService.OnSessionChange	0	None	7:53:16 PM - Session change notice received: SessionLock Session ID: 1
Warning	10/25/2018 7:22:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 6:54:24 PM	MTAService.OnSessionChange	0	None	6:54:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 6:31:41 PM	MTAService.OnSessionChange	0	None	6:31:41 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 6:04:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64790)(?)])(1 )(2 )]

"
Information	10/25/2018 6:04:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/25/2018 6:04:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64790)(?)])(1 )(2 )]

"
Information	10/25/2018 6:04:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64790)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 5:57:35 PM	MTAService.OnSessionChange	0	None	5:57:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 5:43:39 PM	MTAService.OnSessionChange	0	None	5:43:39 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 5:26:02 PM	MTAService.OnSessionChange	0	None	5:26:02 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/25/2018 5:25:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 4:47:09 PM	MTAService.OnSessionChange	0	None	4:47:09 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 4:10:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 4:10:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 4:10:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 4:05:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc9fab9b-d841-11e8-afa4-204747d02364
Report Status: 0"
Information	10/25/2018 3:37:26 PM	MTAService.OnSessionChange	0	None	3:37:26 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/25/2018 3:28:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 3:25:46 PM	MTAService.OnSessionChange	0	None	3:25:46 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 2:40:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 2:40:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 2:14:40 PM	MTAService.OnSessionChange	0	None	2:14:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 2:09:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 2:09:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 2:06:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 2:06:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 2:05:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/25/2018 1:47:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 1:45:08 PM	MTAService.OnSessionChange	0	None	1:45:08 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 1:39:15 PM	MTAService.OnSessionChange	0	None	1:39:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 1:31:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 1:30:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 1:19:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 1:19:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 1:10:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 1:10:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 1:09:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:56:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:55:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:47:45 PM	MTAService.OnSessionChange	0	None	12:47:45 PM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 12:45:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:44:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:42:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:40:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:40:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:39:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:35:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:35:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:33:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:32:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 12:14:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 12:13:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/25/2018 12:12:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 12:10:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 12:10:19 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/25/2018 12:10:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 12:10:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 12:08:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9056.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/25/2018 11:35:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 11:35:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 11:12:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 11:12:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 11:10:16 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 11:09:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/25/2018 11:05:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2c92fb1-d817-11e8-afa4-204747d02364
Report Status: 0"
Information	10/25/2018 10:57:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/25/2018 10:56:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/25/2018 10:15:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 9:44:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65290)(?)])(1 )(2 )]

"
Information	10/25/2018 9:44:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/25/2018 9:44:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65290)(?)])(1 )(2 )]

"
Information	10/25/2018 9:44:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65290)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 9:44:01 AM	MTAService.OnSessionChange	0	None	9:44:01 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 9:12:29 AM	MTAService.OnSessionChange	0	None	9:12:29 AM - Session change notice received: SessionLock Session ID: 1
Information	10/25/2018 9:07:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/25/2018 9:07:35 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/25/2018 9:03:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/25/2018 8:49:49 AM	MTAService.OnSessionChange	0	None	8:49:49 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/25/2018 8:42:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/25/2018 8:42:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:39Z. Reason: GVLK.
Information	10/25/2018 8:37:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/25/2018 8:37:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 8:37:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2018 8:37:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/25/2018 8:36:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 8:30:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/25/2018 8:30:26 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/25/2018 8:10:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 8:09:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 8:09:53 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/25/2018 8:09:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/25/2018 6:44:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 6:05:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e90f6ae0-d7ed-11e8-afa4-204747d02364
Report Status: 0"
Information	10/25/2018 5:20:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/25/2018 5:20:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:19Z. Reason: GVLK.
Information	10/25/2018 5:15:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/25/2018 5:15:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 5:15:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2018 5:15:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/25/2018 5:08:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/25/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/25/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65594)(?)])(1 )(2 )]

"
Information	10/25/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/25/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65594)(?)])(1 )(2 )]

"
Information	10/25/2018 4:41:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65594)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 4:10:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 4:09:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 3:36:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/25/2018 3:36:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:12Z. Reason: GVLK.
Warning	10/25/2018 3:31:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 3:28:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/25/2018 3:28:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2018 3:28:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2018 3:28:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/25/2018 2:48:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/25/2018 2:46:14 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	10/25/2018 1:34:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/25/2018 1:05:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff43138c-d7c3-11e8-afa4-204747d02364
Report Status: 0"
Information	10/25/2018 12:09:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 12:09:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/24/2018 11:46:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/24/2018 10:13:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 9:00:16 PM	MTAService.OnSessionChange	0	None	9:00:16 PM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 8:41:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66073)(?)])(1 )(2 )]

"
Information	10/24/2018 8:41:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 8:41:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66073)(?)])(1 )(2 )]

"
Information	10/24/2018 8:41:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66073)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	10/24/2018 8:35:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 8:09:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 8:09:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/24/2018 8:09:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 8:05:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1589b14b-d79a-11e8-afa4-204747d02364
Report Status: 0"
Warning	10/24/2018 6:36:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 6:00:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 6:00:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:13Z. Reason: GVLK.
Information	10/24/2018 5:55:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 5:55:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 5:55:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 5:55:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2018 5:52:52 PM	MTAService.OnSessionChange	0	None	5:52:52 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/24/2018 5:04:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 4:56:00 PM	MTAService.OnSessionChange	0	None	4:56:00 PM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 4:21:09 PM	GE Software	0	(1)	++Installation complete
Information	10/24/2018 4:21:09 PM	GE Software	0	(1)	++Installation complete with an exit code of: 1073742081
Information	10/24/2018 4:20:32 PM	Desktop Window Manager	9002	None	The Desktop Window Manager was unable to start
Information	10/24/2018 4:20:30 PM	Desktop Window Manager	9007	None	The Desktop Window Manager was unable to start because WDDM is not in use
Information	10/24/2018 4:20:27 PM	Desktop Window Manager	9002	None	The Desktop Window Manager was unable to start
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++Started the installation of Dell Intel HD Graphics 4000 and 5000 series Driver 10.18.14.4889-A18 V01 with the following commandline: /Q
Information	10/24/2018 4:18:36 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/24/2018 4:18:30 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/24/2018 4:09:47 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 141

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 140

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 218

Information	10/24/2018 4:09:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 4:08:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66346)(?)])(1 )(2 )]

"
Information	10/24/2018 4:08:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 4:08:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66346)(?)])(1 )(2 )]

"
Information	10/24/2018 4:08:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66346)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 4:03:44 PM	MTAService.OnSessionChange	0	None	4:03:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 3:58:16 PM	MTAService.OnSessionChange	0	None	3:58:16 PM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 3:46:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 3:46:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:02Z. Reason: GVLK.
Information	10/24/2018 3:41:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 3:41:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 3:41:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 3:40:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/24/2018 3:33:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 3:25:13 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 6723 milliseconds
Information	10/24/2018 3:20:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 3:20:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:20:43Z. Reason: GVLK.
Information	10/24/2018 3:15:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 3:15:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 3:15:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 3:15:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2018 3:05:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2b805481-d770-11e8-afa4-204747d02364
Report Status: 0"
Information	10/24/2018 2:45:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66430)(?)])(1 )(2 )]

"
Information	10/24/2018 2:45:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 2:45:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66430)(?)])(1 )(2 )]

"
Information	10/24/2018 2:45:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66430)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 2:35:31 PM	MTAService.OnSessionChange	0	None	2:35:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 1:59:53 PM	MTAService.OnSessionChange	0	None	1:59:53 PM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 1:58:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:58:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 1:53:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:53:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/24/2018 1:51:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 1:48:32 PM	MTAService.OnSessionChange	0	None	1:48:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 1:48:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 1:48:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 1:17:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:17:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 1:15:11 PM	MTAService.OnSessionChange	0	None	1:15:11 PM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 1:11:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:10:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 1:07:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:07:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 1:02:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 1:02:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 1:00:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:59:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 12:57:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:56:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 12:55:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9055.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/24/2018 12:54:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66540)(?)])(1 )(2 )]

"
Information	10/24/2018 12:54:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 12:54:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66540)(?)])(1 )(2 )]

"
Information	10/24/2018 12:54:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66540)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 12:54:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:53:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 12:15:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:15:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 12:11:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:10:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 12:07:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 12:07:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/24/2018 12:07:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 12:00:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 11:59:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 11:48:29 AM	MTAService.OnSessionChange	0	None	11:48:29 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 11:30:56 AM	MTAService.OnSessionChange	0	None	11:30:56 AM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 11:29:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 11:29:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 11:26:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 11:25:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 11:23:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 11:23:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 10:51:40 AM	MTAService.OnSessionChange	0	None	10:51:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 10:40:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2018 10:40:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2018 10:35:06 AM	MTAService.OnSessionChange	0	None	10:35:06 AM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 10:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎24T04:55:32.143682900Z.
Information	10/24/2018 10:25:32 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎24T04:55:32.143682900Z.
Information	10/24/2018 10:15:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66700)(?)])(1 )(2 )]

"
Information	10/24/2018 10:15:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 10:15:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66700)(?)])(1 )(2 )]

"
Information	10/24/2018 10:15:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66700)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	10/24/2018 10:07:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 10:05:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 41b692ad-d746-11e8-afa4-204747d02364
Report Status: 0"
Information	10/24/2018 9:56:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 9:56:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-31T04:19:59Z. Reason: GVLK.
Information	10/24/2018 9:54:56 AM	MTAService.OnSessionChange	0	None	9:54:56 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/24/2018 9:50:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 9:50:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 9:50:58 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/10/24 04:20"
Information	10/24/2018 9:50:57 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/10/24 04:20, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/24/2018 9:48:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 9:48:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/24/2018 9:48:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 9:45:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 9:45:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 9:45:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 9:45:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2018 9:15:29 AM	MTAService.OnSessionChange	0	None	9:15:29 AM - Session change notice received: SessionLock Session ID: 1
Information	10/24/2018 9:09:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/24/2018 9:09:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/24/2018 9:09:25 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/24/2018 9:09:01 AM	MTAService.OnSessionChange	0	None	9:09:01 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/24/2018 8:28:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/24/2018 6:37:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 5:48:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 5:47:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 5:23:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 5:23:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:54Z. Reason: GVLK.
Information	10/24/2018 5:16:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 5:16:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 5:16:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 5:16:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2018 5:06:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 5:06:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:38Z. Reason: GVLK.
Information	10/24/2018 5:05:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57faa49d-d71c-11e8-afa4-204747d02364
Report Status: 0"
Information	10/24/2018 5:01:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 5:01:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 5:01:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 5:01:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2018 4:58:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2018 4:58:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:16Z. Reason: GVLK.
Information	10/24/2018 4:53:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2018 4:53:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2018 4:53:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2018 4:53:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/24/2018 4:41:18 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/24/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67034)(?)])(1 )(2 )]

"
Information	10/24/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67034)(?)])(1 )(2 )]

"
Information	10/24/2018 4:41:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67034)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	10/24/2018 4:38:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/24/2018 3:07:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 2:20:57 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/24/2018 2:18:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/24/2018 1:48:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2018 1:47:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/24/2018 1:07:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/24/2018 12:05:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6e598a63-d6f2-11e8-afa4-204747d02364
Report Status: 0"
Information	10/24/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/23/2018 11:15:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 9:48:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/23/2018 9:48:06 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/23/2018 9:47:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/23/2018 9:28:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/23/2018 7:47:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 7:05:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 848e24f1-d6c8-11e8-afa4-204747d02364
Report Status: 0"
Information	10/23/2018 7:03:36 PM	MTAService.OnSessionChange	0	None	7:03:36 PM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 6:37:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67637)(?)])(1 )(2 )]

"
Information	10/23/2018 6:37:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 6:37:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67637)(?)])(1 )(2 )]

"
Information	10/23/2018 6:37:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67637)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 6:36:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67639)(?)])(1 )(2 )]

"
Information	10/23/2018 6:36:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 6:36:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67639)(?)])(1 )(2 )]

"
Information	10/23/2018 6:36:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67639)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 6:24:31 PM	MTAService.OnSessionChange	0	None	6:24:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/23/2018 6:22:00 PM	MTAService.OnSessionChange	0	None	6:22:00 PM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 6:11:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 6:11:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67663)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67663)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:28 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/23/2018 6:11:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67663)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:27 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/23/2018 6:11:27 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110863  Grace type=8.
Information	10/23/2018 6:11:26 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=b3856e77-aa96-4697-b27a-b5ecd4a19361"
Information	10/23/2018 6:11:26 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=812092ff-69d4-40e2-bf8e-c74b23ab5ba9"
Information	10/23/2018 6:11:26 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/23/2018 6:11:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21583)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 6:11:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21583)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21583)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 6:11:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/23/2018 6:11:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 6:11:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 6:05:39 PM	MTAService.OnSessionChange	0	None	6:05:39 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/23/2018 6:04:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 5:52:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 5:52:23 PM	MTAService.OnSessionChange	0	None	5:52:23 PM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 5:47:58 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 546

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 437

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 593

Information	10/23/2018 5:47:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/23/2018 5:47:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21607)(?)])(1 )(2 )]

"
Information	10/23/2018 5:47:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 5:47:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21607)(?)])(1 )(2 )]

"
Information	10/23/2018 5:47:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21607)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 5:47:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/23/2018 5:47:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 5:47:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 5:47:12 PM	MTAService.OnSessionChange	0	None	5:47:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/23/2018 5:46:18 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/23/2018 5:06:47 PM	MTAService.OnSessionChange	0	None	5:06:47 PM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 4:30:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎23T11:00:26.919623000Z.
Information	10/23/2018 4:30:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎23T11:00:26.919623000Z.
Information	10/23/2018 4:30:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎23T11:00:12.534500600Z.
Information	10/23/2018 4:30:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎23T11:00:12.534500600Z.
Information	10/23/2018 4:26:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 4:21:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21693)(?)])(1 )(2 )]

"
Information	10/23/2018 4:21:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 4:21:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21693)(?)])(1 )(2 )]

"
Information	10/23/2018 4:21:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 21693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 4:21:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/23/2018 4:21:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 4:21:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/23/2018 4:05:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 2:19:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 2:19:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 2:17:41 PM	MTAService.OnSessionChange	0	None	2:17:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/23/2018 2:16:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 2:15:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/23/2018 2:14:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 2:05:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ac0b04d-d69e-11e8-afa4-204747d02364
Report Status: 0"
Information	10/23/2018 1:58:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:57:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 1:33:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:33:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 1:32:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/23/2018 1:28:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:28:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 1:21:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:20:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 1:18:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:17:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 1:16:39 PM	MTAService.OnSessionChange	0	None	1:16:39 PM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 1:09:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 1:09:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 12:51:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9054.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/23/2018 12:48:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 12:47:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/23/2018 12:39:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 12:32:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 12:32:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 12:19:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 12:19:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 12:03:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 12:03:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 11:55:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 11:54:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 11:54:00 AM	MTAService.OnSessionChange	0	None	11:54:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/23/2018 11:33:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 11:32:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/23/2018 11:32:00 AM	MTAService.OnSessionChange	0	None	11:32:00 AM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 11:19:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/23/2018 11:18:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/23/2018 10:56:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 10:18:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 10:18:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/23/2018 10:13:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 10:13:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 10:13:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 10:13:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:48:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:48:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/23/2018 9:43:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 9:43:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:43:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:43:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:37:05 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:32:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/23/2018 9:32:05 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 46

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	10/23/2018 9:31:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22103)(?)])(1 )(2 )]

"
Information	10/23/2018 9:31:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 9:31:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22103)(?)])(1 )(2 )]

"
Information	10/23/2018 9:31:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22103)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:31:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/23/2018 9:31:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:31:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:30:49 AM	MTAService.OnSessionChange	0	None	9:30:49 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/23/2018 9:25:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:25:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:54Z. Reason: GVLK.
Information	10/23/2018 9:20:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 9:20:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:20:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:20:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:18:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:18:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/23/2018 9:13:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 9:13:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:13:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:13:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:13:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:13:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:41Z. Reason: GVLK.
Information	10/23/2018 9:13:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 9:12:50 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 43, Deleted: 0, Modified: 2, Compared: 28202, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/23/2018 9:09:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/23/2018 9:08:25 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 655

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1139

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 374

Information	10/23/2018 9:08:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/23/2018 9:08:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/23/2018 9:07:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/23/2018 9:06:54 AM	MTAService.OnSessionChange	0	None	9:06:54 AM - Session change notice received: SessionLock Session ID: 1
Information	10/23/2018 9:06:37 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	10/23/2018 9:06:36 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	10/23/2018 9:06:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c17205e2-d674-11e8-afa4-204747d02364
Report Status: 0"
Information	10/23/2018 9:05:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22129)(?)])(1 )(2 )]

"
Information	10/23/2018 9:05:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 9:05:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22129)(?)])(1 )(2 )]

"
Information	10/23/2018 9:05:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22129)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:04:30 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/23/2018 9:04:26 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	10/23/2018 9:03:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C3B700C0-09E4-4AA5-9D6B-3CF1E1FC121D}
Error	10/23/2018 9:03:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C3B700C0-09E4-4AA5-9D6B-3CF1E1FC121D}
Information	10/23/2018 9:03:05 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 9:03:02 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 9:03:01 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 9:02:58 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/23/2018 9:02:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	10/23/2018 9:02:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/23/2018 9:02:42 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8318E <$MAIN$  > SERVICE CONTROL FUNCTION StartService FAILED RC(0) The service did not respond to the start or control request in a timely fashion.  
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181023_085728.log
"
Error	10/23/2018 9:02:40 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8055E <$MAIN$          > SPOOL INITIALIZATION FAILED

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/23/2018 9:02:40 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8057E <$MAIN$          > SPOOL INDEX FILE IS CORRUPT

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/23/2018 9:02:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 9:02:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:02:39 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	10/23/2018 9:02:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22132)(?)])(1 )(2 )]

"
Information	10/23/2018 9:02:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/23/2018 9:02:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:02:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22132)(?)])(1 )(2 )]

"
Information	10/23/2018 9:02:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:02:32 AM	ESENT	302	Logging/Recovery	Windows (8552) Windows: The database engine has successfully completed recovery steps.
Information	10/23/2018 9:02:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22132)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 9:02:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/23/2018 9:02:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 9:02:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 9:02:27 AM	ESENT	301	Logging/Recovery	Windows (8552) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/23/2018 9:02:27 AM	ESENT	300	Logging/Recovery	Windows (8552) Windows: The database engine is initiating recovery steps.
Information	10/23/2018 9:02:27 AM	ESENT	102	General	Windows (8552) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/23/2018 9:02:22 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9053.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	10/23/2018 9:00:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/23/2018 9:00:27 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/23/2018 9:00:25 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/23/2018 9:00:22 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/23/2018 9:00:19 AM	LRS MFPSecure Tray App	1	None	System Check startup with errorCode - 1
Error	10/23/2018 9:00:19 AM	LRS MFPSecure Tray App	1	None	System Check Error - 1 - Retrieving the COM class factory for component with CLSID {06327536-F5F0-4925-A2B2-DBB145C1251D} failed due to the following error: 80040154.
Verify VPSX COM API is installed
Error	10/23/2018 9:00:07 AM	Service1	0	None	"Service cannot be started. System.Runtime.InteropServices.COMException (0x80010002): Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementScope.InitializeGuts(Object o)
   at System.Management.ManagementScope.Initialize()
   at System.Management.ManagementObjectSearcher.Initialize()
   at System.Management.ManagementObjectSearcher.Get()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)"
Information	10/23/2018 8:59:41 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/23/2018 8:59:39 AM	PostgreSQL	0	None	"2018-10-23 08:59:39 IST LOG:  redirecting log output to logging collector process
2018-10-23 08:59:39 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/23/2018 8:59:28 AM	MTAService	0	None	Service started successfully.
Information	10/23/2018 8:59:27 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/23/2018 8:58:54 AM	MTAService.OnStart	0	None	8:58:54 AM - User is already logged in : 212558710
Information	10/23/2018 8:58:49 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/23/2018 8:58:49 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/23/2018 8:58:49 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/23/2018 8:58:32 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/23/2018 8:58:29 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:29 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/23/2018 8:58:29 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/23/2018 8:58:29 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/23/2018 8:58:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/23/2018 8:58:28 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/23/2018 8:58:27 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/23/2018 8:58:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/23/2018 8:58:26 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/23/2018 8:58:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/23/2018 8:58:25 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:24 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/23/2018 8:58:24 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/23/2018 8:58:23 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/23/2018 8:58:23 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/23/2018 8:58:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/23/2018 8:58:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4660 at 10/23/2018 8:52:37 AM (local) 10/23/2018 3:22:37 AM (UTC). This is an informational message only; no user action is required.
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/23/2018 8:58:19 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/23/2018 8:58:18 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/23/2018 8:58:18 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/23/2018 8:58:18 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/23/2018 8:58:18 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4992.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/23/2018 8:58:15 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/23/2018 8:57:05 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/23/2018 8:56:47 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 8:55:57 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/23/2018 8:52:43 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/23/2018 8:55:58 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/23/2018 8:55:42 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/23/2018 8:52:37 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/23/2018 8:52:01 AM	Microsoft-Windows-Winlogon	6004	None	The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Warning	10/23/2018 8:52:01 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 149 second(s) to handle the notification event (CreateSession).
Information	10/23/2018 8:51:05 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/23/2018 8:51:01 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 8:51:01 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 8:51:00 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	10/23/2018 8:50:32 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	10/23/2018 8:49:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Warning	10/23/2018 8:49:39 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	10/23/2018 8:49:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 8:49:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 8:49:27 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	10/23/2018 8:49:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (WMPPlayer)
License Id=7d141cc8-75a1-5d14-1583-53c8065e7556"
Information	10/23/2018 8:49:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	10/23/2018 8:49:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	10/23/2018 8:49:24 AM	ESENT	302	Logging/Recovery	Windows (7848) Windows: The database engine has successfully completed recovery steps.
Information	10/23/2018 8:49:23 AM	ESENT	301	Logging/Recovery	Windows (7848) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/23/2018 8:49:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 8:49:23 AM	ESENT	300	Logging/Recovery	Windows (7848) Windows: The database engine is initiating recovery steps.
Information	10/23/2018 8:49:23 AM	ESENT	102	General	Windows (7848) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/23/2018 8:49:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/23/2018 8:49:11 AM	VPSX Printer Driver Management	1	None	"VPSX Printer Driver Management Service error: 
DRVX8318E <$MAIN$  > SERVICE CONTROL FUNCTION StartService FAILED RC(0) The service did not respond to the start or control request in a timely fashion.  
 
For more detail see log file: 
C:\Program Files\LRS\VPSX Printer Driver Management\drvxlog\20181023_084609.log
"
Error	10/23/2018 8:49:09 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8055E <$MAIN$          > SPOOL INITIALIZATION FAILED

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Error	10/23/2018 8:49:09 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8057E <$MAIN$          > SPOOL INDEX FILE IS CORRUPT

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/23/2018 8:48:59 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9053.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/23/2018 8:48:19 AM	Service1	0	None	Service started successfully.
Error	10/23/2018 8:48:09 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/23/2018 8:48:07 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/23/2018 8:47:47 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/23/2018 8:47:44 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/23/2018 8:47:41 AM	PostgreSQL	0	None	"2018-10-23 08:47:41 IST LOG:  redirecting log output to logging collector process
2018-10-23 08:47:41 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/23/2018 8:47:37 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/23/2018 8:47:25 AM	MTAService	0	None	Service started successfully.
Information	10/23/2018 8:47:25 AM	MTAService.OnStart	0	None	8:47:25 AM - Waiting for user to Logon
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/23/2018 8:47:22 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/23/2018 8:47:21 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/23/2018 8:47:21 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:21 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/23/2018 8:47:20 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/23/2018 8:47:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/23/2018 8:47:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/23/2018 8:47:17 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/23/2018 8:47:15 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:15 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:15 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4200 at 10/23/2018 4:26:33 AM (local) 10/22/2018 10:56:33 PM (UTC). This is an informational message only; no user action is required.
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/23/2018 8:47:14 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/23/2018 8:47:13 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/23/2018 8:47:13 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/23/2018 8:47:13 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/23/2018 8:47:13 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4660.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/23/2018 8:47:01 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/23/2018 8:45:35 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/23/2018 8:45:27 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/23/2018 8:42:49 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/23/2018 8:42:49 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/23/2018 8:42:49 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/23/2018 4:26:47 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/23/2018 4:26:32 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/23/2018 4:10:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 4:10:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:16Z. Reason: GVLK.
Warning	10/23/2018 4:08:50 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 30 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2588 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1056 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Error	10/23/2018 4:08:42 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8101E <$DDNS$          > TCP/IP HOST NAME RESOLUTION FAILED, HOST(vpsx01.cloud.ge.com) ERROR(The requested name is valid, but no data of the requested type was found.  )

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/23/2018 4:08:31 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/23/2018 4:08:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/23/2018 4:08:08 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/23/2018 4:05:38 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\system32\spool\DRIVERS\x64\3\CIOUM64.MSI. Client Process Id: 7892.
Information	10/23/2018 4:05:34 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 64 Bit HP CIO Components Installer. Product Version: 21.2.1. Product Language: 1033. Manufacturer: HP Inc.. Installation success or error status: 0.
Information	10/23/2018 4:05:34 AM	MsiInstaller	11707	None	Product: 64 Bit HP CIO Components Installer -- Installation completed successfully.
Information	10/23/2018 4:05:31 AM	Microsoft-Windows-Winsrv	10002	None	The following application was terminated because it was hung: wuauclt.exe.
Information	10/23/2018 4:05:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 4:05:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 4:05:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 4:05:11 AM	Microsoft-Windows-Winsrv	10002	None	The following application was terminated because it was hung: STS.exe.
Information	10/23/2018 4:05:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 4:04:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 4:04:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:50Z. Reason: GVLK.
Information	10/23/2018 4:04:37 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\system32\spool\DRIVERS\x64\3\CIOUM64.MSI. Client Process Id: 7892.
Information	10/23/2018 4:04:34 AM	GE Software	0	(1)	++Installation complete
Information	10/23/2018 4:04:31 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	10/23/2018 4:04:26 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	10/23/2018 4:04:21 AM	GE Software	0	(1)	++No Reboot requested by GE_InstallMFPSecureTrayApp_1005_V01
Information	10/23/2018 4:04:16 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	10/23/2018 4:04:16 AM	GE Software	0	(1)	Updating Pactrack registry keys with ge_installmfpsecuretrayapp_1005_v01
Information	10/23/2018 4:04:15 AM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	10/23/2018 4:04:15 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	10/23/2018 4:04:15 AM	GE Software	0	(1)	++MFPSecureTrayApp1005 exitcode = 0
Information	10/23/2018 4:04:14 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎22T22:32:37.125210600Z.
Warning	10/23/2018 4:03:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 4:02:37 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎22T22:32:37.125210600Z.
Information	10/23/2018 4:02:30 AM	GE Software	0	(1)	++VPSXAPIINST64.EXE exitcode = 1619
Information	10/23/2018 4:02:28 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\system32\config\systemprofile\AppData\Local\Downloaded Installations\{98031D6B-7254-469D-AB71-81B62CC82480}\vpsxapi.msi. Client Process Id: 17172.
Information	10/23/2018 4:02:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\system32\config\systemprofile\AppData\Local\Downloaded Installations\{98031D6B-7254-469D-AB71-81B62CC82480}\vpsxapi.msi. Client Process Id: 17172.
Information	10/23/2018 4:01:38 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	10/23/2018 4:01:38 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/23/2018 4:01:37 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/23/2018 4:01:32 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\GE_InstallMFPSecureTrayApp_1005_V01\ge_installmfpsecuretrayapp_1005_v01.exe with the following commandline: /Q /NOCHECK
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\GE_InstallMFPSecureTrayApp_1005_V01
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	10/23/2018 4:01:28 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++ GE_InstallMFPSecureTrayApp_1005_V01 was launched using the following Command line: /Q
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/23/2018 4:01:27 AM	GE Software	0	(1)	++ The installation of ge_installmfpsecuretrayapp_1005_v01.exe was launched with the following Command Line Switches: /Q
Information	10/23/2018 4:01:13 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	10/23/2018 4:01:04 AM	GE Software	0	(1)	++No Reboot requested by LRS_VPSX_Printer_1.07_V02
Information	10/23/2018 4:01:00 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	10/23/2018 4:01:00 AM	GE Software	0	(1)	Updating Pactrack registry keys with lrs_vpsx_printer_1.07_v02
Information	10/23/2018 4:01:00 AM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	10/23/2018 4:01:00 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	10/23/2018 4:00:45 AM	GE Software	0	(1)	++Installing GEPRINT printer with exitcode 0
Information	10/23/2018 4:00:45 AM	GE Software	0	(1)	++Executing command C:\Program Files\LRS\VPSX Printer Driver Management\ndrvu.exe  connect http://vpsx.cloud.ge.com:631/GEPRINT -s
Information	10/23/2018 4:00:42 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎22T22:28:04.803551600Z.
Information	10/23/2018 4:00:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\{E969C704-0FB0-47C3-89B8-870B356EAD3A}\drvinst64.msi. Client Process Id: 16276.
Information	10/23/2018 4:00:42 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: VPSX Printer Driver Management. Product Version: 1.072.300. Product Language: 1033. Manufacturer: Levi, Ray & Shoup, Inc. Installation success or error status: 0.
Information	10/23/2018 4:00:42 AM	MsiInstaller	11707	None	Product: VPSX Printer Driver Management -- Installation operation completed successfully.
Error	10/23/2018 4:00:40 AM	LRS VPSX	1	None	"The description for Event ID 1 from source LRS VPSX cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

VPSX8050E <$MAIN$          > OPEN REQUEST FAILED NAME(cntl\ckpt.dat) ERROR(2,No such file or directory)

For a full description of the above message please refer to the VPSX product documentation

If you are unable to determine the cause of the error please contact LRS Technical support http://www.vpsx.com/contact
"
Information	10/23/2018 3:58:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:58:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:58:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:58:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:58:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎22T22:28:04.803551600Z.
Information	10/23/2018 3:57:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\{E969C704-0FB0-47C3-89B8-870B356EAD3A}\drvinst64.msi. Client Process Id: 16276.
Information	10/23/2018 3:57:00 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	10/23/2018 3:57:00 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/23/2018 3:57:00 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/23/2018 3:56:51 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\LRS_VPSX_Printer_1.07_V02\lrs_vpsx_printer_1.07_v02.exe with the following commandline: /Q /NOCHECK
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\LRS_VPSX_Printer_1.07_V02
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	10/23/2018 3:56:27 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++ LRS_VPSX_Printer_1.07_V02 was launched using the following Command line: /Q
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/23/2018 3:56:26 AM	GE Software	0	(1)	++ The installation of lrs_vpsx_printer_1.07_v02.exe was launched with the following Command Line Switches: /Q
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++No Install Check was performed.
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++Started the installation of GE Print as a Service 1.0 V01 with the following commandline: /Q
Information	10/23/2018 3:56:06 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	10/23/2018 3:56:05 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	10/23/2018 3:51:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:51:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:19Z. Reason: GVLK.
Error	10/23/2018 3:43:19 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/23/2018 3:41:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:41:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:41:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:41:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:33:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:33:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:46Z. Reason: GVLK.
Information	10/23/2018 3:28:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:28:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:28:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:28:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:28:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:28:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:42Z. Reason: GVLK.
Information	10/23/2018 3:23:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:23:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:23:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:23:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:17:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:17:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:17Z. Reason: GVLK.
Information	10/23/2018 3:07:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:07:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:07:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:07:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:07:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:07:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:38Z. Reason: GVLK.
Error	10/23/2018 3:06:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/23/2018 3:02:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 3:02:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 3:02:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 3:02:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 3:01:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 3:01:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/23/2018 2:52:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 2:52:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 2:52:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 2:52:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 2:48:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 2:48:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:58Z. Reason: GVLK.
Information	10/23/2018 2:38:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 2:38:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 2:38:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 2:38:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 2:33:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 2:33:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:50Z. Reason: GVLK.
Warning	10/23/2018 2:25:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 2:24:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 2:24:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 2:24:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 2:24:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 2:19:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 2:19:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:51Z. Reason: GVLK.
Information	10/23/2018 2:10:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 2:10:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 2:10:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 2:10:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 2:05:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 2:05:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:09Z. Reason: GVLK.
Information	10/23/2018 1:55:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 1:55:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 1:55:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 1:55:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 1:51:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 1:51:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:13Z. Reason: GVLK.
Information	10/23/2018 1:42:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 1:42:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 1:42:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 1:41:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 1:34:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 1:34:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:02Z. Reason: GVLK.
Information	10/23/2018 1:24:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 1:24:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 1:24:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 1:24:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 1:18:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 1:18:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:48Z. Reason: GVLK.
Information	10/23/2018 1:09:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 1:09:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 1:09:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 1:09:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 1:04:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 1:03:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:42Z. Reason: GVLK.
Information	10/23/2018 12:54:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 12:54:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 12:54:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 12:54:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 12:49:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 12:49:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:25Z. Reason: GVLK.
Warning	10/23/2018 12:41:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/23/2018 12:40:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 12:40:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 12:40:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 12:40:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 12:35:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 12:35:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:09Z. Reason: GVLK.
Information	10/23/2018 12:26:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 12:26:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 12:25:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 12:25:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 12:20:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 12:20:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:20Z. Reason: GVLK.
Information	10/23/2018 12:17:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e5fcf000-d62a-11e8-83ef-204747d02364
Report Status: 0"
Information	10/23/2018 12:06:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/23/2018 12:06:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/23/2018 12:06:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/23/2018 12:06:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/23/2018 12:06:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/23/2018 12:06:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:58Z. Reason: GVLK.
Information	10/22/2018 11:56:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:56:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:56:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:56:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:52:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:52:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:17Z. Reason: GVLK.
Information	10/22/2018 11:46:32 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/22/2018 11:46:18 PM	ESENT	102	General	Windows (16444) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/22/2018 11:43:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:43:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:43:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:43:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:38:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:38:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:00Z. Reason: GVLK.
Information	10/22/2018 11:30:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12396.
Information	10/22/2018 11:30:01 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20080. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	10/22/2018 11:30:01 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	10/22/2018 11:30:01 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20080. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.008.20080). Installation success or error status: 0.
Information	10/22/2018 11:30:01 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.008.20080)' installed successfully.
Information	10/22/2018 11:28:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:28:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:28:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:28:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:28:28 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/22/2018 11:28:21 PM	ESENT	103	General	Windows (8628) Windows: The database engine stopped the instance (0).
Information	10/22/2018 11:27:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12396.
Information	10/22/2018 11:26:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 16176.
Information	10/22/2018 11:26:10 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20080. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	10/22/2018 11:26:10 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	10/22/2018 11:24:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 16176.
Information	10/22/2018 11:22:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:22:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:44Z. Reason: GVLK.
Information	10/22/2018 11:13:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:13:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:13:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:13:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:08:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:08:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:01Z. Reason: GVLK.
Warning	10/22/2018 11:06:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 11:03:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:03:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:03:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:03:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:02:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:02:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/22/2018 10:57:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:57:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:57:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:57:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:45:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:45:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:58Z. Reason: GVLK.
Information	10/22/2018 10:35:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:35:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:35:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:35:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:30:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:30:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:48Z. Reason: GVLK.
Information	10/22/2018 10:21:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:21:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:21:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:21:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:16:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:16:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:30Z. Reason: GVLK.
Information	10/22/2018 10:07:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:07:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:07:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:07:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:02:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:02:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:47Z. Reason: GVLK.
Information	10/22/2018 9:53:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:53:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:53:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:53:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:49:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:49:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:32Z. Reason: GVLK.
Information	10/22/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:40:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:36:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:36:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:10Z. Reason: GVLK.
Information	10/22/2018 9:27:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:27:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:27:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:27:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:22:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:22:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:51Z. Reason: GVLK.
Information	10/22/2018 9:21:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	10/22/2018 9:16:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/22/2018 9:16:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/22/2018 9:16:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22838)(?)])(1 )(2 )]

"
Information	10/22/2018 9:16:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/22/2018 9:16:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22838)(?)])(1 )(2 )]

"
Information	10/22/2018 9:16:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 22838)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:16:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/22/2018 9:16:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:16:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:13:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:13:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:13:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:13:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:09:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:09:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:40Z. Reason: GVLK.
Information	10/22/2018 9:00:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:00:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:00:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:00:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 8:55:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 8:55:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:09Z. Reason: GVLK.
Information	10/22/2018 8:46:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 8:46:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 8:46:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 8:46:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 8:42:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 8:42:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:58Z. Reason: GVLK.
Information	10/22/2018 8:33:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 8:33:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 8:33:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 8:33:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 8:30:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 8:30:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:59Z. Reason: GVLK.
Information	10/22/2018 8:21:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 8:21:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 8:21:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 8:21:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 8:18:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 8:18:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:36Z. Reason: GVLK.
Information	10/22/2018 8:09:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 8:09:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 8:09:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 8:09:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 8:05:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 8:05:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:58Z. Reason: GVLK.
Information	10/22/2018 7:55:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 7:55:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 7:55:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 7:55:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 7:48:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 7:48:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:14Z. Reason: GVLK.
Warning	10/22/2018 7:41:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 7:39:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 7:39:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 7:39:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 7:38:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 7:34:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 7:34:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:41Z. Reason: GVLK.
Information	10/22/2018 7:25:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 7:25:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 7:25:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 7:25:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 7:20:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 7:20:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:53Z. Reason: GVLK.
Information	10/22/2018 7:17:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fc536867-d600-11e8-83ef-204747d02364
Report Status: 0"
Information	10/22/2018 7:11:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 7:11:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 7:11:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 7:11:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 7:05:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 7:05:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:29Z. Reason: GVLK.
Information	10/22/2018 6:55:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 6:55:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 6:55:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 6:55:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 6:49:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 6:49:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:32Z. Reason: GVLK.
Information	10/22/2018 6:39:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 6:39:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 6:39:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 6:39:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 6:33:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 6:33:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:28Z. Reason: GVLK.
Information	10/22/2018 6:24:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 6:24:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 6:24:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 6:24:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 6:17:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 6:17:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:52Z. Reason: GVLK.
Information	10/22/2018 6:08:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 6:08:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 6:08:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 6:08:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 6:03:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 6:03:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:17Z. Reason: GVLK.
Information	10/22/2018 5:54:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 5:54:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 5:54:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 5:54:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 5:49:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 5:49:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:13Z. Reason: GVLK.
Warning	10/22/2018 5:47:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 5:40:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 5:40:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 5:40:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 5:40:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 5:35:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 5:35:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:12Z. Reason: GVLK.
Information	10/22/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 5:26:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 5:20:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 5:20:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:49Z. Reason: GVLK.
Information	10/22/2018 5:19:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 5:12:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/22/2018 5:12:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 5:12:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 5:11:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 5:11:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 5:11:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 5:11:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 5:06:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 5:06:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:14Z. Reason: GVLK.
Information	10/22/2018 4:56:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 4:56:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 4:56:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 4:56:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 4:51:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 4:51:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:26Z. Reason: GVLK.
Information	10/22/2018 4:42:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 4:42:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 4:42:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 4:42:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 4:39:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 4:39:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:46Z. Reason: GVLK.
Information	10/22/2018 4:31:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 4:31:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 4:31:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 4:31:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 4:29:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 4:29:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:10Z. Reason: GVLK.
Information	10/22/2018 4:20:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 4:20:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 4:20:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 4:20:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 4:18:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 4:18:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:16Z. Reason: GVLK.
Information	10/22/2018 4:09:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 4:09:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 4:09:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 4:09:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 4:08:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 4:08:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:01Z. Reason: GVLK.
Information	10/22/2018 3:59:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:59:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:59:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:59:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/22/2018 3:58:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 3:57:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:57:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:12Z. Reason: GVLK.
Information	10/22/2018 3:48:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:48:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:48:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:48:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 3:47:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:47:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:04Z. Reason: GVLK.
Information	10/22/2018 3:38:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:38:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:38:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:38:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 3:36:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:36:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:02Z. Reason: GVLK.
Information	10/22/2018 3:26:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:26:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:26:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:26:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 3:23:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:23:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:11Z. Reason: GVLK.
Information	10/22/2018 3:14:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:14:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:14:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:14:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 3:12:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:12:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:06Z. Reason: GVLK.
Information	10/22/2018 3:03:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 3:03:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 3:03:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 3:03:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 3:01:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 3:01:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:38Z. Reason: GVLK.
Information	10/22/2018 2:52:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 2:52:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:52:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:52:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:50:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:50:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:51Z. Reason: GVLK.
Information	10/22/2018 2:41:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 2:41:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:41:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:41:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:40:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:40:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:00Z. Reason: GVLK.
Information	10/22/2018 2:31:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 2:31:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:31:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:31:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:29:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:29:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:17Z. Reason: GVLK.
Warning	10/22/2018 2:20:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 2:19:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 2:19:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:19:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:19:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:17:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:17:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:21Z. Reason: GVLK.
Information	10/22/2018 2:14:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bff74743-d5d6-11e8-83ef-204747d02364
Report Status: 0"
Information	10/22/2018 2:09:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:08:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 2:08:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:08:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:08:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:07:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 2:07:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:14Z. Reason: GVLK.
Information	10/22/2018 2:04:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23271)(?)])(1 )(2 )]

"
Information	10/22/2018 2:04:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/22/2018 2:04:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23271)(?)])(1 )(2 )]

"
Information	10/22/2018 2:04:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23271)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 2:04:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/22/2018 2:04:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 2:03:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 2:01:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/22/2018 2:00:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/22/2018 1:58:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:58:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:58:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:58:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:57:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:56:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:59Z. Reason: GVLK.
Information	10/22/2018 1:48:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:48:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:48:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:48:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:46:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:46:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:56Z. Reason: GVLK.
Information	10/22/2018 1:38:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:38:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:38:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:38:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:33:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:33:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:41Z. Reason: GVLK.
Information	10/22/2018 1:28:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/22/2018 1:25:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:25:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:25:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:25:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:23:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:23:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:38Z. Reason: GVLK.
Information	10/22/2018 1:15:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/22/2018 1:14:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:14:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:14:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:14:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:13:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:13:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:21Z. Reason: GVLK.
Information	10/22/2018 1:04:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 1:04:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 1:04:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 1:04:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 1:03:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 1:03:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:14Z. Reason: GVLK.
Information	10/22/2018 12:54:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 12:54:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 12:54:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 12:54:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 12:52:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 12:52:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:40Z. Reason: GVLK.
Information	10/22/2018 12:45:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/22/2018 12:45:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/22/2018 12:43:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 12:43:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 12:43:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 12:43:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 12:42:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/22/2018 12:42:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/22/2018 12:41:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 12:41:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:50Z. Reason: GVLK.
Warning	10/22/2018 12:38:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 12:35:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/22/2018 12:34:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/22/2018 12:33:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/22/2018 12:33:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/22/2018 12:32:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 12:32:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 12:32:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 12:32:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 12:29:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 12:29:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:23Z. Reason: GVLK.
Information	10/22/2018 12:20:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 12:20:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 12:20:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 12:20:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 12:04:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 12:04:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:22Z. Reason: GVLK.
Information	10/22/2018 11:54:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:54:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:54:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:54:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:52:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:52:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:25Z. Reason: GVLK.
Information	10/22/2018 11:44:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:44:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:44:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:44:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:42:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:42:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:16Z. Reason: GVLK.
Information	10/22/2018 11:34:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:34:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:34:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:34:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:32:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:32:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:12Z. Reason: GVLK.
Information	10/22/2018 11:24:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:24:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:24:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:24:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:12:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:12:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:57Z. Reason: GVLK.
Information	10/22/2018 11:04:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 11:04:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 11:04:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 11:04:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 11:03:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 11:03:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:03Z. Reason: GVLK.
Information	10/22/2018 10:54:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:54:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:54:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:54:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:52:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:52:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:44Z. Reason: GVLK.
Information	10/22/2018 10:44:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:44:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:44:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:44:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/22/2018 10:42:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/22/2018 10:42:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:42:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:11Z. Reason: GVLK.
Information	10/22/2018 10:33:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:33:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:33:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:33:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:30:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:30:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:43Z. Reason: GVLK.
Information	10/22/2018 10:25:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:25:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:25:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:25:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:18:09 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9053.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/22/2018 10:10:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:10:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:29Z. Reason: GVLK.
Information	10/22/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 10:05:03 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/22/2018 10:01:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 10:01:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:55Z. Reason: GVLK.
Information	10/22/2018 9:55:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:55:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:55:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:55:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:49:37 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Error	10/22/2018 9:48:47 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/22/2018 9:41:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:41:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:32Z. Reason: GVLK.
Information	10/22/2018 9:36:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:36:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:36:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:36:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:31:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 42, Deleted: 0, Modified: 4, Compared: 28133, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/22/2018 9:30:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:30:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:42Z. Reason: GVLK.
Information	10/22/2018 9:28:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/22/2018 9:28:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/22/2018 9:28:32 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2295.
Information	10/22/2018 9:28:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/22/2018 9:28:07 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/22/2018 9:26:44 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 998

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 780

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 827

Information	10/22/2018 9:25:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:20:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:20:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:20:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:20:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/22/2018 9:20:23 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/22/2018 9:20:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23554)(?)])(1 )(2 )]

"
Information	10/22/2018 9:20:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/22/2018 9:20:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23554)(?)])(1 )(2 )]

"
Information	10/22/2018 9:20:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23554)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:19:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/22/2018 9:19:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:44Z. Reason: GVLK.
Information	10/22/2018 9:14:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d663b044-d5ac-11e8-83ef-204747d02364
Report Status: 0"
Information	10/22/2018 9:14:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/22/2018 9:14:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	10/22/2018 9:13:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/22/2018 9:13:50 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/22/2018 9:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23561)(?)])(1 )(2 )]

"
Information	10/22/2018 9:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/22/2018 9:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23561)(?)])(1 )(2 )]

"
Information	10/22/2018 9:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23561)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	10/22/2018 9:13:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/22/2018 9:12:26 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0C5AB098-1FDA-412D-995F-B6B1FC4D5F27}
Error	10/22/2018 9:12:26 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0C5AB098-1FDA-412D-995F-B6B1FC4D5F27}
Information	10/22/2018 9:12:16 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/22/2018 9:12:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/22/2018 9:12:14 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/22/2018 9:12:11 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/22/2018 9:12:08 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/22/2018 9:12:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23563)(?)])(1 )(2 )]

"
Information	10/22/2018 9:12:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/22/2018 9:12:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23563)(?)])(1 )(2 )]

"
Information	10/22/2018 9:12:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 23563)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:12:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/22/2018 9:12:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:12:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/22/2018 9:11:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/22/2018 9:11:40 AM	ESENT	302	Logging/Recovery	Windows (8628) Windows: The database engine has successfully completed recovery steps.
Information	10/22/2018 9:11:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/22/2018 9:11:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/22/2018 9:11:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/22/2018 9:11:32 AM	ESENT	301	Logging/Recovery	Windows (8628) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/22/2018 9:11:32 AM	ESENT	300	Logging/Recovery	Windows (8628) Windows: The database engine is initiating recovery steps.
Information	10/22/2018 9:11:31 AM	ESENT	102	General	Windows (8628) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/22/2018 9:11:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/22/2018 9:11:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9050.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/22/2018 9:10:48 AM	Service1	0	None	Service started successfully.
Error	10/22/2018 9:10:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/22/2018 9:10:26 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/22/2018 9:10:14 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/22/2018 9:10:08 AM	PostgreSQL	0	None	"2018-10-22 09:10:08 IST LOG:  redirecting log output to logging collector process
2018-10-22 09:10:08 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/22/2018 9:10:06 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/22/2018 9:10:04 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/22/2018 9:09:58 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/22/2018 9:09:57 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/22/2018 9:09:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/22/2018 9:09:39 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/22/2018 9:09:39 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/22/2018 9:09:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/22/2018 9:09:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/22/2018 9:09:34 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/22/2018 9:09:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/22/2018 9:09:32 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4432 at 10/20/2018 2:12:59 PM (local) 10/20/2018 8:42:59 AM (UTC). This is an informational message only; no user action is required.
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/22/2018 9:09:30 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/22/2018 9:09:29 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/22/2018 9:09:29 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/22/2018 9:09:29 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/22/2018 9:09:29 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4200.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/22/2018 9:09:25 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/22/2018 9:09:19 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/22/2018 9:09:09 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/22/2018 9:09:01 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/20/2018 2:13:05 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/22/2018 9:09:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/22/2018 9:09:01 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/20/2018 2:12:59 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/20/2018 2:12:57 PM	MTAService.OnSessionChange	0	None	2:12:57 PM - Logoff
Information	10/20/2018 2:12:57 PM	MTAService.OnSessionChange	0	None	2:12:57 PM - Session change notice received: SessionLogoff Session ID: 1
Warning	10/20/2018 2:12:56 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 4476 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1032 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4476 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/20/2018 2:12:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/20/2018 2:12:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/20/2018 2:12:55 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/20/2018 2:12:51 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/20/2018 2:11:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/20/2018 2:11:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:18Z. Reason: GVLK.
Information	10/20/2018 2:06:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/20/2018 2:06:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/20/2018 2:06:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/20/2018 2:06:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/20/2018 2:05:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/20/2018 2:05:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:22Z. Reason: GVLK.
Information	10/20/2018 1:58:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/20/2018 1:57:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7b892c9-d441-11e8-b703-204747d02364
Report Status: 0"
Information	10/20/2018 1:55:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9050.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/20/2018 1:55:03 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/20/2018 1:53:52 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/20/2018 1:53:47 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/20/2018 1:53:46 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/20/2018 1:53:45 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	10/20/2018 1:53:40 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {8DEDCFD2-C7C6-487B-A2D8-400EE35D1174}
Information	10/20/2018 1:53:23 PM	ESENT	302	Logging/Recovery	Windows (8672) Windows: The database engine has successfully completed recovery steps.
Information	10/20/2018 1:53:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/20/2018 1:53:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/20/2018 1:53:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	10/20/2018 1:53:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/20/2018 1:53:11 PM	ESENT	301	Logging/Recovery	Windows (8672) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/20/2018 1:53:10 PM	ESENT	300	Logging/Recovery	Windows (8672) Windows: The database engine is initiating recovery steps.
Information	10/20/2018 1:53:10 PM	ESENT	102	General	Windows (8672) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/20/2018 1:53:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/20/2018 1:53:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 26162)(?)])(1 )(2 )]

"
Information	10/20/2018 1:53:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/20/2018 1:53:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 26162)(?)])(1 )(2 )]

"
Information	10/20/2018 1:53:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 26162)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/20/2018 1:53:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/20/2018 1:53:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/20/2018 1:52:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/20/2018 1:52:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: mfevtp
P2: mfevtps.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5993030b-d441-11e8-b703-204747d02364
Report Status: 0"
Information	10/20/2018 1:51:37 PM	Service1	0	None	Service started successfully.
Error	10/20/2018 1:51:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/20/2018 1:51:01 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/20/2018 1:51:01 PM	MTAService	0	None	Service started successfully.
Error	10/20/2018 1:50:48 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/20/2018 1:50:48 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/20/2018 1:50:46 PM	PostgreSQL	0	None	"2018-10-20 13:50:46 IST LOG:  redirecting log output to logging collector process
2018-10-20 13:50:46 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/20/2018 1:50:46 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/20/2018 1:50:44 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/20/2018 1:50:37 PM	MTAService.OnStart	0	None	1:50:37 PM - User is already logged in : 212558710
Information	10/20/2018 1:50:29 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/20/2018 1:50:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/20/2018 1:50:28 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/20/2018 1:50:28 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/20/2018 1:50:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/20/2018 1:50:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/20/2018 1:50:20 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4736 at 10/19/2018 10:51:10 PM (local) 10/19/2018 5:21:10 PM (UTC). This is an informational message only; no user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/20/2018 1:50:18 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4432.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/20/2018 1:50:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/20/2018 1:49:48 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/20/2018 1:49:41 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/20/2018 1:49:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/20/2018 1:49:12 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/20/2018 1:49:11 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/19/2018 10:51:20 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/19/2018 10:51:10 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/19/2018 10:51:09 PM	McLogEvent	257	None	The scan of C:\Users\212558710\NTUSER.DAT has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9050.0000.
Warning	10/19/2018 10:51:05 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 596 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1288 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/19/2018 10:51:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/19/2018 10:51:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/19/2018 10:51:04 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/19/2018 10:51:00 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/19/2018 10:26:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 10:26:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:00Z. Reason: GVLK.
Information	10/19/2018 10:20:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 10:20:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 10:20:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 10:20:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 9:32:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 9:32:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:23Z. Reason: GVLK.
Information	10/19/2018 9:32:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 9:27:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 9:27:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 9:27:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 9:27:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/19/2018 9:27:12 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/19/2018 9:27:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27148)(?)])(1 )(2 )]

"
Information	10/19/2018 9:27:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/19/2018 9:27:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27148)(?)])(1 )(2 )]

"
Information	10/19/2018 9:27:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27148)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 9:27:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/19/2018 9:27:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 9:27:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 6:27:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 6:22:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27332)(?)])(1 )(2 )]

"
Information	10/19/2018 6:22:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/19/2018 6:22:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27332)(?)])(1 )(2 )]

"
Information	10/19/2018 6:22:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27332)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 6:22:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/19/2018 6:22:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 6:22:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 6:10:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2fc14851-d39c-11e8-aeb5-204747d02364
Report Status: 0"
Information	10/19/2018 2:36:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9050.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/19/2018 2:24:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 2:24:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:45Z. Reason: GVLK.
Information	10/19/2018 2:19:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 2:19:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 2:19:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 2:19:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 2:14:14 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/19/2018 1:54:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 1:54:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:45Z. Reason: GVLK.
Information	10/19/2018 1:49:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 1:49:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 1:49:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 1:49:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 1:38:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 1:38:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:47Z. Reason: GVLK.
Information	10/19/2018 1:33:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 1:33:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 1:33:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 1:33:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/19/2018 1:31:58 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/19/2018 1:27:29 PM	McLogEvent	257	None	The scan of D:\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 6000.8403 DAT version 9049.0000.
Information	10/19/2018 1:24:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 1:24:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:44Z. Reason: GVLK.
Error	10/19/2018 1:18:05 PM	Application Error	1000	(100)	"Faulting application name: UcMapi.exe, version: 16.0.9126.2295, time stamp: 0x5bab44d2
Faulting module name: mso30win32client.dll, version: 0.0.0.0, time stamp: 0x5bab3cd3
Exception code: 0xc0000005
Fault offset: 0x000b4d86
Faulting process id: 0x2770
Faulting application start time: 0x01d4677fe12a9082
Faulting application path: C:\Program Files (x86)\Microsoft Office\Root\Office16\UcMapi.exe
Faulting module path: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso30win32client.dll
Report Id: 4f54c01f-d373-11e8-aeb5-204747d02364"
Information	10/19/2018 1:17:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/19/2018 1:17:00 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	10/19/2018 1:12:38 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/19/2018 1:12:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27642)(?)])(1 )(2 )]

"
Information	10/19/2018 1:12:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/19/2018 1:12:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27642)(?)])(1 )(2 )]

"
Information	10/19/2018 1:12:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27642)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	10/19/2018 1:11:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/19/2018 1:08:59 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/19/2018 1:07:58 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	10/19/2018 1:07:55 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {3096A4C8-22FD-4583-87D9-259953566BF9}
Error	10/19/2018 1:07:55 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {3096A4C8-22FD-4583-87D9-259953566BF9}
Information	10/19/2018 1:07:55 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/19/2018 1:07:54 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/19/2018 1:07:52 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/19/2018 1:07:39 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	10/19/2018 1:07:38 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/19/2018 1:07:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/19/2018 1:07:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 1:07:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 1:07:24 PM	ESENT	302	Logging/Recovery	Windows (9188) Windows: The database engine has successfully completed recovery steps.
Information	10/19/2018 1:07:17 PM	ESENT	301	Logging/Recovery	Windows (9188) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/19/2018 1:07:17 PM	ESENT	300	Logging/Recovery	Windows (9188) Windows: The database engine is initiating recovery steps.
Information	10/19/2018 1:07:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 1:07:16 PM	ESENT	102	General	Windows (9188) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/19/2018 1:07:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27648)(?)])(1 )(2 )]

"
Information	10/19/2018 1:06:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/19/2018 1:06:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27648)(?)])(1 )(2 )]

"
Information	10/19/2018 1:06:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 27648)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/19/2018 1:06:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/19/2018 1:06:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/19/2018 1:06:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/19/2018 1:06:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9049.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	10/19/2018 1:06:31 PM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	10/19/2018 1:05:06 PM	Service1	0	None	Service started successfully.
Error	10/19/2018 1:04:59 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/19/2018 1:04:41 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/19/2018 1:04:29 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/19/2018 1:04:29 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/19/2018 1:04:27 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/19/2018 1:04:26 PM	PostgreSQL	0	None	"2018-10-19 13:04:26 IST LOG:  redirecting log output to logging collector process
2018-10-19 13:04:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/19/2018 1:04:14 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/19/2018 1:04:03 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/19/2018 1:03:34 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:34 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/19/2018 1:03:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/19/2018 1:03:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/19/2018 1:03:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/19/2018 1:03:33 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/19/2018 1:03:32 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/19/2018 1:03:31 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/19/2018 1:03:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/19/2018 1:03:31 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/19/2018 1:03:31 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/19/2018 1:03:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/19/2018 1:03:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4416 at 10/18/2018 12:25:39 PM (local) 10/18/2018 6:55:39 AM (UTC). This is an informational message only; no user action is required.
Information	10/19/2018 1:03:30 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/19/2018 1:03:29 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/19/2018 1:03:28 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/19/2018 1:03:28 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/19/2018 1:03:28 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/19/2018 1:03:28 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4736.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/19/2018 1:03:19 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/19/2018 1:02:30 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/19/2018 1:02:20 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/19/2018 1:02:11 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/18/2018 12:25:45 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/19/2018 1:02:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/19/2018 1:02:11 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	10/18/2018 12:25:39 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 15 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 536 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2560 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/18/2018 12:25:39 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/18/2018 12:25:39 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/18/2018 12:25:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/18/2018 12:25:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/18/2018 12:25:37 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/18/2018 12:25:35 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/18/2018 12:24:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29130)(?)])(1 )(2 )]

"
Information	10/18/2018 12:24:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/18/2018 12:24:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29130)(?)])(1 )(2 )]

"
Information	10/18/2018 12:24:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29130)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 12:24:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2018 12:24:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 12:24:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2018 12:05:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9049.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/18/2018 11:50:28 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2018 11:45:29 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:29 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2295. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:45:29 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	10/18/2018 11:45:28 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/18/2018 11:45:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29169)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 11:45:28 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/18/2018 11:45:28 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/18/2018 11:45:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:45:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2018 11:45:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:45:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2018 11:45:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2018 11:45:14 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:14 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2295. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:45:14 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	10/18/2018 11:45:11 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:11 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2295. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:45:11 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/18/2018 11:45:09 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:09 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:09 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2295. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:45:09 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/18/2018 11:45:03 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:03 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:45:03 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2295. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:45:03 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/18/2018 11:44:55 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/18/2018 11:44:46 AM	ESENT	102	General	Windows (9316) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/18/2018 11:44:45 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:44:42 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/18/2018 11:44:42 AM	ESENT	103	General	Windows (10936) Windows: The database engine stopped the instance (0).
Information	10/18/2018 11:44:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:44:42 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2295. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/18/2018 11:44:42 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/18/2018 11:44:32 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	10/18/2018 11:43:55 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6788.
Information	10/18/2018 11:43:40 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/18/2018 11:43:39 AM	ESENT	102	General	Windows (10936) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/18/2018 11:43:36 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/18/2018 11:43:36 AM	ESENT	103	General	Windows (8464) Windows: The database engine stopped the instance (0).
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:35 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/18/2018 11:43:33 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:33 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/18/2018 11:43:33 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:33 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/18/2018 11:43:33 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	10/18/2018 11:43:13 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/18/2018 11:43:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29172)(?)])(1 )(2 )]

"
Information	10/18/2018 11:43:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/18/2018 11:43:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29172)(?)])(1 )(2 )]

"
Information	10/18/2018 11:43:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29172)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 11:43:08 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/18/2018 11:43:08 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/18/2018 11:43:07 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	10/18/2018 11:43:06 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Skype for Business'.
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/18/2018 11:43:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2018 11:43:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:43:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/18/2018 11:43:02 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/18/2018 11:42:37 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	10/18/2018 11:42:00 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Information	10/18/2018 11:42:00 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	10/18/2018 11:42:00 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	10/18/2018 11:41:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎18T06:11:28.313826000Z.
Information	10/18/2018 11:36:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2018 11:36:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:11Z. Reason: GVLK.
Information	10/18/2018 11:31:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2018 11:31:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 11:31:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:31:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2018 11:26:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2018 11:26:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:15:04Z. Reason: GVLK.
Information	10/18/2018 11:24:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2018 11:22:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 09e19e46-d29a-11e8-a7d4-204747d02364
Report Status: 0"
Error	10/18/2018 11:19:54 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {33501253-74FD-4626-B825-114E96A0375F}
Information	10/18/2018 11:19:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/18/2018 11:19:33 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	10/18/2018 11:19:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/18/2018 11:19:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29196)(?)])(1 )(2 )]

"
Information	10/18/2018 11:19:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/18/2018 11:19:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29196)(?)])(1 )(2 )]

"
Information	10/18/2018 11:19:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 29196)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 11:19:06 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2018 11:19:06 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:19:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2018 11:18:52 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2018 11:18:50 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2018 11:18:49 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2018 11:18:47 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/18/2018 11:18:13 AM	ESENT	302	Logging/Recovery	Windows (8464) Windows: The database engine has successfully completed recovery steps.
Information	10/18/2018 11:18:04 AM	ESENT	301	Logging/Recovery	Windows (8464) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/18/2018 11:18:04 AM	ESENT	300	Logging/Recovery	Windows (8464) Windows: The database engine is initiating recovery steps.
Information	10/18/2018 11:18:03 AM	ESENT	102	General	Windows (8464) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/18/2018 11:17:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2018 11:17:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2018 11:17:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2018 11:17:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2018 11:17:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9048.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/18/2018 11:16:58 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/18/2018 11:16:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/18/2018 11:16:23 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/18/2018 11:16:23 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/18/2018 11:16:23 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/18/2018 11:16:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/18/2018 11:16:22 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/18/2018 11:16:22 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/18/2018 11:16:22 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/18/2018 11:16:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/18/2018 11:16:20 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/18/2018 11:16:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/18/2018 11:16:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/18/2018 11:16:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Error	10/18/2018 11:16:12 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/18/2018 11:16:12 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/18/2018 11:16:01 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/18/2018 11:15:55 AM	PostgreSQL	0	None	"2018-10-18 11:15:55 IST LOG:  redirecting log output to logging collector process
2018-10-18 11:15:55 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/18/2018 11:15:54 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/18/2018 11:15:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/18/2018 11:15:52 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/18/2018 11:15:52 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/18/2018 11:15:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/18/2018 11:15:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/18/2018 11:15:50 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/18/2018 11:15:09 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/18/2018 11:15:09 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/18/2018 11:15:09 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/18/2018 11:15:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/18/2018 11:15:09 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/18/2018 11:15:08 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/18/2018 11:15:08 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/18/2018 11:15:08 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/18/2018 11:15:08 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4620 at 10/17/2018 3:39:45 PM (local) 10/17/2018 10:09:45 AM (UTC). This is an informational message only; no user action is required.
Information	10/18/2018 11:15:08 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/18/2018 11:14:49 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/18/2018 11:14:49 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/18/2018 11:14:49 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/18/2018 11:14:49 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/18/2018 11:14:49 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4416.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/18/2018 11:14:38 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/18/2018 11:13:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/18/2018 11:12:58 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2018 11:12:28 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/18/2018 11:12:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/18/2018 11:12:28 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/17/2018 3:39:45 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/17/2018 3:39:28 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 34 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 732 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/17/2018 3:39:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/17/2018 3:39:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/17/2018 3:39:25 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	10/17/2018 3:37:56 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 11292 did not respond and is being forcibly terminated {filter host process 8160}. 

Warning	10/17/2018 3:14:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 3:03:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:02:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:02:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:01:39 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/17/2018 3:01:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/17/2018 2:55:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/17/2018 2:50:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 30424)(?)])(1 )(2 )]

"
Information	10/17/2018 2:50:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/17/2018 2:50:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 30424)(?)])(1 )(2 )]

"
Information	10/17/2018 2:50:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 30424)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 2:50:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/17/2018 2:50:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2018 2:50:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/17/2018 1:21:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 12:31:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/17/2018 12:31:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/17/2018 12:18:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9048.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/17/2018 11:55:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c5e0cf5-d1d5-11e8-8179-204747d02364
Report Status: 0"
Information	10/17/2018 11:40:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/17/2018 11:40:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/17/2018 11:40:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/17/2018 11:40:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	10/17/2018 11:23:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 11:02:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 11:02:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 11:02:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 11:01:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 9:50:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2018 9:50:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-24T04:14:55Z. Reason: GVLK.
Information	10/17/2018 9:45:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 9:45:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 9:45:55 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/10/17 04:15"
Information	10/17/2018 9:45:54 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/10/17 04:15, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	10/17/2018 9:44:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 9:40:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2018 9:40:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 9:40:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2018 9:40:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/17/2018 8:00:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 7:02:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 7:02:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 7:02:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 7:02:05 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/17/2018 7:01:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 6:55:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 92286a5c-d1ab-11e8-8179-204747d02364
Report Status: 0"
Warning	10/17/2018 6:10:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/17/2018 4:25:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 4:14:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2018 4:14:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:24Z. Reason: GVLK.
Information	10/17/2018 4:09:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2018 4:09:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 4:09:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2018 4:09:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/17/2018 4:08:30 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/17/2018 4:08:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2018 4:08:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:17Z. Reason: GVLK.
Error	10/17/2018 4:03:29 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/17/2018 4:03:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2018 4:03:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2018 4:03:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2018 4:03:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/17/2018 3:02:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:02:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:02:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:01:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:01:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2018 3:01:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/17/2018 2:38:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 1:55:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8763491-d181-11e8-8179-204747d02364
Report Status: 0"
Warning	10/17/2018 12:47:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/17/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/16/2018 11:12:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 11:02:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:42 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/16/2018 11:01:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 9:46:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 9:46:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:19Z. Reason: GVLK.
Information	10/16/2018 9:41:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 9:41:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 9:41:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 9:41:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	10/16/2018 9:16:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/16/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/16/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 31479)(?)])(1 )(2 )]

"
Information	10/16/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 31479)(?)])(1 )(2 )]

"
Information	10/16/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 31479)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 9:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2018 9:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2018 8:55:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bea3024c-d157-11e8-8179-204747d02364
Report Status: 0"
Warning	10/16/2018 7:23:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 7:02:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 7:01:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 7:01:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 7:01:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/16/2018 7:01:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/16/2018 5:50:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 3:55:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d4f34a5d-d12d-11e8-8179-204747d02364
Report Status: 0"
Warning	10/16/2018 3:54:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 3:26:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/16/2018 3:25:54 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/16/2018 3:14:23 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/16/2018 3:02:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 3:02:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 3:01:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 3:01:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 2:49:07 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎10‎-‎16T09:19:07.276389700Z.
Information	10/16/2018 2:49:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎10‎-‎16T09:19:07.276389700Z.
Warning	10/16/2018 2:20:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 1:49:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 1:49:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 1:19:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 1:19:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:42:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:41:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:37:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:36:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:33:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:32:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:30:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9047.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/16/2018 12:28:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:27:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:25:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:25:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 12:22:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:22:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/16/2018 12:20:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 12:13:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 12:13:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 11:58:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 11:57:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 11:53:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 11:52:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 11:22:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 11:22:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 11:19:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/16/2018 11:19:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/16/2018 11:02:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 11:01:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 10:55:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb46bc84-d103-11e8-8179-204747d02364
Report Status: 0"
Warning	10/16/2018 10:32:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/16/2018 8:38:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 8:24:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 8:24:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:56Z. Reason: GVLK.
Information	10/16/2018 8:19:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 8:19:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 8:19:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 8:19:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/16/2018 7:03:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 7:01:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 7:01:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 7:01:16 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/16/2018 7:00:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 6:11:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 6:11:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:04Z. Reason: GVLK.
Information	10/16/2018 6:06:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 6:06:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 6:06:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 6:06:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2018 5:55:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 019281dd-d0da-11e8-8179-204747d02364
Report Status: 0"
Warning	10/16/2018 5:31:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 5:00:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 5:00:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:20Z. Reason: GVLK.
Information	10/16/2018 4:55:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 4:55:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 4:55:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 4:55:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/16/2018 4:54:24 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/16/2018 4:54:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 4:54:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:20Z. Reason: GVLK.
Error	10/16/2018 4:49:30 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/16/2018 4:49:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 4:49:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 4:49:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 4:49:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/16/2018 3:53:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 3:41:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 3:41:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:08Z. Reason: GVLK.
Information	10/16/2018 3:36:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 3:36:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 3:36:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 3:36:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2018 3:01:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 3:01:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 3:00:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2018 2:15:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2018 2:15:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:17Z. Reason: GVLK.
Information	10/16/2018 2:10:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2018 2:10:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2018 2:10:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2018 2:10:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/16/2018 1:56:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 12:55:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17d9e348-d0b0-11e8-8179-204747d02364
Report Status: 0"
Warning	10/16/2018 12:12:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/16/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/15/2018 11:01:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 11:01:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 11:00:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/15/2018 10:37:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 9:21:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/15/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/15/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 32919)(?)])(1 )(2 )]

"
Information	10/15/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/15/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 32919)(?)])(1 )(2 )]

"
Information	10/15/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 32919)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2018 9:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/15/2018 9:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/15/2018 8:39:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 7:55:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e1e5102-d086-11e8-8179-204747d02364
Report Status: 0"
Information	10/15/2018 7:37:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2018 7:37:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:23Z. Reason: GVLK.
Information	10/15/2018 7:32:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2018 7:32:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2018 7:32:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2018 7:32:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/15/2018 7:30:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2018 7:30:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:18Z. Reason: GVLK.
Information	10/15/2018 7:25:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2018 7:25:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2018 7:25:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2018 7:25:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/15/2018 7:01:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:01:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:00:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:00:47 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/15/2018 7:00:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/15/2018 6:55:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 6:28:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/15/2018 6:17:55 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	10/15/2018 5:02:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/15/2018 3:28:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 3:05:07 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/15/2018 3:01:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 3:00:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 3:00:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 2:55:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 445de902-d05c-11e8-8179-204747d02364
Report Status: 0"
Information	10/15/2018 2:47:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/15/2018 2:46:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/15/2018 1:57:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 12:43:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/15/2018 12:43:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/15/2018 12:35:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/15/2018 12:35:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/15/2018 12:30:26 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9046.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	10/15/2018 12:17:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 12:15:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/15/2018 12:14:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/15/2018 11:20:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/15/2018 11:19:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/15/2018 11:01:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 11:00:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 11:00:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	10/15/2018 10:35:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 9:55:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a39b7ab-d032-11e8-8179-204747d02364
Report Status: 0"
Warning	10/15/2018 8:51:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 8:39:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/15/2018 8:39:33 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/15/2018 7:00:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:00:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:00:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 7:00:39 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/15/2018 7:00:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/15/2018 6:51:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/15/2018 5:20:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 5:07:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2018 5:07:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:46Z. Reason: GVLK.
Information	10/15/2018 5:02:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2018 5:02:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2018 5:02:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2018 5:02:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/15/2018 4:55:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 708a62c8-d008-11e8-8179-204747d02364
Report Status: 0"
Information	10/15/2018 4:30:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2018 4:30:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:06Z. Reason: GVLK.
Error	10/15/2018 4:24:36 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	10/15/2018 4:22:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/15/2018 4:22:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2018 4:22:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2018 4:22:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2018 4:22:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/15/2018 3:35:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 3:00:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 3:00:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/15/2018 3:00:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/15/2018 2:03:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/15/2018 12:04:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/15/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/14/2018 11:55:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86c9adae-cfde-11e8-8179-204747d02364
Report Status: 0"
Information	10/14/2018 11:00:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 11:00:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 11:00:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/14/2018 10:05:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 9:21:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/14/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/14/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 34359)(?)])(1 )(2 )]

"
Information	10/14/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/14/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 34359)(?)])(1 )(2 )]

"
Information	10/14/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 34359)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/14/2018 9:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/14/2018 9:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/14/2018 9:16:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/14/2018 8:06:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 7:00:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 7:00:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 7:00:29 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/14/2018 7:00:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 6:55:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d034e88-cfb4-11e8-8179-204747d02364
Report Status: 0"
Warning	10/14/2018 6:33:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 6:31:14 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 27827, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/14/2018 6:30:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/14/2018 6:30:20 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/14/2018 4:47:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/14/2018 4:47:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:31Z. Reason: GVLK.
Information	10/14/2018 4:42:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/14/2018 4:42:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/14/2018 4:42:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/14/2018 4:42:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/14/2018 4:38:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 3:00:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 3:00:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 2:59:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/14/2018 2:54:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 1:55:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b34f667d-cf8a-11e8-8179-204747d02364
Report Status: 0"
Warning	10/14/2018 1:11:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 12:51:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9045.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	10/14/2018 11:39:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 11:30:50 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/14/2018 11:30:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/14/2018 11:30:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/14/2018 11:30:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/14/2018 11:30:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/14/2018 11:30:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/14/2018 11:00:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 11:00:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 10:59:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/14/2018 10:03:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 9:39:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/14/2018 9:39:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:51Z. Reason: GVLK.
Information	10/14/2018 9:34:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/14/2018 9:34:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/14/2018 9:34:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/14/2018 9:34:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/14/2018 8:55:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c98c4107-cf60-11e8-8179-204747d02364
Report Status: 0"
Warning	10/14/2018 8:27:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 7:00:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 7:00:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 6:59:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 6:59:54 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/14/2018 6:59:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 6:53:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/14/2018 6:53:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:53Z. Reason: GVLK.
Information	10/14/2018 6:48:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/14/2018 6:48:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/14/2018 6:48:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/14/2018 6:48:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/14/2018 6:46:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/14/2018 4:57:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 4:47:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/14/2018 4:47:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:53Z. Reason: GVLK.
Error	10/14/2018 4:42:33 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	10/14/2018 4:41:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/14/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/14/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/14/2018 4:41:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/14/2018 4:41:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/14/2018 3:55:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dff24a34-cf36-11e8-8179-204747d02364
Report Status: 0"
Warning	10/14/2018 3:05:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 3:00:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 2:59:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/14/2018 2:59:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/14/2018 1:28:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/13/2018 11:56:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 11:00:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 10:59:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 10:59:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 10:55:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f637e5c1-cf0c-11e8-8179-204747d02364
Report Status: 0"
Warning	10/13/2018 10:00:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 9:21:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/13/2018 9:16:02 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 35799)(?)])(1 )(2 )]

"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 35799)(?)])(1 )(2 )]

"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 35799)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/13/2018 9:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 9:16:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/13/2018 8:10:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2018 8:10:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:38Z. Reason: GVLK.
Information	10/13/2018 8:05:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2018 8:05:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 8:05:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 8:05:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/13/2018 8:01:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 7:00:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/13/2018 6:59:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/13/2018 6:29:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 6:18:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2018 6:18:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:13Z. Reason: GVLK.
Information	10/13/2018 6:13:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2018 6:13:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 6:13:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 6:13:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2018 5:55:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c7ff3b4-cee3-11e8-8179-204747d02364
Report Status: 0"
Information	10/13/2018 4:46:52 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	10/13/2018 4:40:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 3:00:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 2:59:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 2:59:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 2:59:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/13/2018 2:49:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/13/2018 1:15:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 12:55:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 22c1bd88-ceb9-11e8-8179-204747d02364
Report Status: 0"
Information	10/13/2018 12:05:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9044.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	10/13/2018 11:35:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 10:59:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 10:59:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 10:59:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/13/2018 9:37:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 7:55:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38f125f2-ce8f-11e8-8179-204747d02364
Report Status: 0"
Warning	10/13/2018 7:44:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 6:59:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:59:36 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/13/2018 6:59:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 6:46:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2018 6:46:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:11Z. Reason: GVLK.
Information	10/13/2018 6:41:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2018 6:41:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 6:41:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 6:41:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/13/2018 6:04:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 5:09:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2018 5:09:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:51Z. Reason: GVLK.
Information	10/13/2018 5:04:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2018 5:04:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 5:04:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 5:04:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/13/2018 5:03:56 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/13/2018 5:03:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2018 5:03:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:36Z. Reason: GVLK.
Error	10/13/2018 4:58:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/13/2018 4:58:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2018 4:58:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2018 4:58:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2018 4:58:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/13/2018 4:11:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 2:59:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 2:59:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/13/2018 2:55:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4f3527bc-ce65-11e8-8179-204747d02364
Report Status: 0"
Warning	10/13/2018 2:14:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/13/2018 12:21:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/12/2018 10:59:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 10:59:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 10:59:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/12/2018 10:40:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 9:55:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 65712f24-ce3b-11e8-8179-204747d02364
Report Status: 0"
Information	10/12/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/12/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37239)(?)])(1 )(2 )]

"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37239)(?)])(1 )(2 )]

"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37239)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/12/2018 8:46:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/12/2018 7:07:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 6:59:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 6:59:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 6:59:27 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/12/2018 6:59:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 6:51:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 6:51:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:18Z. Reason: GVLK.
Information	10/12/2018 6:46:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 6:46:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 6:46:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 6:46:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/12/2018 5:15:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 4:55:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7bb83de3-ce11-11e8-8179-204747d02364
Report Status: 0"
Information	10/12/2018 4:45:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/12/2018 4:45:28 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	10/12/2018 3:24:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 2:59:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 2:59:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/12/2018 1:40:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 1:05:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 1:01:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9043.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/12/2018 1:00:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37735)(?)])(1 )(2 )]

"
Information	10/12/2018 1:00:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2018 1:00:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37735)(?)])(1 )(2 )]

"
Information	10/12/2018 1:00:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37735)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 1:00:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2018 1:00:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 1:00:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2018 12:59:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 12:54:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37740)(?)])(1 )(2 )]

"
Information	10/12/2018 12:54:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2018 12:54:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37740)(?)])(1 )(2 )]

"
Information	10/12/2018 12:54:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 37740)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 12:54:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2018 12:54:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 12:54:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2018 11:52:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/12/2018 11:51:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/12/2018 11:49:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/12/2018 11:49:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/12/2018 11:44:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 11:38:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2bab8d2d-cde5-11e8-8179-204747d02364
Report Status: 0"
Information	10/12/2018 10:59:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/12/2018 10:58:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/12/2018 10:26:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 10:26:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:47Z. Reason: GVLK.
Information	10/12/2018 10:21:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 10:21:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 10:21:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 10:21:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/12/2018 10:12:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/12/2018 8:23:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 7:27:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 7:27:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:37Z. Reason: GVLK.
Information	10/12/2018 7:22:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 7:22:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 7:22:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 7:22:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2018 6:59:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 6:59:14 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/12/2018 6:58:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/12/2018 6:39:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 6:37:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 41cb4cbe-cdbb-11e8-8179-204747d02364
Report Status: 0"
Information	10/12/2018 5:24:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 5:24:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:09Z. Reason: GVLK.
Information	10/12/2018 5:19:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 5:19:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 5:19:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 5:19:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/12/2018 5:04:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 4:14:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 4:14:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:02Z. Reason: GVLK.
Information	10/12/2018 4:09:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 4:09:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 4:09:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 4:09:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/12/2018 4:08:07 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/12/2018 4:07:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2018 4:07:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:37Z. Reason: GVLK.
Error	10/12/2018 4:02:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/12/2018 4:02:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2018 4:02:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2018 4:02:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2018 4:02:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/12/2018 3:30:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 2:59:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2018 2:58:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/12/2018 1:58:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 1:37:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 580f036e-cd91-11e8-8179-204747d02364
Report Status: 0"
Warning	10/12/2018 12:11:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/12/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/11/2018 10:59:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 10:58:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/11/2018 10:35:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 9:21:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/11/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/11/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 38679)(?)])(1 )(2 )]

"
Information	10/11/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/11/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 38679)(?)])(1 )(2 )]

"
Information	10/11/2018 9:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 38679)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 9:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/11/2018 9:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/11/2018 8:39:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 8:37:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6e782643-cd67-11e8-8179-204747d02364
Report Status: 0"
Information	10/11/2018 6:58:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 6:58:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 6:58:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	10/11/2018 6:53:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 6:52:48 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 27795, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/11/2018 6:50:53 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	10/11/2018 5:07:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 5:00:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 6000.8403
 DAT version : 9042.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	10/11/2018 3:37:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 84bfdeef-cd3d-11e8-8179-204747d02364
Report Status: 0"
Warning	10/11/2018 3:21:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 3:18:54 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/11/2018 3:18:45 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/11/2018 3:00:11 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/11/2018 2:58:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/11/2018 2:58:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/11/2018 2:58:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	10/11/2018 12:44:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 12:44:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2018 12:42:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 12:41:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2018 12:28:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 12:28:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2018 12:25:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 12:25:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2018 12:01:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2018 12:01:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:43Z. Reason: GVLK.
Information	10/11/2018 11:56:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2018 11:56:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 11:56:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 11:56:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2018 11:47:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 11:47:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2018 11:41:29 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/11/2018 11:41:29 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/11/2018 11:41:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/11/2018 11:41:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/11/2018 11:30:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2018 11:30:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/11/2018 11:11:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 10:58:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 10:58:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 10:58:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 10:37:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9b4e1fac-cd13-11e8-8179-204747d02364
Report Status: 0"
Warning	10/11/2018 9:16:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/11/2018 7:26:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 6:58:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 6:58:33 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/11/2018 6:58:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 6:58:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/11/2018 5:49:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 5:37:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1a72bfb-cce9-11e8-8179-204747d02364
Report Status: 0"
Information	10/11/2018 4:30:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2018 4:30:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:45Z. Reason: GVLK.
Information	10/11/2018 4:25:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2018 4:25:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 4:25:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 4:25:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2018 4:24:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2018 4:24:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:53Z. Reason: GVLK.
Error	10/11/2018 4:24:34 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	10/11/2018 4:20:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/11/2018 4:19:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2018 4:19:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 4:19:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 4:19:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/11/2018 4:15:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 2:58:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 2:58:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2018 2:57:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2018 2:57:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:58Z. Reason: GVLK.
Information	10/11/2018 2:52:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2018 2:52:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 2:52:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 2:52:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/11/2018 2:21:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 2:09:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2018 2:09:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:08Z. Reason: GVLK.
Information	10/11/2018 2:04:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2018 2:04:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2018 2:04:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2018 2:04:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2018 2:00:00 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/11/2018 1:58:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	10/11/2018 12:40:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/11/2018 12:37:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c802c013-ccbf-11e8-8179-204747d02364
Report Status: 0"
Information	10/11/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/10/2018 10:58:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 10:58:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/10/2018 10:48:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/10/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40119)(?)])(1 )(2 )]

"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40119)(?)])(1 )(2 )]

"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40119)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/10/2018 9:01:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 7:37:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dedb51fd-cc95-11e8-8179-204747d02364
Report Status: 0"
Warning	10/10/2018 7:15:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 6:58:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 6:58:20 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/10/2018 6:58:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 5:49:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 5:49:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:10Z. Reason: GVLK.
Information	10/10/2018 5:44:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 5:44:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 5:44:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 5:44:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/10/2018 5:26:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 3:43:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 3:43:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:08Z. Reason: GVLK.
Information	10/10/2018 3:38:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 3:38:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 3:38:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 3:38:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/10/2018 3:36:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/10/2018 3:33:58 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/10/2018 3:23:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 3:23:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:10:18Z. Reason: GVLK.
Error	10/10/2018 3:13:55 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/10/2018 3:13:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 3:13:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 3:13:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 3:13:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/10/2018 3:04:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 3:00:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17588.
Information	10/10/2018 3:00:25 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20074. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	10/10/2018 3:00:25 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	10/10/2018 3:00:25 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20074. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.008.20074). Installation success or error status: 0.
Information	10/10/2018 3:00:25 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.008.20074)' installed successfully.
Information	10/10/2018 3:00:12 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 890

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 2137

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 811

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	10/10/2018 3:00:10 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/10/2018 2:59:55 PM	ESENT	102	General	Windows (12692) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	10/10/2018 2:59:52 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5FDEFE80-3725-4A4C-8F9E-8AF78DC8BD39}
Error	10/10/2018 2:59:52 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5FDEFE80-3725-4A4C-8F9E-8AF78DC8BD39}
Information	10/10/2018 2:59:40 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/10/2018 2:59:39 PM	ESENT	103	General	Windows (9040) Windows: The database engine stopped the instance (0).
Information	10/10/2018 2:58:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17588.
Information	10/10/2018 2:58:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17820.
Information	10/10/2018 2:58:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20074. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	10/10/2018 2:58:02 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	10/10/2018 2:57:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 2:57:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]

"
Information	10/10/2018 2:57:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2018 2:57:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]

"
Information	10/10/2018 2:57:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 2:57:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17820.
Information	10/10/2018 2:56:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]

"
Information	10/10/2018 2:56:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2018 2:56:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]

"
Information	10/10/2018 2:56:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 40498)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	10/10/2018 2:56:43 PM	Microsoft Office 16	2000	None	Microsoft Outlook: Accepted Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Warning	10/10/2018 2:56:31 PM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	10/10/2018 2:56:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2018 2:56:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 2:56:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2018 2:55:59 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 9157 milliseconds
Information	10/10/2018 2:37:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5176fee-cc6b-11e8-8179-204747d02364
Report Status: 0"
Warning	10/10/2018 1:45:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 12:55:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2018 12:54:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/10/2018 12:41:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9041.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/10/2018 12:40:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2018 12:39:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/10/2018 12:39:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2018 12:38:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/10/2018 12:06:33 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/10/2018 12:04:09 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	10/10/2018 12:03:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 11:46:14 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/10/2018 11:26:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 11:25:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 11:25:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/10/2018 10:20:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 9:45:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 9:45:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-17T04:09:44Z. Reason: GVLK.
Information	10/10/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/10/10 04:10"
Information	10/10/2018 9:40:42 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/10/10 04:10, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/10/2018 9:37:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0ae5e0a2-cc42-11e8-8179-204747d02364
Report Status: 0"
Information	10/10/2018 9:35:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 9:35:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 9:35:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 9:35:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/10/2018 8:33:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 7:26:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 7:25:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 7:25:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/10/2018 7:25:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 7:25:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 7:05:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2018 7:05:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/10/2018 6:49:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/10/2018 5:23:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2018 5:23:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/10/2018 5:07:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 5:07:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:38Z. Reason: GVLK.
Information	10/10/2018 5:00:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 5:00:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 5:00:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 5:00:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/10/2018 4:58:40 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/10/2018 4:54:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2018 4:54:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:36Z. Reason: GVLK.
Warning	10/10/2018 4:50:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	10/10/2018 4:50:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/10/2018 4:49:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2018 4:49:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2018 4:49:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2018 4:49:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/10/2018 4:37:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2127c64c-cc18-11e8-8179-204747d02364
Report Status: 0"
Information	10/10/2018 3:26:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 3:25:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2018 3:25:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/10/2018 2:59:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/10/2018 12:59:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 11:37:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 377e3cf3-cbee-11e8-8179-204747d02364
Report Status: 0"
Information	10/9/2018 11:25:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 11:25:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 11:25:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/9/2018 11:00:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 10:10:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 10:10:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:13Z. Reason: GVLK.
Information	10/9/2018 10:05:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 10:05:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 10:05:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 10:05:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2018 9:21:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/9/2018 9:16:05 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/9/2018 9:16:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 41559)(?)])(1 )(2 )]

"
Information	10/9/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/9/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 41559)(?)])(1 )(2 )]

"
Information	10/9/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 41559)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 9:16:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2018 9:16:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 9:16:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/9/2018 9:07:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 7:25:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/9/2018 7:25:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/9/2018 7:23:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 6:37:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4dbe48e6-cbc4-11e8-8179-204747d02364
Report Status: 0"
Warning	10/9/2018 5:36:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/9/2018 3:39:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 3:25:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 3:25:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 3:25:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 3:25:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/9/2018 3:25:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 3:20:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 3:20:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:38Z. Reason: GVLK.
Information	10/9/2018 3:15:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 3:15:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 3:15:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 3:15:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2018 3:13:57 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/9/2018 3:03:17 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/9/2018 3:02:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/9/2018 2:20:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 2:20:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 2:04:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 2:04:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/9/2018 2:00:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 1:37:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63ebd783-cb9a-11e8-8179-204747d02364
Report Status: 0"
Information	10/9/2018 1:32:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 1:32:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:52Z. Reason: GVLK.
Information	10/9/2018 1:27:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 1:27:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 1:27:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 1:27:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2018 1:24:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 1:23:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 1:10:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 1:10:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 1:07:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 1:07:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 1:07:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 1:07:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:48:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9040.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/9/2018 12:46:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:45:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:45:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:45:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:42:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:42:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:39:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:38:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:36:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:36:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 12:25:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:25:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/9/2018 12:23:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 12:21:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 12:21:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 11:48:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 11:48:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 11:25:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 11:24:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 11:17:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 11:16:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 11:06:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 11:06:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/9/2018 10:56:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/9/2018 10:55:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/9/2018 10:34:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/9/2018 8:52:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 8:37:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7a0b5438-cb70-11e8-8179-204747d02364
Report Status: 0"
Information	10/9/2018 7:25:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 7:25:09 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/9/2018 7:24:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/9/2018 7:04:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/9/2018 5:18:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 4:52:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 4:52:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:27Z. Reason: GVLK.
Information	10/9/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/9/2018 4:45:15 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/9/2018 4:40:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 4:40:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:28Z. Reason: GVLK.
Error	10/9/2018 4:35:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/9/2018 4:35:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 4:35:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 4:35:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 4:35:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2018 3:48:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2018 3:48:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:14Z. Reason: GVLK.
Warning	10/9/2018 3:46:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 3:43:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2018 3:43:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2018 3:43:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2018 3:43:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2018 3:37:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9055e075-cb46-11e8-8179-204747d02364
Report Status: 0"
Information	10/9/2018 3:25:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2018 3:24:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/9/2018 1:50:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/9/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/9/2018 12:02:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 11:25:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 11:24:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 10:42:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 10:42:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:05Z. Reason: GVLK.
Information	10/8/2018 10:37:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a6a81300-cb1c-11e8-8179-204747d02364
Report Status: 0"
Information	10/8/2018 10:37:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 10:37:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 10:37:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 10:37:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/8/2018 10:20:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 9:30:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 9:30:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:39Z. Reason: GVLK.
Information	10/8/2018 9:25:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 9:25:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 9:25:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 9:25:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 9:21:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/8/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 42999)(?)])(1 )(2 )]

"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 42999)(?)])(1 )(2 )]

"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 42999)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 8:40:26 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/8/2018 8:32:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 7:29:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 7:28:09 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 24, Deleted: 1, Modified: 1, Compared: 27613, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/8/2018 7:25:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:25:00 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 187

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 858

Information	10/8/2018 7:24:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/8/2018 7:24:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:23:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 7:23:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 7:23:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43111)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 7:23:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 7:23:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 7:23:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/8/2018 6:51:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 5:37:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bcdd80f6-caf2-11e8-8179-204747d02364
Report Status: 0"
Warning	10/8/2018 4:51:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 4:19:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 4:19:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:35Z. Reason: GVLK.
Information	10/8/2018 4:14:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 4:14:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 4:14:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 4:14:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 4:11:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 4:06:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43309)(?)])(1 )(2 )]

"
Information	10/8/2018 4:06:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 4:06:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43309)(?)])(1 )(2 )]

"
Information	10/8/2018 4:06:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43309)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 4:06:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 4:06:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 4:06:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:49:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 3:49:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:35Z. Reason: GVLK.
Information	10/8/2018 3:44:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 3:44:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 3:44:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 3:44:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:40:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 3:40:25 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/8/2018 3:40:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T10:10:05.185354300Z.
Information	10/8/2018 3:40:21 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{4BF823C1-ED3F-42B8-B6BA-FA443F63CD38}\DeviceManager.msi. Client Process Id: 10592.
Information	10/8/2018 3:40:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T10:10:05.185354300Z.
Information	10/8/2018 3:40:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{4BF823C1-ED3F-42B8-B6BA-FA443F63CD38}\DeviceManager.msi. Client Process Id: 10592.
Information	10/8/2018 3:40:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T10:09:52.982177000Z.
Information	10/8/2018 3:40:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BEA6BB5C-5218-4911-8E6B-9B5CDEFC7C23}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 6056.
Information	10/8/2018 3:40:00 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 3:40:00 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/8/2018 3:39:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T10:09:52.982177000Z.
Information	10/8/2018 3:39:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BEA6BB5C-5218-4911-8E6B-9B5CDEFC7C23}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 6056.
Information	10/8/2018 3:26:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:56:16.577361700Z.
Information	10/8/2018 3:26:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 4664.
Information	10/8/2018 3:26:20 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 3:26:20 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/8/2018 3:26:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:56:16.577361700Z.
Information	10/8/2018 3:26:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 4664.
Information	10/8/2018 3:26:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 4664.
Information	10/8/2018 3:26:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	10/8/2018 3:26:02 PM	MsiInstaller	11729	None	Product: DeviceDriver -- Configuration failed.
Information	10/8/2018 3:25:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 4664.
Information	10/8/2018 3:25:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:55:51.523647900Z.
Information	10/8/2018 3:25:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 4664.
Information	10/8/2018 3:25:55 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 3:25:55 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/8/2018 3:25:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:55:51.523647900Z.
Information	10/8/2018 3:25:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 4664.
Information	10/8/2018 3:19:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 3:19:37 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:36Z. Reason: GVLK.
Information	10/8/2018 3:14:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 3:14:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 3:14:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 3:14:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:10:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 3:10:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:01Z. Reason: GVLK.
Information	10/8/2018 3:07:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 3:04:06 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/8/2018 3:02:40 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/8/2018 3:02:39 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2018 3:02:38 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2018 3:02:36 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2018 3:02:34 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	10/8/2018 3:02:24 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/8/2018 3:02:16 PM	ESENT	302	Logging/Recovery	Windows (9040) Windows: The database engine has successfully completed recovery steps.
Information	10/8/2018 3:02:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43373)(?)])(1 )(2 )]

"
Information	10/8/2018 3:02:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 3:02:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43373)(?)])(1 )(2 )]

"
Information	10/8/2018 3:02:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43373)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 3:02:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 3:02:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 3:02:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 3:02:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 3:02:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 3:02:08 PM	ESENT	301	Logging/Recovery	Windows (9040) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/8/2018 3:02:08 PM	ESENT	300	Logging/Recovery	Windows (9040) Windows: The database engine is initiating recovery steps.
Information	10/8/2018 3:02:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:02:08 PM	ESENT	102	General	Windows (9040) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/8/2018 3:02:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:01:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9039.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	10/8/2018 3:01:47 PM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	10/8/2018 3:00:03 PM	PostgreSQL	0	None	Server started and accepting connections

Error	10/8/2018 3:00:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/8/2018 3:00:02 PM	Service1	0	None	Service started successfully.
Information	10/8/2018 2:59:56 PM	PostgreSQL	0	None	"2018-10-08 14:59:56 IST LOG:  redirecting log output to logging collector process
2018-10-08 14:59:56 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Error	10/8/2018 2:59:49 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/8/2018 2:59:48 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/8/2018 2:59:39 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/8/2018 2:59:37 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/8/2018 2:59:11 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/8/2018 2:58:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/8/2018 2:58:47 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/8/2018 2:58:47 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/8/2018 2:58:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/8/2018 2:58:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/8/2018 2:58:39 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:39 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/8/2018 2:58:39 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/8/2018 2:58:39 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/8/2018 2:58:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/8/2018 2:58:38 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/8/2018 2:58:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/8/2018 2:58:38 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:37 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/8/2018 2:58:36 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/8/2018 2:58:36 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/8/2018 2:58:36 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4348 at 10/8/2018 2:53:11 PM (local) 10/8/2018 9:23:11 AM (UTC). This is an informational message only; no user action is required.
Information	10/8/2018 2:58:34 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/8/2018 2:58:33 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/8/2018 2:58:33 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/8/2018 2:58:33 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/8/2018 2:58:33 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/8/2018 2:58:33 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/8/2018 2:58:28 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/8/2018 2:58:28 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/8/2018 2:58:28 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/8/2018 2:58:28 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/8/2018 2:58:28 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4620.
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/8/2018 2:58:27 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/8/2018 2:57:46 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/8/2018 2:57:39 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2018 2:57:21 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/8/2018 2:53:24 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Warning	10/8/2018 2:53:13 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 23 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1052 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 180 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 180 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4436 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 180 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 180 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 180 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 4436 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
"
Information	10/8/2018 2:57:21 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/8/2018 2:57:21 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/8/2018 2:53:11 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/8/2018 2:53:05 PM	MTAService.OnSessionChange	0	None	2:53:05 PM - Logoff
Information	10/8/2018 2:53:05 PM	MTAService.OnSessionChange	0	None	2:53:05 PM - Session change notice received: SessionLogoff Session ID: 1
Information	10/8/2018 2:53:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/8/2018 2:53:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/8/2018 2:53:03 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/8/2018 2:47:22 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 2:47:22 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/8/2018 2:46:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:16:46.809362400Z.
Information	10/8/2018 2:46:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{843C025B-0477-4359-8566-8C0D03737F66}\DeviceManager.msi. Client Process Id: 15872.
Information	10/8/2018 2:46:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:16:46.809362400Z.
Information	10/8/2018 2:46:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{843C025B-0477-4359-8566-8C0D03737F66}\DeviceManager.msi. Client Process Id: 15872.
Information	10/8/2018 2:46:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:16:35.276209200Z.
Information	10/8/2018 2:46:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{23DDA7E8-DFEB-468C-A6E3-0DAB89B1AB5F}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 4344.
Information	10/8/2018 2:46:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 2:46:42 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/8/2018 2:46:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:16:35.276209200Z.
Information	10/8/2018 2:46:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{23DDA7E8-DFEB-468C-A6E3-0DAB89B1AB5F}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 4344.
Information	10/8/2018 2:45:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:15:24.302112500Z.
Information	10/8/2018 2:45:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8756.
Information	10/8/2018 2:45:31 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 2:45:31 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/8/2018 2:45:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:15:24.302112500Z.
Information	10/8/2018 2:45:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8756.
Information	10/8/2018 2:45:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8756.
Information	10/8/2018 2:45:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	10/8/2018 2:45:19 PM	MsiInstaller	11729	None	Product: DeviceManager -- Configuration failed.
Information	10/8/2018 2:45:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8756.
Information	10/8/2018 2:44:48 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	10/8/2018 2:44:48 PM	MsiInstaller	11729	None	Product: DeviceManager -- Configuration failed.
Information	10/8/2018 2:44:28 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	10/8/2018 2:44:13 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 2:44:13 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/8/2018 2:44:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T09:13:58.307513900Z.
Information	10/8/2018 2:44:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3B8448FE-D45A-47A1-8930-F40B213A4D6C}\DeviceManager.msi. Client Process Id: 15980.
Information	10/8/2018 2:43:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T09:13:58.307513900Z.
Information	10/8/2018 2:43:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3B8448FE-D45A-47A1-8930-F40B213A4D6C}\DeviceManager.msi. Client Process Id: 15980.
Information	10/8/2018 2:43:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	10/8/2018 2:43:02 PM	MsiInstaller	11708	None	Product: DeviceManager -- Installation operation failed.
Information	10/8/2018 2:42:28 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	10/8/2018 2:42:28 PM	MsiInstaller	11708	None	Product: DeviceManager -- Installation operation failed.
Information	10/8/2018 2:12:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T08:42:37.559457900Z.
Information	10/8/2018 2:12:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 16372.
Information	10/8/2018 2:12:40 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 2:12:40 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/8/2018 2:12:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T08:42:37.559457900Z.
Information	10/8/2018 2:12:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 16372.
Information	10/8/2018 2:12:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T08:42:20.358738000Z.
Information	10/8/2018 2:12:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 16372.
Information	10/8/2018 2:12:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 2:12:27 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/8/2018 2:12:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T08:42:20.358738000Z.
Information	10/8/2018 2:12:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 16372.
Information	10/8/2018 2:00:53 PM	MTAService.OnSessionChange	0	None	2:00:53 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/8/2018 1:32:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 1:13:21 PM	MTAService.OnSessionChange	0	None	1:13:21 PM - Session change notice received: SessionLock Session ID: 1
Information	10/8/2018 1:10:57 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 1:10:57 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/8/2018 1:10:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:40:42.665005600Z.
Information	10/8/2018 1:10:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{7310EDAB-CF37-47A9-B7CE-80CF3AD412B0}\DeviceManager.msi. Client Process Id: 14208.
Information	10/8/2018 1:10:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:40:42.665005600Z.
Information	10/8/2018 1:10:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{7310EDAB-CF37-47A9-B7CE-80CF3AD412B0}\DeviceManager.msi. Client Process Id: 14208.
Information	10/8/2018 1:10:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:40:29.702709500Z.
Information	10/8/2018 1:10:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BF22F109-3C85-4BB3-AC86-BCF304EEC77D}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 17352.
Information	10/8/2018 1:10:38 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 1:10:38 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/8/2018 1:10:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:40:29.702709500Z.
Information	10/8/2018 1:10:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BF22F109-3C85-4BB3-AC86-BCF304EEC77D}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 17352.
Information	10/8/2018 1:05:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:35:09.033645800Z.
Information	10/8/2018 1:05:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15904.
Information	10/8/2018 1:05:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 1:05:11 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/8/2018 1:05:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:35:09.033645800Z.
Information	10/8/2018 1:05:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15904.
Information	10/8/2018 1:05:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:34:59.793721900Z.
Information	10/8/2018 1:05:03 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15904.
Information	10/8/2018 1:05:03 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 1:05:03 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/8/2018 1:04:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:34:59.793721900Z.
Information	10/8/2018 1:04:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15904.
Error	10/8/2018 1:03:45 PM	Application Error	1000	(100)	"Faulting application name: DeviceManager.Api.exe, version: 0.0.0.0, time stamp: 0x5b36974f
Faulting module name: KERNELBASE.dll, version: 6.1.7601.24231, time stamp: 0x5b6db2d4
Exception code: 0xe0434352
Fault offset: 0x0000c54f
Faulting process id: 0x1cf4
Faulting application start time: 0x01d45ed93cf8ce45
Faulting application path: D:\4sightv2\publish\DeviceManager.Api.exe
Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report Id: 7cbae8fd-cacc-11e8-8fdc-204747d02364"
Error	10/8/2018 1:03:44 PM	.NET Runtime	1026	None	"Application: DeviceManager.Api.exe
CoreCLR Version: 4.6.26628.5
Description: The process was terminated due to an unhandled exception.
Exception Info: System.IO.IOException: Failed to bind to address http://127.0.0.1:9000: address already in use. ---> Microsoft.AspNetCore.Connections.AddressInUseException: Only one usage of each socket address (protocol/network address/port) is normally permitted ---> System.Net.Sockets.SocketException: Only one usage of each socket address (protocol/network address/port) is normally permitted
   at System.Net.Sockets.Socket.UpdateStatusAfterSocketErrorAndThrowException(SocketError error, String callerName)
   at System.Net.Sockets.Socket.DoBind(EndPoint endPointSnapshot, SocketAddress socketAddress)
   at System.Net.Sockets.Socket.Bind(EndPoint localEP)
   at Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets.SocketTransport.BindAsync()
   --- End of inner exception stack trace ---
   at Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets.SocketTransport.BindAsync()
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.<>c__DisplayClass22_0`1.<<StartAsync>g__OnBind|0>d.MoveNext()
--- End of stack trace from previous location where exception was thrown ---
   at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindEndpointAsync(ListenOptions endpoint, AddressBindContext context)
   --- End of inner exception stack trace ---
   at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindEndpointAsync(ListenOptions endpoint, AddressBindContext context)
   at Microsoft.AspNetCore.Server.Kestrel.Core.LocalhostListenOptions.BindAsync(AddressBindContext context)
   at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.EndpointsStrategy.BindAsync(AddressBindContext context)
   at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindAsync(IServerAddressesFeature addresses, KestrelServerOptions serverOptions, ILogger logger, Func`2 createBinding)
   at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServer.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken)
   at Microsoft.AspNetCore.Hosting.Internal.WebHost.StartAsync(CancellationToken cancellationToken)
   at Microsoft.AspNetCore.Hosting.WebHostExtensions.RunAsync(IWebHost host, CancellationToken token, String shutdownMessage)
   at Microsoft.AspNetCore.Hosting.WebHostExtensions.RunAsync(IWebHost host, CancellationToken token)
   at Microsoft.AspNetCore.Hosting.WebHostExtensions.Run(IWebHost host)
   at DeviceManager.Api.Program.RunInteractive(String[] args) in C:\4SightV2\CMS-DeviceManager\src\DeviceManager.Api\Program.cs:line 80
   at DeviceManager.Api.Program.Main(String[] args) in C:\4SightV2\CMS-DeviceManager\src\DeviceManager.Api\Program.cs:line 58
"
Information	10/8/2018 12:47:55 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 12:47:55 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/8/2018 12:47:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:17:24.769230000Z.
Information	10/8/2018 12:47:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B8C24687-4D2A-4D06-A72D-996587B7C32F}\DeviceManager.msi. Client Process Id: 12072.
Information	10/8/2018 12:47:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:17:24.769230000Z.
Information	10/8/2018 12:47:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B8C24687-4D2A-4D06-A72D-996587B7C32F}\DeviceManager.msi. Client Process Id: 12072.
Information	10/8/2018 12:47:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:17:11.353888600Z.
Information	10/8/2018 12:47:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0F9A357B-EB6A-4E62-9CE3-A0EDBAFDE8A4}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 11464.
Information	10/8/2018 12:47:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/8/2018 12:47:20 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/8/2018 12:47:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:17:11.353888600Z.
Information	10/8/2018 12:47:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0F9A357B-EB6A-4E62-9CE3-A0EDBAFDE8A4}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 11464.
Information	10/8/2018 12:45:33 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	10/8/2018 12:45:33 PM	MsiInstaller	11708	None	Product: DeviceManager -- Installation operation failed.
Information	10/8/2018 12:44:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:14:30.837838600Z.
Information	10/8/2018 12:44:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 13844.
Information	10/8/2018 12:44:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 12:44:36 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/8/2018 12:44:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:14:30.837838600Z.
Information	10/8/2018 12:44:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 13844.
Information	10/8/2018 12:44:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎08T07:14:10.379793000Z.
Information	10/8/2018 12:44:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 13844.
Information	10/8/2018 12:44:19 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/8/2018 12:44:19 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/8/2018 12:44:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎08T07:14:10.379793000Z.
Information	10/8/2018 12:44:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 13844.
Information	10/8/2018 12:37:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d37e78d5-cac8-11e8-8fdc-204747d02364
Report Status: 0"
Information	10/8/2018 12:23:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9039.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/8/2018 12:00:38 PM	MTAService.OnSessionChange	0	None	12:00:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/8/2018 11:51:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 11:50:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 11:50:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 11:50:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 11:44:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/8/2018 11:44:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/8/2018 11:44:10 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/8/2018 11:44:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 27644, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/8/2018 11:42:05 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/8/2018 11:42:05 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	10/8/2018 11:34:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 11:31:53 AM	MTAService.OnSessionChange	0	None	11:31:53 AM - Session change notice received: SessionLock Session ID: 1
Information	10/8/2018 11:30:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/8/2018 11:18:22 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/8/2018 11:11:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 11:06:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]

"
Information	10/8/2018 11:06:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 11:06:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]

"
Information	10/8/2018 11:06:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 11:05:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]

"
Information	10/8/2018 11:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 11:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]

"
Information	10/8/2018 11:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43609)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 11:05:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 11:05:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 11:05:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 11:03:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/8/2018 10:35:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 10:30:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43644)(?)])(1 )(2 )]

"
Information	10/8/2018 10:30:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 10:30:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43644)(?)])(1 )(2 )]

"
Information	10/8/2018 10:30:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43644)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 10:26:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43648)(?)])(1 )(2 )]

"
Information	10/8/2018 10:26:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2018 10:26:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43648)(?)])(1 )(2 )]

"
Information	10/8/2018 10:26:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 43648)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 10:26:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2018 10:26:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 10:26:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 10:07:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 10:07:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:04Z. Reason: GVLK.
Warning	10/8/2018 10:03:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 10:02:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 10:02:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 10:02:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 10:02:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 9:55:56 AM	MTAService.OnSessionChange	0	None	9:55:56 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/8/2018 9:16:23 AM	MTAService.OnSessionChange	0	None	9:16:23 AM - Session change notice received: SessionLock Session ID: 1
Information	10/8/2018 9:14:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/8/2018 9:14:26 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/8/2018 9:13:50 AM	MTAService.OnSessionChange	0	None	9:13:50 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/8/2018 8:27:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 7:50:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:50:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:50:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:50:09 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/8/2018 7:49:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 7:37:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e9b323e5-ca9e-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/8/2018 6:38:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 6:01:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 6:01:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:03Z. Reason: GVLK.
Information	10/8/2018 5:56:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 5:56:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 5:56:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 5:56:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/8/2018 4:52:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 4:21:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 4:21:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:20Z. Reason: GVLK.
Information	10/8/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 4:16:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/8/2018 4:13:46 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/8/2018 4:11:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2018 4:11:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:19Z. Reason: GVLK.
Error	10/8/2018 4:06:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/8/2018 4:06:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2018 4:06:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2018 4:06:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2018 4:06:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2018 3:50:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 3:50:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 3:49:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/8/2018 3:49:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/8/2018 3:06:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Thursday, September 27, 2018 2:29:55 AM.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Symantec Class 3 Public Primary Certification Authority - G6, OU=Symantec Trust Network, O=Symantec Corporation, C=US> Sha1 thumbprint: <26A16C235A2472229B23628025BC8097C88524A1>.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Global Chambersign Root, OU=http://www.chambersign.org, O=AC Camerfirma SA CIF A82743287, C=EU> Sha1 thumbprint: <339B6B1450249B557A01877284D9E02FC3D2D8E9>.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Global Chambersign Root - 2008, O=AC Camerfirma S.A., SERIALNUMBER=A82743287, L=Madrid (see current address at www.camerfirma.com/address), C=EU> Sha1 thumbprint: <4ABDEEEC950D359C89AEC752A12C5B29F6D6AA0C>.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU=""(c) 2006 VeriSign, Inc. - For authorized use only"", OU=VeriSign Trust Network, O=""VeriSign, Inc."", C=US> Sha1 thumbprint: <4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5>."
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Chambers of Commerce Root, OU=http://www.chambersign.org, O=AC Camerfirma SA CIF A82743287, C=EU> Sha1 thumbprint: <6E3A55A4190C195C93843CC0DB722E313061F0B1>.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Network Solutions Certificate Authority, O=Network Solutions L.L.C., C=US> Sha1 thumbprint: <71899A67BF33AF31BEFDC071F8F733B183856332>.
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=thawte Primary Root CA - G2, OU=""(c) 2007 thawte, Inc. - For authorized use only"", O=""thawte, Inc."", C=US> Sha1 thumbprint: <AADBBC22238FC401A127BB38DDF41DDB089EF012>."
Information	10/8/2018 2:50:44 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GeoTrust Universal CA, O=GeoTrust Inc., C=US> Sha1 thumbprint: <E621F3354379059A4B68309D8A2F74221587EC79>.
Information	10/8/2018 2:37:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 00077c65-ca75-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/8/2018 1:32:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/8/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/7/2018 11:51:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 11:50:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:50:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:49:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/7/2018 10:16:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 9:37:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 16721b61-ca4b-11e8-8fdc-204747d02364
Report Status: 0"
Information	10/7/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/7/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 44439)(?)])(1 )(2 )]

"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 44439)(?)])(1 )(2 )]

"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 44439)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/7/2018 8:41:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 7:50:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:50:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:50:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:50:05 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/7/2018 7:49:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/7/2018 6:54:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/7/2018 5:12:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 4:37:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2cbfe596-ca21-11e8-8fdc-204747d02364
Report Status: 0"
Information	10/7/2018 3:50:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 3:50:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 3:49:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 3:49:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/7/2018 3:26:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 3:07:08 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/7/2018 2:09:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2018 2:09:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:07Z. Reason: GVLK.
Information	10/7/2018 2:04:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2018 2:04:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 2:04:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 2:04:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/7/2018 1:43:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 12:16:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9038.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	10/7/2018 11:55:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 11:50:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:49:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:49:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:49:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 11:37:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 430d6efe-c9f7-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/7/2018 10:03:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/7/2018 8:12:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 7:49:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:49:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:49:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/7/2018 7:49:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 7:49:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 6:52:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2018 6:52:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:19Z. Reason: GVLK.
Information	10/7/2018 6:47:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2018 6:47:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 6:47:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 6:47:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/7/2018 6:39:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 6:37:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58d01da0-c9cd-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/7/2018 4:43:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 4:24:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2018 4:24:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:31Z. Reason: GVLK.
Information	10/7/2018 4:19:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2018 4:19:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 4:19:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 4:19:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/7/2018 3:49:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 3:49:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2018 3:43:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2018 3:43:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:28Z. Reason: GVLK.
Information	10/7/2018 3:38:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2018 3:38:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 3:38:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 3:38:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/7/2018 3:36:43 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/7/2018 3:34:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2018 3:34:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:01Z. Reason: GVLK.
Error	10/7/2018 3:29:11 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/7/2018 3:29:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2018 3:29:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2018 3:29:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2018 3:29:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/7/2018 3:10:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 1:37:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6f0a5a60-c9a3-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/7/2018 1:31:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/6/2018 11:57:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 11:49:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 11:49:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/6/2018 10:13:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 9:45:24 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/6/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/6/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 45879)(?)])(1 )(2 )]

"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 45879)(?)])(1 )(2 )]

"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 45879)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2018 8:37:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 855a7303-c979-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/6/2018 8:37:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 7:49:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 7:49:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/6/2018 7:49:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/6/2018 6:57:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/6/2018 5:01:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 3:49:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 3:48:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 3:37:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9bae76d4-c94f-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/6/2018 3:01:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 2:22:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2018 2:22:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:19Z. Reason: GVLK.
Information	10/6/2018 2:15:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2018 2:15:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2018 2:15:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2018 2:15:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/6/2018 1:06:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 12:19:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9037.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/6/2018 11:49:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 11:48:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 11:48:47 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/6/2018 11:48:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/6/2018 11:33:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 10:37:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1cd8c6b-c925-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/6/2018 9:45:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/6/2018 8:10:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 7:49:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 7:48:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 7:48:45 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/6/2018 7:48:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/6/2018 6:12:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 5:37:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c84d955c-c8fb-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/6/2018 4:28:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 3:48:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 3:48:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2018 3:25:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2018 3:25:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:31Z. Reason: GVLK.
Information	10/6/2018 3:20:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2018 3:20:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2018 3:20:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2018 3:20:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/6/2018 3:18:48 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/6/2018 3:13:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2018 3:13:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:48Z. Reason: GVLK.
Error	10/6/2018 3:09:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/6/2018 3:08:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2018 3:08:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2018 3:08:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2018 3:08:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/6/2018 2:51:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/6/2018 12:52:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/6/2018 12:46:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2018 12:46:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:05Z. Reason: GVLK.
Information	10/6/2018 12:41:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2018 12:41:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2018 12:41:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2018 12:41:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/6/2018 12:37:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de9980e1-c8d1-11e8-8fdc-204747d02364
Report Status: 0"
Information	10/6/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/5/2018 11:48:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 11:48:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/5/2018 11:21:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 10:13:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 10:13:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:40Z. Reason: GVLK.
Information	10/5/2018 10:08:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 10:08:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:08:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:08:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/5/2018 9:36:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 9:22:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/5/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/5/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47319)(?)])(1 )(2 )]

"
Information	10/5/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47319)(?)])(1 )(2 )]

"
Information	10/5/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47319)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/5/2018 8:02:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 7:48:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 7:48:20 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/5/2018 7:48:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 7:37:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4e19aec-c8a7-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/5/2018 6:05:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 4:50:36 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/5/2018 4:25:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 4:05:45 PM	MTAService.OnSessionChange	0	None	4:05:45 PM - Session change notice received: SessionLock Session ID: 1
Information	10/5/2018 3:48:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 2:37:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0b4126af-c87e-11e8-8fdc-204747d02364
Report Status: 0"
Warning	10/5/2018 2:27:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 2:23:51 PM	MTAService.OnSessionChange	0	None	2:23:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/5/2018 1:10:21 PM	MTAService.OnSessionChange	0	None	1:10:21 PM - Session change notice received: SessionLock Session ID: 1
Warning	10/5/2018 12:37:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 12:25:45 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/5/2018 12:25:45 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/5/2018 12:25:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:55:13.758648700Z.
Information	10/5/2018 12:25:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{50B19412-2002-405C-B887-206C56826F57}\DeviceManager.msi. Client Process Id: 7088.
Information	10/5/2018 12:25:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:55:13.758648700Z.
Information	10/5/2018 12:25:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{50B19412-2002-405C-B887-206C56826F57}\DeviceManager.msi. Client Process Id: 7088.
Information	10/5/2018 12:25:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:53:23.285648700Z.
Information	10/5/2018 12:25:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{38FFC9E2-9B64-4060-BD27-3EA507A0E2F2}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 8644.
Information	10/5/2018 12:25:09 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/5/2018 12:25:09 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/5/2018 12:23:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:53:23.285648700Z.
Information	10/5/2018 12:23:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{38FFC9E2-9B64-4060-BD27-3EA507A0E2F2}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 8644.
Information	10/5/2018 12:21:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:51:29.353648700Z.
Information	10/5/2018 12:21:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 12:21:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/5/2018 12:21:36 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/5/2018 12:21:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:51:29.353648700Z.
Information	10/5/2018 12:21:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 12:20:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 12:20:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:39Z. Reason: GVLK.
Information	10/5/2018 12:15:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 12:15:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 12:15:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 12:15:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 12:04:53 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/5/2018 12:04:53 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/5/2018 12:04:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:34:30.303415400Z.
Information	10/5/2018 12:04:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{655C243D-EBFF-4740-9811-CCB3D9F930A4}\DeviceManager.msi. Client Process Id: 8988.
Information	10/5/2018 12:04:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:34:30.303415400Z.
Information	10/5/2018 12:04:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{655C243D-EBFF-4740-9811-CCB3D9F930A4}\DeviceManager.msi. Client Process Id: 8988.
Information	10/5/2018 12:03:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9036.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/5/2018 11:53:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 11:52:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 2, Deleted: 0, Modified: 27, Compared: 27619, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/5/2018 11:50:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 11:50:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:38Z. Reason: GVLK.
Information	10/5/2018 11:49:05 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:18:58.824276800Z.
Information	10/5/2018 11:49:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 11:49:05 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/5/2018 11:49:05 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/5/2018 11:48:58 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:18:58.824276800Z.
Information	10/5/2018 11:48:56 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 11:48:44 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/5/2018 11:48:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/5/2018 11:48:34 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 141

Information	10/5/2018 11:48:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 11:47:28 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/5/2018 11:47:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47887)(?)])(1 )(2 )]

"
Information	10/5/2018 11:47:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2018 11:47:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47887)(?)])(1 )(2 )]

"
Information	10/5/2018 11:47:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47888)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 11:47:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2018 11:47:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 11:47:04 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 11:45:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 11:45:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 11:45:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 11:45:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 11:30:21 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/5/2018 11:30:21 AM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/5/2018 11:30:17 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T06:00:03.929382100Z.
Information	10/5/2018 11:30:17 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{40DE8BFA-FD12-44B0-A859-48EDD0C56273}\DeviceManager.msi. Client Process Id: 10960.
Information	10/5/2018 11:30:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T06:00:03.929382100Z.
Information	10/5/2018 11:30:03 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{40DE8BFA-FD12-44B0-A859-48EDD0C56273}\DeviceManager.msi. Client Process Id: 10960.
Information	10/5/2018 11:26:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T05:56:02.773056900Z.
Information	10/5/2018 11:26:09 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 11:26:09 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/5/2018 11:26:09 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/5/2018 11:26:02 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T05:56:02.773056900Z.
Information	10/5/2018 11:26:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 2276.
Information	10/5/2018 11:22:27 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	10/5/2018 11:20:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 11:20:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:39Z. Reason: GVLK.
Information	10/5/2018 11:15:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 11:15:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 11:15:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 11:15:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 11:11:38 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10715. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/5/2018 11:11:38 AM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/5/2018 11:11:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎05T05:41:13.981566500Z.
Information	10/5/2018 11:11:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{51199DFE-982F-4909-96AB-4FCC48EAE5A0}\DeviceManager.msi. Client Process Id: 8684.
Information	10/5/2018 11:11:13 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎05T05:41:13.981566500Z.
Information	10/5/2018 11:11:13 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{51199DFE-982F-4909-96AB-4FCC48EAE5A0}\DeviceManager.msi. Client Process Id: 8684.
Information	10/5/2018 11:10:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 11:10:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:49Z. Reason: GVLK.
Information	10/5/2018 11:08:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 11:04:55 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/5/2018 11:03:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	10/5/2018 11:03:29 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 11:03:28 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 11:03:26 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 11:03:25 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/5/2018 11:03:08 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	10/5/2018 11:03:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/5/2018 11:03:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47932)(?)])(1 )(2 )]

"
Information	10/5/2018 11:03:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2018 11:03:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47932)(?)])(1 )(2 )]

"
Information	10/5/2018 11:03:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 11:03:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 11:03:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47932)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 11:03:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 11:03:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2018 11:03:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 11:02:59 AM	ESENT	302	Logging/Recovery	Windows (8616) Windows: The database engine has successfully completed recovery steps.
Information	10/5/2018 11:02:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 11:02:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 11:02:51 AM	ESENT	301	Logging/Recovery	Windows (8616) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/5/2018 11:02:51 AM	ESENT	300	Logging/Recovery	Windows (8616) Windows: The database engine is initiating recovery steps.
Information	10/5/2018 11:02:51 AM	ESENT	102	General	Windows (8616) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/5/2018 11:02:45 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9035.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/5/2018 11:00:37 AM	MTAService	0	None	Service started successfully.
Error	10/5/2018 11:00:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/5/2018 11:00:28 AM	Service1	0	None	Service started successfully.
Error	10/5/2018 11:00:20 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/5/2018 11:00:06 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/5/2018 11:00:05 AM	PostgreSQL	0	None	"2018-10-05 11:00:05 IST LOG:  redirecting log output to logging collector process
2018-10-05 11:00:05 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/5/2018 11:00:04 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/5/2018 11:00:02 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/5/2018 11:00:02 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/5/2018 11:00:01 AM	MTAService.OnStart	0	None	11:00:01 AM - User is already logged in : 212558710
Information	10/5/2018 10:59:44 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/5/2018 10:59:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/5/2018 10:59:39 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/5/2018 10:59:39 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/5/2018 10:59:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/5/2018 10:59:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/5/2018 10:59:32 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/5/2018 10:59:31 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4268 at 10/5/2018 10:56:17 AM (local) 10/5/2018 5:26:17 AM (UTC). This is an informational message only; no user action is required.
Information	10/5/2018 10:59:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/5/2018 10:59:26 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/5/2018 10:59:26 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/5/2018 10:59:26 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/5/2018 10:59:26 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/5/2018 10:59:26 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4348.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/5/2018 10:59:23 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/5/2018 10:58:16 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/5/2018 10:58:04 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 10:57:51 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/5/2018 10:57:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/5/2018 10:57:51 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/5/2018 10:56:23 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/5/2018 10:56:17 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/5/2018 10:56:03 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 712 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2216 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/5/2018 10:56:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/5/2018 10:56:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/5/2018 10:56:02 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/5/2018 10:55:57 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/5/2018 10:55:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 10:55:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:55:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:55:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 10:55:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 10:55:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:30Z. Reason: GVLK.
Information	10/5/2018 10:54:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 10:50:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	10/5/2018 10:49:35 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	10/5/2018 10:49:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/5/2018 10:49:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/5/2018 10:49:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47946)(?)])(1 )(2 )]

"
Information	10/5/2018 10:49:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2018 10:49:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47946)(?)])(1 )(2 )]

"
Information	10/5/2018 10:49:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 47946)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:48:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2018 10:48:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:48:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 10:48:54 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 10:48:53 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 10:48:52 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 10:48:51 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/5/2018 10:48:29 AM	ESENT	302	Logging/Recovery	Windows (8600) Windows: The database engine has successfully completed recovery steps.
Information	10/5/2018 10:48:27 AM	ESENT	301	Logging/Recovery	Windows (8600) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/5/2018 10:48:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 10:48:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:48:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:48:14 AM	ESENT	301	Logging/Recovery	Windows (8600) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0128B.log.
Information	10/5/2018 10:48:14 AM	ESENT	300	Logging/Recovery	Windows (8600) Windows: The database engine is initiating recovery steps.
Information	10/5/2018 10:48:13 AM	ESENT	102	General	Windows (8600) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/5/2018 10:48:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 10:47:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9035.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/5/2018 10:47:27 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	10/5/2018 10:46:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/5/2018 10:46:39 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/5/2018 10:46:21 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/5/2018 10:46:19 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/5/2018 10:46:19 AM	PostgreSQL	0	None	"2018-10-05 10:46:19 IST LOG:  redirecting log output to logging collector process
2018-10-05 10:46:19 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/5/2018 10:46:17 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/5/2018 10:46:09 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/5/2018 10:46:09 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/5/2018 10:46:09 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/5/2018 10:46:09 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/5/2018 10:46:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/5/2018 10:46:08 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/5/2018 10:46:08 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/5/2018 10:46:08 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/5/2018 10:46:07 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/5/2018 10:45:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/5/2018 10:45:56 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/5/2018 10:45:56 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/5/2018 10:45:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/5/2018 10:45:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/5/2018 10:45:37 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/5/2018 10:45:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/5/2018 10:45:37 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4952 at 10/5/2018 10:41:28 AM (local) 10/5/2018 5:11:28 AM (UTC). This is an informational message only; no user action is required.
Information	10/5/2018 10:45:36 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/5/2018 10:45:16 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/5/2018 10:45:16 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/5/2018 10:45:16 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/5/2018 10:45:16 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/5/2018 10:45:16 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4268.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/5/2018 10:45:07 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/5/2018 10:43:44 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/5/2018 10:43:35 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2018 10:43:16 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/5/2018 10:43:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/5/2018 10:43:16 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/5/2018 10:41:28 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/5/2018 10:41:23 AM	McLogEvent	257	None	The scan of C:\Windows\System32\nlasvc.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 9035.0000.
Warning	10/5/2018 10:41:18 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 4980 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Warning	10/5/2018 10:41:17 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2396 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1052 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 188 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2084 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/5/2018 10:41:18 AM	MTAService.OnSessionChange	0	None	10:41:18 AM - Logoff
Information	10/5/2018 10:41:18 AM	MTAService.OnSessionChange	0	None	10:41:18 AM - Session change notice received: SessionLogoff Session ID: 1
Information	10/5/2018 10:41:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/5/2018 10:41:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/5/2018 10:41:13 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/5/2018 10:41:03 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/5/2018 10:31:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 10:31:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:06:00Z. Reason: GVLK.
Information	10/5/2018 10:26:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 10:25:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:25:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:25:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2018 10:18:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 10:18:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:49Z. Reason: GVLK.
Information	10/5/2018 10:13:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 10:13:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 10:13:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 10:13:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/5/2018 10:05:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 9:56:26 AM	MTAService.OnSessionChange	0	None	9:56:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/5/2018 9:37:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 218d5c0e-c854-11e8-b79e-204747d02364
Report Status: 0"
Information	10/5/2018 9:36:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 9:19:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 9:19:37 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/5/2018 9:19:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 8:55:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/5/2018 8:55:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/5/2018 8:12:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 7:56:17 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/5/2018 6:30:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 6:30:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:49Z. Reason: GVLK.
Information	10/5/2018 6:25:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 6:25:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 6:25:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 6:25:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/5/2018 6:16:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 5:35:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 5:19:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 4:37:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37ecc0f4-c82a-11e8-b79e-204747d02364
Report Status: 0"
Information	10/5/2018 4:36:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 4:36:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:36Z. Reason: GVLK.
Information	10/5/2018 4:31:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 4:31:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 4:31:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 4:31:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/5/2018 4:29:38 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/5/2018 4:26:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2018 4:26:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:39Z. Reason: GVLK.
Error	10/5/2018 4:21:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/5/2018 4:21:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2018 4:21:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2018 4:21:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2018 4:21:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/5/2018 4:19:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/5/2018 2:31:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/5/2018 1:35:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2018 1:19:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	10/5/2018 12:58:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 11:37:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e34e5b4-c800-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/4/2018 11:20:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 11:12:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 11:12:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:56Z. Reason: GVLK.
Information	10/4/2018 11:07:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2018 11:07:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 11:07:55 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 11:07:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/4/2018 9:48:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 9:35:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 9:23:40 PM	MTAService.OnSessionChange	0	None	9:23:40 PM - Session change notice received: SessionLock Session ID: 1
Information	10/4/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 9:19:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 9:19:26 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/4/2018 9:19:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	10/4/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/4/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 48759)(?)])(1 )(2 )]

"
Information	10/4/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 48759)(?)])(1 )(2 )]

"
Information	10/4/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 48759)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/4/2018 7:52:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 7:15:39 PM	MTAService.OnSessionChange	0	None	7:15:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 6:41:24 PM	MTAService.OnSessionChange	0	None	6:41:24 PM - Session change notice received: SessionLock Session ID: 1
Information	10/4/2018 6:37:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 647fe816-c7d6-11e8-b79e-204747d02364
Report Status: 0"
Information	10/4/2018 6:27:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	10/4/2018 6:20:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 5:56:14 PM	MTAService.OnSessionChange	0	None	5:56:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 5:35:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 5:19:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 5:10:00 PM	MTAService.OnSessionChange	0	None	5:10:00 PM - Session change notice received: SessionLock Session ID: 1
Information	10/4/2018 4:56:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/4/2018 4:56:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	10/4/2018 4:44:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 3:29:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 3:29:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:47Z. Reason: GVLK.
Information	10/4/2018 3:24:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2018 3:24:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 3:24:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 3:24:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/4/2018 2:55:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 2:16:05 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/4/2018 2:13:25 PM	MTAService.OnSessionChange	0	None	2:13:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 1:37:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7ab5e3ef-c7ac-11e8-b79e-204747d02364
Report Status: 0"
Information	10/4/2018 1:35:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 1:30:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/4/2018 1:18:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 1:14:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 1:10:42 PM	MTAService.OnSessionChange	0	None	1:10:42 PM - Session change notice received: SessionLock Session ID: 1
Information	10/4/2018 1:09:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49246)(?)])(1 )(2 )]

"
Information	10/4/2018 1:08:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 1:08:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49246)(?)])(1 )(2 )]

"
Information	10/4/2018 1:08:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49246)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 1:08:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2018 1:08:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 1:08:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/4/2018 1:08:26 PM	MTAService.OnSessionChange	0	None	1:08:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 1:02:40 PM	MTAService.OnSessionChange	0	None	1:02:40 PM - Session change notice received: SessionLock Session ID: 1
Warning	10/4/2018 12:59:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 12:54:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9035.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/4/2018 12:38:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 12:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49281)(?)])(1 )(2 )]

"
Information	10/4/2018 12:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 12:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49281)(?)])(1 )(2 )]

"
Information	10/4/2018 12:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 12:32:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49282)(?)])(1 )(2 )]

"
Information	10/4/2018 12:32:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 12:32:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49282)(?)])(1 )(2 )]

"
Information	10/4/2018 12:32:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49282)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 12:32:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2018 12:32:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 12:32:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/4/2018 11:46:00 AM	MTAService.OnSessionChange	0	None	11:46:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 11:30:52 AM	MTAService.OnSessionChange	0	None	11:30:52 AM - Session change notice received: SessionLock Session ID: 1
Warning	10/4/2018 11:11:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 10:10:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 10:05:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49429)(?)])(1 )(2 )]

"
Information	10/4/2018 10:05:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 10:05:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49429)(?)])(1 )(2 )]

"
Information	10/4/2018 10:05:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49429)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 10:05:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2018 10:05:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 10:05:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/4/2018 9:57:26 AM	MTAService.OnSessionChange	0	None	9:57:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 9:48:43 AM	MTAService.OnSessionChange	0	None	9:48:43 AM - Session change notice received: SessionLock Session ID: 1
Information	10/4/2018 9:35:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 9:35:11 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	10/4/2018 9:27:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 9:23:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 9:18:57 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 343

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 561

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 32

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 250

Information	10/4/2018 9:18:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2018 9:18:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49476)(?)])(1 )(2 )]

"
Information	10/4/2018 9:18:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2018 9:18:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49476)(?)])(1 )(2 )]

"
Information	10/4/2018 9:18:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 49476)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 9:18:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2018 9:18:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 9:18:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/4/2018 9:18:14 AM	MTAService.OnSessionChange	0	None	9:18:14 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/4/2018 8:37:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 90ca6a6d-c782-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/4/2018 7:51:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/4/2018 5:55:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 5:07:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 5:07:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:50Z. Reason: GVLK.
Information	10/4/2018 5:02:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2018 5:02:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 5:02:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 5:02:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/4/2018 5:01:10 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/4/2018 4:59:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2018 4:59:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:23Z. Reason: GVLK.
Error	10/4/2018 4:54:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/4/2018 4:54:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2018 4:54:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2018 4:54:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2018 4:54:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/4/2018 4:00:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 3:37:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a7126085-c758-11e8-b79e-204747d02364
Report Status: 0"
Information	10/4/2018 2:19:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/4/2018 2:17:08 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	10/4/2018 2:10:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/4/2018 12:37:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/4/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/3/2018 11:06:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 10:37:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bd40e63c-c72e-11e8-b79e-204747d02364
Report Status: 0"
Information	10/3/2018 9:30:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 9:30:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:43Z. Reason: GVLK.
Information	10/3/2018 9:25:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 9:25:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:25:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 9:25:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 9:21:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/3/2018 9:16:05 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/3/2018 9:16:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50199)(?)])(1 )(2 )]

"
Information	10/3/2018 9:16:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50199)(?)])(1 )(2 )]

"
Information	10/3/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50199)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:16:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2018 9:16:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 9:16:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/3/2018 9:08:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 7:38:27 PM	MTAService.OnSessionChange	0	None	7:38:27 PM - Session change notice received: SessionLock Session ID: 1
Warning	10/3/2018 7:31:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 7:29:14 PM	MTAService.OnSessionChange	0	None	7:29:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 7:26:45 PM	MTAService.OnSessionChange	0	None	7:26:45 PM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 6:25:34 PM	MTAService.OnSessionChange	0	None	6:25:34 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	10/3/2018 5:57:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 5:36:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d380cf9a-c704-11e8-b79e-204747d02364
Report Status: 0"
Information	10/3/2018 5:31:23 PM	MTAService.OnSessionChange	0	None	5:31:23 PM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 5:21:40 PM	MTAService.OnSessionChange	0	None	5:21:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 5:15:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 5:14:30 PM	MTAService.OnSessionChange	0	None	5:14:30 PM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 5:10:13 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 281

Information	10/3/2018 5:09:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2018 5:09:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50446)(?)])(1 )(2 )]

"
Information	10/3/2018 5:09:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2018 5:09:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50446)(?)])(1 )(2 )]

"
Information	10/3/2018 5:09:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50446)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 5:09:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2018 5:09:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 5:09:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/3/2018 4:01:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 3:38:40 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 14586 milliseconds
Information	10/3/2018 3:25:21 PM	MTAService.OnSessionChange	0	None	3:25:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 3:18:16 PM	MTAService.OnSessionChange	0	None	3:18:16 PM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 2:50:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 2:45:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50589)(?)])(1 )(2 )]

"
Information	10/3/2018 2:45:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2018 2:45:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50589)(?)])(1 )(2 )]

"
Information	10/3/2018 2:45:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50589)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 2:45:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2018 2:45:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 2:45:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 2:45:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎03T09:15:24.039743200Z.
Information	10/3/2018 2:45:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 1084.
Information	10/3/2018 2:45:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10518. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/3/2018 2:45:38 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/3/2018 2:45:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎03T09:15:24.039743200Z.
Information	10/3/2018 2:45:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 1084.
Information	10/3/2018 2:45:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎10‎-‎03T09:14:58.557195200Z.
Information	10/3/2018 2:45:15 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 1084.
Information	10/3/2018 2:45:15 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.4.0.10518. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/3/2018 2:45:15 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/3/2018 2:44:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎10‎-‎03T09:14:58.557195200Z.
Information	10/3/2018 2:44:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 1084.
Warning	10/3/2018 2:28:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 2:21:17 PM	MTAService.OnSessionChange	0	None	2:21:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 1:42:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 1:42:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:21Z. Reason: GVLK.
Information	10/3/2018 1:37:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 1:37:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 1:37:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 1:37:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 1:27:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 20764.
Information	10/3/2018 1:27:27 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20071. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	10/3/2018 1:27:27 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	10/3/2018 1:27:27 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20071. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (19.008.20071). Installation success or error status: 0.
Information	10/3/2018 1:27:27 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (19.008.20071)' installed successfully.
Information	10/3/2018 1:25:13 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/3/2018 1:24:45 PM	ESENT	102	General	Windows (20752) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	10/3/2018 1:24:07 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/3/2018 1:24:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/3/2018 1:23:45 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/3/2018 1:23:45 PM	ESENT	103	General	Windows (10824) Windows: The database engine stopped the instance (0).
Information	10/3/2018 1:23:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 20764.
Information	10/3/2018 1:23:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15512.
Information	10/3/2018 1:23:23 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 19.008.20071. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	10/3/2018 1:23:23 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	10/3/2018 1:23:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15512.
Information	10/3/2018 1:15:28 PM	MTAService.OnSessionChange	0	None	1:15:28 PM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 1:08:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2018 1:08:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2018 12:52:20 PM	MTAService.OnSessionChange	0	None	12:52:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 12:48:59 PM	MTAService.OnSessionChange	0	None	12:48:59 PM - Session change notice received: SessionLock Session ID: 1
Warning	10/3/2018 12:41:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 12:36:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e28a5e51-c6da-11e8-b79e-204747d02364
Report Status: 0"
Information	10/3/2018 12:15:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9034.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	10/3/2018 11:43:33 AM	MTAService.OnSessionChange	0	None	11:43:33 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 11:30:41 AM	MTAService.OnSessionChange	0	None	11:30:41 AM - Session change notice received: SessionLock Session ID: 1
Warning	10/3/2018 11:08:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 11:03:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 11:03:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:56Z. Reason: GVLK.
Information	10/3/2018 10:58:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 10:58:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 10:58:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 10:58:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 10:49:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 10:44:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50830)(?)])(1 )(2 )]

"
Information	10/3/2018 10:44:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2018 10:44:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50830)(?)])(1 )(2 )]

"
Information	10/3/2018 10:44:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50830)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 10:44:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2018 10:44:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 10:44:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 9:53:45 AM	MTAService.OnSessionChange	0	None	9:53:45 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 9:41:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 9:41:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-10T04:05:10Z. Reason: GVLK.
Information	10/3/2018 9:36:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:36:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:36:10 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/10/03 04:06"
Information	10/3/2018 9:36:09 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/10/03 04:06, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/3/2018 9:31:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 9:31:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:31:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 9:31:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 9:28:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/3/2018 9:28:10 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/3/2018 9:28:10 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/3/2018 9:27:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 27530, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	10/3/2018 9:26:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/3/2018 9:26:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	10/3/2018 9:19:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 9:15:32 AM	MTAService.OnSessionChange	0	None	9:15:32 AM - Session change notice received: SessionLock Session ID: 1
Information	10/3/2018 9:13:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 9:09:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/3/2018 9:08:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/3/2018 9:08:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2018 9:08:43 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/3/2018 9:08:43 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/3/2018 9:08:42 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 1029

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 671

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1014

Information	10/3/2018 9:08:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2018 9:07:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50927)(?)])(1 )(2 )]

"
Information	10/3/2018 9:07:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2018 9:07:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50927)(?)])(1 )(2 )]

"
Information	10/3/2018 9:07:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 50927)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 9:07:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2018 9:07:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 9:07:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/3/2018 9:07:06 AM	MTAService.OnSessionChange	0	None	9:07:06 AM - Session change notice received: SessionUnlock Session ID: 1
Information	10/3/2018 7:36:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f8b4df30-c6b0-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/3/2018 7:30:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/3/2018 5:35:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 4:58:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 4:58:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:05Z. Reason: GVLK.
Information	10/3/2018 4:53:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 4:53:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 4:53:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 4:53:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/3/2018 4:51:17 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/3/2018 4:49:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2018 4:49:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:05Z. Reason: GVLK.
Error	10/3/2018 4:44:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/3/2018 4:44:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2018 4:44:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2018 4:44:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2018 4:44:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/3/2018 4:00:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 2:36:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0efa44be-c687-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/3/2018 2:21:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/3/2018 12:30:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/3/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/2/2018 10:36:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 9:36:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 255bdfc1-c65d-11e8-b79e-204747d02364
Report Status: 0"
Information	10/2/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/2/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 51639)(?)])(1 )(2 )]

"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 51639)(?)])(1 )(2 )]

"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 51639)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/2/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	10/2/2018 8:47:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 8:23:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 8:23:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:31Z. Reason: GVLK.
Information	10/2/2018 8:18:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 8:18:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 8:18:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 8:18:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/2/2018 6:46:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/2/2018 5:15:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 4:36:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3bbf0551-c633-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/2/2018 3:44:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/2/2018 1:57:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 12:25:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9033.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	10/2/2018 12:07:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 11:36:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 51f21568-c609-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/2/2018 10:17:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 9:28:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 9:28:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:52Z. Reason: GVLK.
Information	10/2/2018 9:23:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 9:23:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 9:23:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 9:23:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/2/2018 8:22:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/2/2018 6:38:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 6:38:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 6:38:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:10Z. Reason: GVLK.
Information	10/2/2018 6:36:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6662fd18-c5df-11e8-b79e-204747d02364
Report Status: 0"
Information	10/2/2018 6:33:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 6:33:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 6:33:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 6:33:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/2/2018 4:39:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 4:09:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 4:09:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:52Z. Reason: GVLK.
Information	10/2/2018 4:04:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 4:04:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 4:04:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 4:04:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/2/2018 4:02:59 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/2/2018 3:59:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 3:59:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:45Z. Reason: GVLK.
Error	10/2/2018 3:55:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/2/2018 3:54:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 3:54:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 3:54:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 3:54:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2018 3:19:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2018 3:19:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:30Z. Reason: GVLK.
Information	10/2/2018 3:14:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2018 3:14:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2018 3:14:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2018 3:14:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/2/2018 3:07:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 1:36:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7cb886b1-c5b5-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/2/2018 1:11:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/2/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	10/1/2018 11:21:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 9:43:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/1/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	10/1/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 53079)(?)])(1 )(2 )]

"
Information	10/1/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/1/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 53079)(?)])(1 )(2 )]

"
Information	10/1/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 53079)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/1/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/1/2018 8:36:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 930d1da3-c58b-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/1/2018 8:12:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 6:21:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 4:23:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 3:36:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9512273-c561-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/1/2018 2:41:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 12:52:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 12:36:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2018 12:36:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:25Z. Reason: GVLK.
Information	10/1/2018 12:31:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2018 12:31:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2018 12:31:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2018 12:31:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/1/2018 12:30:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9032.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	10/1/2018 11:20:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 10:36:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bf6b0f57-c537-11e8-b79e-204747d02364
Report Status: 0"
Warning	10/1/2018 9:24:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 7:42:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 5:48:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 5:36:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5ab92c5-c50d-11e8-b79e-204747d02364
Report Status: 0"
Information	10/1/2018 5:09:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2018 5:09:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:56Z. Reason: GVLK.
Information	10/1/2018 5:04:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2018 5:04:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2018 5:04:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2018 5:04:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/1/2018 5:03:01 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/1/2018 5:00:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2018 5:00:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:14Z. Reason: GVLK.
Error	10/1/2018 4:55:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/1/2018 4:55:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2018 4:55:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2018 4:55:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2018 4:55:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/1/2018 4:16:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	10/1/2018 2:29:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 1:48:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2018 1:48:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:21Z. Reason: GVLK.
Information	10/1/2018 1:43:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2018 1:43:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2018 1:43:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2018 1:43:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	10/1/2018 12:49:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	10/1/2018 12:36:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ebf5d174-c4e3-11e8-b79e-204747d02364
Report Status: 0"
Information	10/1/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/30/2018 10:56:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/30/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/30/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 54519)(?)])(1 )(2 )]

"
Information	9/30/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/30/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 54519)(?)])(1 )(2 )]

"
Information	9/30/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 54519)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/30/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/30/2018 9:06:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 7:36:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0248a4da-c4ba-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/30/2018 7:28:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/30/2018 5:30:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/30/2018 3:42:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 2:36:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 186e253f-c490-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/30/2018 1:53:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 12:28:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9031.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	9/30/2018 12:09:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 11:38:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 11:38:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:15Z. Reason: GVLK.
Information	9/30/2018 11:33:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 11:33:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 11:33:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 11:33:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/30/2018 10:32:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 9:53:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 9:53:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:22Z. Reason: GVLK.
Information	9/30/2018 9:48:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 9:48:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 9:48:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 9:48:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2018 9:42:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 9:42:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:34Z. Reason: GVLK.
Information	9/30/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2018 9:36:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2eb955ff-c466-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/30/2018 8:42:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/30/2018 6:49:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 5:18:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 5:18:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:15Z. Reason: GVLK.
Information	9/30/2018 5:13:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 5:13:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 5:13:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 5:13:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/30/2018 5:07:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 4:36:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 450eb5d4-c43c-11e8-b79e-204747d02364
Report Status: 0"
Information	9/30/2018 3:48:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 3:48:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:24Z. Reason: GVLK.
Information	9/30/2018 3:43:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 3:43:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 3:43:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 3:43:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/30/2018 3:41:33 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/30/2018 3:39:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2018 3:39:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:22Z. Reason: GVLK.
Error	9/30/2018 3:34:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/30/2018 3:34:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2018 3:34:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2018 3:34:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2018 3:34:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/30/2018 3:19:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/30/2018 1:48:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/30/2018 12:05:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/30/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/29/2018 11:36:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b589cd5-c412-11e8-b79e-204747d02364
Report Status: 0"
Information	9/29/2018 10:49:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2018 10:49:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:15Z. Reason: GVLK.
Information	9/29/2018 10:44:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2018 10:44:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2018 10:44:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2018 10:44:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/29/2018 10:17:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/29/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 55959)(?)])(1 )(2 )]

"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 55959)(?)])(1 )(2 )]

"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 55959)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/29/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/29/2018 8:43:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/29/2018 6:49:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 6:36:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71cae975-c3e8-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/29/2018 5:06:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 3:32:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2018 3:32:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:30Z. Reason: GVLK.
Information	9/29/2018 3:27:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2018 3:27:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2018 3:27:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2018 3:27:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/29/2018 3:19:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 1:49:14 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/29/2018 1:36:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 882bfc1c-c3be-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/29/2018 1:24:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 12:51:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9030.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	9/29/2018 11:48:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/29/2018 9:50:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 8:36:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e6f64ac-c394-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/29/2018 7:52:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/29/2018 6:00:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 5:00:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2018 5:00:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:22Z. Reason: GVLK.
Information	9/29/2018 4:55:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2018 4:55:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2018 4:55:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2018 4:55:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/29/2018 4:53:27 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/29/2018 4:50:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2018 4:50:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:20Z. Reason: GVLK.
Error	9/29/2018 4:45:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/29/2018 4:45:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2018 4:45:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2018 4:45:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2018 4:45:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/29/2018 4:15:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/29/2018 3:36:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b4d1d5ae-c36a-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/29/2018 2:31:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/29/2018 1:00:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/28/2018 11:11:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 10:36:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb312c86-c340-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/28/2018 9:25:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/28/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57399)(?)])(1 )(2 )]

"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57399)(?)])(1 )(2 )]

"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57399)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2018 8:46:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 8:46:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:15Z. Reason: GVLK.
Information	9/28/2018 8:41:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 8:41:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 8:41:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 8:41:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/28/2018 7:48:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 7:43:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 7:43:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:43Z. Reason: GVLK.
Information	9/28/2018 7:38:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 7:38:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 7:38:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 7:38:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/28/2018 5:56:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 5:36:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e16b8c4d-c316-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/28/2018 4:06:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 3:28:37 PM	MTAService.OnSessionChange	0	None	3:28:37 PM - Session change notice received: SessionLock Session ID: 1
Information	9/28/2018 3:15:32 PM	MTAService.OnSessionChange	0	None	3:15:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/28/2018 3:13:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 3:11:45 PM	MTAService.OnSessionChange	0	None	3:11:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/28/2018 3:08:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57766)(?)])(1 )(2 )]

"
Information	9/28/2018 3:08:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2018 3:08:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57766)(?)])(1 )(2 )]

"
Information	9/28/2018 3:08:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57766)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 3:08:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2018 3:08:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 3:08:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/28/2018 2:15:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 2:09:59 PM	MTAService.OnSessionChange	0	None	2:09:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/28/2018 1:48:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 1:48:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 1:48:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 12:58:56 PM	MTAService.OnSessionChange	0	None	12:58:56 PM - Session change notice received: SessionLock Session ID: 1
Information	9/28/2018 12:48:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9029.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/28/2018 12:36:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7a44758-c2ec-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/28/2018 12:31:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 12:15:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 12:10:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57944)(?)])(1 )(2 )]

"
Information	9/28/2018 12:10:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2018 12:10:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57944)(?)])(1 )(2 )]

"
Information	9/28/2018 12:10:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 57944)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 12:10:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2018 12:10:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 12:10:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2018 12:07:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/28/2018 12:07:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/28/2018 12:01:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/28/2018 12:01:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/28/2018 11:59:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/28/2018 11:59:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/28/2018 11:47:53 AM	MTAService.OnSessionChange	0	None	11:47:53 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/28/2018 11:44:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/28/2018 11:43:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/28/2018 11:31:36 AM	MTAService.OnSessionChange	0	None	11:31:36 AM - Session change notice received: SessionLock Session ID: 1
Warning	9/28/2018 10:52:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 9:59:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/28/2018 9:59:45 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/28/2018 9:59:40 AM	MTAService.OnSessionChange	0	None	9:59:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/28/2018 9:48:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 9:48:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 9:48:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/28/2018 9:48:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 9:38:17 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	9/28/2018 8:58:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 7:36:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0de70aaf-c2c3-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/28/2018 7:25:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 5:48:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 5:48:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 5:47:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/28/2018 5:30:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 5:19:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 5:19:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:58Z. Reason: GVLK.
Information	9/28/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 5:14:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2018 4:38:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 4:38:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:37Z. Reason: GVLK.
Information	9/28/2018 4:33:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 4:33:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 4:33:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 4:33:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/28/2018 4:31:57 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/28/2018 4:28:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 4:28:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:37Z. Reason: GVLK.
Error	9/28/2018 4:23:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/28/2018 4:23:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 4:23:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 4:23:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 4:23:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/28/2018 3:33:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 3:09:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2018 3:09:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:16Z. Reason: GVLK.
Information	9/28/2018 3:04:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2018 3:04:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2018 3:04:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2018 3:04:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2018 2:36:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2439675f-c299-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/28/2018 1:53:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 1:48:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 1:48:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2018 1:47:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/28/2018 12:13:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/28/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/27/2018 10:14:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 9:48:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:48:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:48:03 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/27/2018 9:47:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:36:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3a7eba62-c26f-11e8-b79e-204747d02364
Report Status: 0"
Information	9/27/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/27/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/27/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 58839)(?)])(1 )(2 )]

"
Information	9/27/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/27/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 58839)(?)])(1 )(2 )]

"
Information	9/27/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 58839)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/27/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2018 9:16:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/27/2018 8:33:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 7:31:19 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/27/2018 7:29:09 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/27/2018 7:15:55 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/27/2018 6:54:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 6:43:15 PM	MTAService.OnSessionChange	0	None	6:43:15 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 6:42:10 PM	MTAService.OnSessionChange	0	None	6:42:10 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 6:39:14 PM	MTAService.OnSessionChange	0	None	6:39:14 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 5:48:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 5:47:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 5:46:32 PM	MTAService.OnSessionChange	0	None	5:46:32 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/27/2018 5:06:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 4:37:34 PM	MTAService.OnSessionChange	0	None	4:37:34 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 4:36:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 50a41dba-c245-11e8-b79e-204747d02364
Report Status: 0"
Information	9/27/2018 4:34:50 PM	MTAService.OnSessionChange	0	None	4:34:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/27/2018 3:32:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 3:25:31 PM	MTAService.OnSessionChange	0	None	3:25:31 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 2:17:55 PM	MTAService.OnSessionChange	0	None	2:17:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 2:02:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 2:01:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/27/2018 1:48:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2018 1:48:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:44Z. Reason: GVLK.
Information	9/27/2018 1:48:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/27/2018 1:47:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/27/2018 1:43:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2018 1:43:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2018 1:43:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2018 1:43:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/27/2018 1:33:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 1:29:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 1:29:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/27/2018 1:11:20 PM	MTAService.OnSessionChange	0	None	1:11:20 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 12:52:22 PM	MTAService.OnSessionChange	0	None	12:52:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 12:47:37 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9028.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/27/2018 12:43:21 PM	MTAService.OnSessionChange	0	None	12:43:21 PM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 12:25:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 12:24:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/27/2018 12:21:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 12:20:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/27/2018 12:16:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 12:15:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/27/2018 11:55:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 11:51:43 AM	MTAService.OnSessionChange	0	None	11:51:43 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 11:35:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 67259115-c21b-11e8-b79e-204747d02364
Report Status: 0"
Information	9/27/2018 11:31:14 AM	MTAService.OnSessionChange	0	None	11:31:14 AM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 11:28:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 11:27:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/27/2018 11:03:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2018 11:03:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:53Z. Reason: GVLK.
Information	9/27/2018 10:58:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2018 10:58:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2018 10:58:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2018 10:58:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/27/2018 10:18:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 9:54:40 AM	MTAService.OnSessionChange	0	None	9:54:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 9:47:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:47:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:47:21 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/27/2018 9:47:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 9:40:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 27404, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/27/2018 9:38:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/27/2018 9:38:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/27/2018 9:38:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/27/2018 9:28:06 AM	MTAService.OnSessionChange	0	None	9:28:06 AM - Session change notice received: SessionLock Session ID: 1
Information	9/27/2018 9:25:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/27/2018 9:25:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/27/2018 9:25:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/27/2018 9:25:06 AM	MTAService.OnSessionChange	0	None	9:25:06 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/27/2018 9:24:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/27/2018 9:23:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/27/2018 8:31:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 8:30:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/27/2018 8:30:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	9/27/2018 6:48:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 6:35:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7d80e6d6-c1f1-11e8-b79e-204747d02364
Report Status: 0"
Information	9/27/2018 5:47:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 5:47:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/27/2018 4:53:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 4:39:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2018 4:39:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:00Z. Reason: GVLK.
Information	9/27/2018 4:34:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2018 4:34:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2018 4:34:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2018 4:34:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/27/2018 4:32:14 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/27/2018 4:32:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2018 4:32:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:01Z. Reason: GVLK.
Error	9/27/2018 4:27:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/27/2018 4:27:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2018 4:27:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2018 4:27:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2018 4:27:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/27/2018 3:22:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/27/2018 1:47:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 1:47:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2018 1:35:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 93d62b4c-c1c7-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/27/2018 1:31:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/26/2018 11:40:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/26/2018 10:00:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 9:47:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 9:47:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/26/2018 9:47:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/26/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60279)(?)])(1 )(2 )]

"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60279)(?)])(1 )(2 )]

"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60279)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 8:35:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa4a1a45-c19d-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/26/2018 8:08:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 8:05:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 8:05:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:12Z. Reason: GVLK.
Information	9/26/2018 8:00:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 8:00:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 8:00:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 8:00:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 7:23:45 PM	MTAService.OnSessionChange	0	None	7:23:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/26/2018 7:22:14 PM	MTAService.OnSessionChange	0	None	7:22:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/26/2018 7:14:19 PM	MTAService.OnSessionChange	0	None	7:14:19 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/26/2018 6:20:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 5:52:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 5:47:25 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1123

Information	9/26/2018 5:47:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 5:46:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60488)(?)])(1 )(2 )]

"
Information	9/26/2018 5:46:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2018 5:46:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60488)(?)])(1 )(2 )]

"
Information	9/26/2018 5:46:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60488)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 5:46:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2018 5:46:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 5:46:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 5:37:18 PM	MTAService.OnSessionChange	0	None	5:37:18 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/26/2018 4:35:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 4:04:44 PM	MTAService.OnSessionChange	0	None	4:04:44 PM - Session change notice received: SessionLock Session ID: 1
Information	9/26/2018 3:45:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 3:45:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:01:22Z. Reason: GVLK.
Information	9/26/2018 3:40:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 3:40:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 3:40:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 3:40:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 3:35:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bfc6d380-c173-11e8-b79e-204747d02364
Report Status: 0"
Error	9/26/2018 3:34:25 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/26/2018 3:27:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 3:27:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:34Z. Reason: GVLK.
Error	9/26/2018 3:20:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/26/2018 3:18:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 3:18:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 3:18:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 3:18:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/26/2018 2:51:13 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	9/26/2018 2:51:13 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	9/26/2018 2:49:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 2:32:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 2:32:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 2:23:15 PM	MTAService.OnSessionChange	0	None	2:23:15 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/26/2018 1:17:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 1:12:52 PM	MTAService.OnSessionChange	0	None	1:12:52 PM - Session change notice received: SessionLock Session ID: 1
Information	9/26/2018 1:00:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9027.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/26/2018 12:19:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/26/2018 12:19:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/26/2018 11:30:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/26/2018 11:30:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/26/2018 11:28:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 11:17:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/26/2018 11:17:01 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/26/2018 10:37:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 10:35:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5ac031f-c149-11e8-b79e-204747d02364
Report Status: 0"
Information	9/26/2018 10:32:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/26/2018 10:32:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 10:32:30 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/26/2018 10:32:30 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 577

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 405

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 609

Information	9/26/2018 10:32:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2018 10:31:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60923)(?)])(1 )(2 )]

"
Information	9/26/2018 10:31:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2018 10:31:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60923)(?)])(1 )(2 )]

"
Information	9/26/2018 10:31:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 60923)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 10:31:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2018 10:31:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 10:31:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 10:01:22 AM	MTAService.OnSessionChange	0	None	10:01:22 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/26/2018 9:40:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 9:36:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 9:36:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-10-03T04:00:30Z. Reason: GVLK.
Information	9/26/2018 9:31:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 9:31:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 9:31:29 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/09/26 04:01"
Information	9/26/2018 9:31:28 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/09/26 04:01, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/26/2018 9:26:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 9:26:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 9:26:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 9:26:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/26/2018 7:59:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/26/2018 6:02:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 5:35:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ebfcac22-c11f-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/26/2018 4:20:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 4:00:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 4:00:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:25Z. Reason: GVLK.
Information	9/26/2018 3:55:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 3:55:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 3:55:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 3:55:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 3:54:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2018 3:54:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:02Z. Reason: GVLK.
Error	9/26/2018 3:53:19 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	9/26/2018 3:45:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/26/2018 3:45:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2018 3:45:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2018 3:45:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2018 3:45:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2018 3:08:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/26/2018 3:07:04 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	9/26/2018 2:49:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/26/2018 12:59:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/26/2018 12:35:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 023cca68-c0f6-11e8-b79e-204747d02364
Report Status: 0"
Information	9/26/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/25/2018 11:08:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/25/2018 9:24:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 9:21:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/25/2018 9:16:03 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 61719)(?)])(1 )(2 )]

"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 61719)(?)])(1 )(2 )]

"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 61719)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/25/2018 9:16:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 9:16:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/25/2018 8:03:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 7:58:38 PM	MTAService.OnSessionChange	0	None	7:58:38 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/25/2018 7:52:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 7:35:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 188bba09-c0cc-11e8-b79e-204747d02364
Report Status: 0"
Information	9/25/2018 6:52:47 PM	MTAService.OnSessionChange	0	None	6:52:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 6:38:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 6:38:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:53Z. Reason: GVLK.
Information	9/25/2018 6:33:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 6:33:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 6:33:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 6:33:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/25/2018 6:09:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 5:41:33 PM	MTAService.OnSessionChange	0	None	5:41:33 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 5:02:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 5:01:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 4:50:11 PM	MTAService.OnSessionChange	0	None	4:50:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 4:39:13 PM	MTAService.OnSessionChange	0	None	4:39:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/25/2018 4:31:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 4:26:12 PM	MTAService.OnSessionChange	0	None	4:26:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 4:12:33 PM	MTAService.OnSessionChange	0	None	4:12:33 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 4:08:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 62026)(?)])(1 )(2 )]

"
Information	9/25/2018 4:08:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/25/2018 4:08:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 62026)(?)])(1 )(2 )]

"
Information	9/25/2018 4:08:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 62026)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 3:32:20 PM	MTAService.OnSessionChange	0	None	3:32:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 3:10:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 3:10:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 3:02:48 PM	MTAService.OnSessionChange	0	None	3:02:48 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 2:45:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 2:44:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 2:35:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2eab63b0-c0a2-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/25/2018 2:34:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 2:20:17 PM	MTAService.OnSessionChange	0	None	2:20:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 1:56:27 PM	MTAService.OnSessionChange	0	None	1:56:27 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 1:56:12 PM	MTAService.OnSessionChange	0	None	1:56:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 1:19:26 PM	MTAService.OnSessionChange	0	None	1:19:26 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 1:15:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 1:15:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 1:02:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 1:01:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 1:01:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 12:55:26 PM	MTAService.OnSessionChange	0	None	12:55:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 12:54:29 PM	MTAService.OnSessionChange	0	None	12:54:29 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 12:44:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	9/25/2018 12:44:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 12:44:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:38:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:38:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:35:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:34:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:32:09 PM	MTAService.OnSessionChange	0	None	12:32:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 12:27:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:26:38 PM	MTAService.OnSessionChange	0	None	12:26:38 PM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 12:26:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:16:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:16:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:15:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:14:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 12:12:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9026.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/25/2018 12:09:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 12:09:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 11:51:13 AM	MTAService.OnSessionChange	0	None	11:51:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 11:35:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 11:35:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 11:30:58 AM	MTAService.OnSessionChange	0	None	11:30:58 AM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 11:29:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 11:28:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 11:23:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 11:22:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 11:20:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 11:20:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/25/2018 11:09:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 10:52:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 10:52:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 10:00:41 AM	MTAService.OnSessionChange	0	None	10:00:41 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 9:35:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44eb094e-c078-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/25/2018 9:24:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 9:22:12 AM	MTAService.OnSessionChange	0	None	9:22:12 AM - Session change notice received: SessionLock Session ID: 1
Information	9/25/2018 9:12:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/25/2018 9:11:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/25/2018 9:11:42 AM	MTAService.OnSessionChange	0	None	9:11:42 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/25/2018 9:08:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/25/2018 9:02:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 9:01:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 9:01:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 9:01:37 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/25/2018 9:01:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/25/2018 7:42:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 6:24:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 6:24:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:04Z. Reason: GVLK.
Information	9/25/2018 6:19:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 6:19:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 6:19:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 6:19:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/25/2018 6:09:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 6:07:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 6:07:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:52Z. Reason: GVLK.
Information	9/25/2018 6:02:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 6:02:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 6:02:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 6:02:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2018 5:53:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/25/2018 5:52:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/25/2018 5:21:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 5:21:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:50Z. Reason: GVLK.
Information	9/25/2018 5:16:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 5:16:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 5:16:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 5:16:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2018 5:02:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 5:01:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 5:01:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 4:35:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b4848f0-c04e-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/25/2018 4:15:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 3:25:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 3:25:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:20Z. Reason: GVLK.
Information	9/25/2018 3:20:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 3:20:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 3:20:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 3:20:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/25/2018 3:17:13 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/25/2018 3:13:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2018 3:13:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:16Z. Reason: GVLK.
Error	9/25/2018 3:08:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/25/2018 3:07:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2018 3:07:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2018 3:07:49 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	9/25/2018 3:07:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2018 3:07:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/25/2018 2:28:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 1:01:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 1:01:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2018 1:01:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/25/2018 12:45:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/25/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/24/2018 11:35:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7181273d-c024-11e8-b79e-204747d02364
Report Status: 0"
Warning	9/24/2018 10:45:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	9/24/2018 9:16:04 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/24/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63159)(?)])(1 )(2 )]

"
Information	9/24/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 9:16:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63159)(?)])(1 )(2 )]

"
Information	9/24/2018 9:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63159)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 9:01:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 9:01:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 9:01:26 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/24/2018 9:01:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/24/2018 8:53:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 8:22:05 PM	MTAService.OnSessionChange	0	None	8:22:05 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 7:29:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63265)(?)])(1 )(2 )]

"
Information	9/24/2018 7:29:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 7:29:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63265)(?)])(1 )(2 )]

"
Information	9/24/2018 7:29:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 7:22:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63272)(?)])(1 )(2 )]

"
Information	9/24/2018 7:22:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 7:22:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63272)(?)])(1 )(2 )]

"
Information	9/24/2018 7:22:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63272)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	9/24/2018 7:10:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 7:04:31 PM	MTAService.OnSessionChange	0	None	7:04:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 6:56:55 PM	MTAService.OnSessionChange	0	None	6:56:55 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 6:37:45 PM	MTAService.OnSessionChange	0	None	6:37:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 6:35:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 87684e00-bffa-11e8-b79e-204747d02364
Report Status: 0"
Information	9/24/2018 6:34:15 PM	MTAService.OnSessionChange	0	None	6:34:15 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 6:17:36 PM	MTAService.OnSessionChange	0	None	6:17:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 5:36:16 PM	MTAService.OnSessionChange	0	None	5:36:16 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 5:31:03 PM	MTAService.OnSessionChange	0	None	5:31:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 5:27:54 PM	MTAService.OnSessionChange	0	None	5:27:54 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 5:24:08 PM	MTAService.OnSessionChange	0	None	5:24:08 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/24/2018 5:10:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 5:01:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 5:00:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/24/2018 3:39:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 3:28:09 PM	MTAService.OnSessionChange	0	None	3:28:09 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 3:24:46 PM	MTAService.OnSessionChange	0	None	3:24:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 3:24:08 PM	MTAService.OnSessionChange	0	None	3:24:08 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 2:58:18 PM	MTAService.OnSessionChange	0	None	2:58:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 2:42:33 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/24/2018 2:09:57 PM	MTAService.OnSessionChange	0	None	2:09:57 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 2:09:24 PM	MTAService.OnSessionChange	0	None	2:09:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 2:08:52 PM	MTAService.OnSessionChange	0	None	2:08:52 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 2:04:53 PM	MTAService.OnSessionChange	0	None	2:04:53 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/24/2018 1:46:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 1:35:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d933083-bfd0-11e8-b79e-204747d02364
Report Status: 0"
Information	9/24/2018 1:23:44 PM	MTAService.OnSessionChange	0	None	1:23:44 PM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 1:01:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 1:00:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 12:21:41 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9025.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/24/2018 12:00:49 PM	MTAService.OnSessionChange	0	None	12:00:49 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/24/2018 11:59:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 11:57:51 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/24/2018 11:30:22 AM	MTAService.OnSessionChange	0	None	11:30:22 AM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 11:13:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63761)(?)])(1 )(2 )]

"
Information	9/24/2018 11:13:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 11:13:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63761)(?)])(1 )(2 )]

"
Information	9/24/2018 11:13:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63761)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	9/24/2018 10:09:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/24/2018 9:55:01 AM	MTAService.OnSessionChange	0	None	9:55:01 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/24/2018 9:43:25 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/24/2018 9:43:22 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 27288, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/24/2018 9:37:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/24/2018 9:37:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/24/2018 9:32:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 9:32:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:00Z. Reason: GVLK.
Information	9/24/2018 9:27:20 AM	MTAService.OnSessionChange	0	None	9:27:20 AM - Session change notice received: SessionLock Session ID: 1
Information	9/24/2018 9:26:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2018 9:26:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 9:26:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 9:26:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 9:09:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 9:09:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:23Z. Reason: GVLK.
Information	9/24/2018 9:04:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2018 9:04:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 9:04:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 9:04:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 9:01:30 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/24/2018 9:01:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 9:01:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63893)(?)])(1 )(2 )]

"
Information	9/24/2018 9:01:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63893)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 9:01:29 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/24/2018 9:01:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 9:01:19 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 171

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 827

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 62

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 733

Information	9/24/2018 9:01:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/24/2018 9:01:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 44 63893)(?)])(1 )(2 )]

"
Information	9/24/2018 9:01:14 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/24/2018 9:01:14 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=107093  Grace type=8.
Information	9/24/2018 9:01:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=8db22af8-660b-4dab-b631-3237c28d9fe7"
Information	9/24/2018 9:01:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=8bcb5a60-ce15-4979-a946-ac190f957ba6"
Information	9/24/2018 9:01:13 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/24/2018 9:00:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2018 8:59:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17815)(?)])(1 )(2 )]

"
Information	9/24/2018 8:59:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 8:59:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17815)(?)])(1 )(2 )]

"
Information	9/24/2018 8:59:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17815)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:59:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2018 8:59:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:59:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	9/24/2018 8:56:31 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/24/2018 8:55:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 8:50:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 8:50:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:52Z. Reason: GVLK.
Information	9/24/2018 8:50:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 8852.
Information	9/24/2018 8:50:05 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2282. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:50:05 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	9/24/2018 8:50:04 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/24/2018 8:50:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17824)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:50:03 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/24/2018 8:50:03 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/24/2018 8:50:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:50:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2018 8:50:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:50:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 8:49:58 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 8:49:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:47 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:47 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2282. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:49:47 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	9/24/2018 8:49:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2282. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:49:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	9/24/2018 8:49:42 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:42 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2282. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:49:42 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	9/24/2018 8:49:36 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:36 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/24/2018 8:49:36 AM	ESENT	102	General	Windows (10824) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/24/2018 8:49:36 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:36 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2282. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:49:36 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	9/24/2018 8:49:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:08 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	9/24/2018 8:49:08 AM	ESENT	103	General	Windows (10324) Windows: The database engine stopped the instance (0).
Information	9/24/2018 8:49:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:49:08 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2282. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/24/2018 8:49:08 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	9/24/2018 8:48:04 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 8852.
Information	9/24/2018 8:47:15 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/24/2018 8:47:15 AM	ESENT	102	General	Windows (10324) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	9/24/2018 8:47:11 AM	ESENT	103	General	Windows (3728) Windows: The database engine stopped the instance (0).
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:11 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	9/24/2018 8:47:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:47:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	9/24/2018 8:46:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	9/24/2018 8:46:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	9/24/2018 8:46:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	9/24/2018 8:46:41 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	9/24/2018 8:46:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2018 8:46:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:46:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	9/24/2018 8:46:31 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/24/2018 8:45:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2018 8:45:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:45:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:45:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 8:45:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 8:45:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:44Z. Reason: GVLK.
Information	9/24/2018 8:44:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/24/2018 8:39:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	9/24/2018 8:39:37 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17835)(?)])(1 )(2 )]

"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17835)(?)])(1 )(2 )]

"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17835)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2018 8:39:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:39:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 8:39:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/24/2018 8:35:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/24/2018 8:34:39 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	9/24/2018 8:34:16 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {7EED06E2-D093-4874-BA78-D9053F4898A8}
Error	9/24/2018 8:34:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/24/2018 8:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17840)(?)])(1 )(2 )]

"
Information	9/24/2018 8:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2018 8:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17840)(?)])(1 )(2 )]

"
Information	9/24/2018 8:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 17840)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:33:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2018 8:33:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:33:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 8:33:34 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/24/2018 8:33:32 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/24/2018 8:33:30 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	9/24/2018 8:33:16 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	9/24/2018 8:33:00 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/24/2018 8:32:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2018 8:32:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2018 8:32:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2018 8:32:42 AM	ESENT	302	Logging/Recovery	Windows (3728) Windows: The database engine has successfully completed recovery steps.
Information	9/24/2018 8:32:36 AM	ESENT	301	Logging/Recovery	Windows (3728) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/24/2018 8:32:36 AM	ESENT	300	Logging/Recovery	Windows (3728) Windows: The database engine is initiating recovery steps.
Information	9/24/2018 8:32:36 AM	ESENT	102	General	Windows (3728) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/24/2018 8:32:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2018 8:32:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9024.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Error	9/24/2018 8:31:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/24/2018 8:31:23 AM	Service1	0	None	Service started successfully.
Error	9/24/2018 8:31:15 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/24/2018 8:31:14 AM	MTAService	0	None	Service started successfully.
Information	9/24/2018 8:30:58 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/24/2018 8:30:56 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/24/2018 8:30:54 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/24/2018 8:30:54 AM	PostgreSQL	0	None	"2018-09-24 08:30:54 IST LOG:  redirecting log output to logging collector process
2018-09-24 08:30:54 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/24/2018 8:30:42 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/24/2018 8:30:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/24/2018 8:30:33 AM	MTAService.OnStart	0	None	8:30:32 AM - User is already logged in : 212558710
Information	9/24/2018 8:30:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/24/2018 8:30:16 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/24/2018 8:30:16 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/24/2018 8:30:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/24/2018 8:30:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/24/2018 8:30:12 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4668 at 9/23/2018 2:22:02 PM (local) 9/23/2018 8:52:02 AM (UTC). This is an informational message only; no user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/24/2018 8:30:10 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4952.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/24/2018 8:30:08 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/24/2018 8:29:30 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/24/2018 8:29:17 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/24/2018 8:29:09 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/24/2018 8:29:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/24/2018 8:29:09 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/23/2018 2:22:09 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/23/2018 2:22:02 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	9/23/2018 2:21:27 PM	McLogEvent	257	None	The scan of C:\Windows\System32\en-US\tzres.dll.mui has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 9024.0000.
Warning	9/23/2018 2:21:24 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1044 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4808 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4808 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2120 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/23/2018 2:21:24 PM	MTAService.OnSessionChange	0	None	2:21:24 PM - Logoff
Information	9/23/2018 2:21:24 PM	MTAService.OnSessionChange	0	None	2:21:24 PM - Session change notice received: SessionLogoff Session ID: 1
Information	9/23/2018 2:21:22 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/23/2018 2:21:22 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/23/2018 2:21:22 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/23/2018 2:21:15 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/23/2018 12:46:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2018 12:46:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:27Z. Reason: GVLK.
Information	9/23/2018 12:41:45 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	9/23/2018 12:41:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 1220) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/23/2018 12:41:45 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 6788) cannot be restarted - Application SID does not match Conductor SID..
Information	9/23/2018 12:41:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎23T07:11:45.271248000Z.
Information	9/23/2018 12:41:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎23T07:11:40.088951600Z.
Information	9/23/2018 12:41:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2018 12:41:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2018 12:41:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2018 12:41:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2018 12:17:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9024.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/23/2018 12:16:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2018 12:16:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:26Z. Reason: GVLK.
Information	9/23/2018 12:11:39 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	9/23/2018 12:11:39 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 1220) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/23/2018 12:11:39 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 6788) cannot be restarted - Application SID does not match Conductor SID..
Information	9/23/2018 12:11:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎23T06:41:39.241949100Z.
Information	9/23/2018 12:11:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎23T06:41:37.872870800Z.
Information	9/23/2018 12:11:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2018 12:11:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2018 12:11:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2018 12:11:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2018 11:59:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2018 11:59:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:01Z. Reason: GVLK.
Information	9/23/2018 11:54:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2018 11:54:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2018 11:54:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2018 11:54:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/23/2018 11:50:42 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/23/2018 11:48:58 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	9/23/2018 11:48:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 1220) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/23/2018 11:48:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 6788) cannot be restarted - Application SID does not match Conductor SID..
Information	9/23/2018 11:48:58 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎23T06:18:58.410113900Z.
Information	9/23/2018 11:48:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎23T06:18:56.585009600Z.
Information	9/23/2018 11:46:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2018 11:46:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:25Z. Reason: GVLK.
Information	9/23/2018 11:36:58 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/23/2018 11:35:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a6f236e4-bef6-11e8-aaff-204747d02364
Report Status: 0"
Error	9/23/2018 11:34:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/23/2018 11:33:00 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	9/23/2018 11:32:02 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/23/2018 11:32:02 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	9/23/2018 11:31:53 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {B46651E2-D4E4-406C-875A-733AE72009BA}
Information	9/23/2018 11:31:01 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	9/23/2018 11:30:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/23/2018 11:29:42 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/23/2018 11:29:37 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/23/2018 11:29:35 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/23/2018 11:29:33 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/23/2018 11:29:16 AM	ESENT	302	Logging/Recovery	Windows (9428) Windows: The database engine has successfully completed recovery steps.
Information	9/23/2018 11:29:14 AM	ESENT	301	Logging/Recovery	Windows (9428) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/23/2018 11:29:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 19105)(?)])(1 )(2 )]

"
Information	9/23/2018 11:29:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/23/2018 11:29:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 19105)(?)])(1 )(2 )]

"
Information	9/23/2018 11:29:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 19105)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2018 11:29:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/23/2018 11:29:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2018 11:29:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2018 11:29:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2018 11:29:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2018 11:28:59 AM	ESENT	301	Logging/Recovery	Windows (9428) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS011C5.log.
Information	9/23/2018 11:28:59 AM	ESENT	300	Logging/Recovery	Windows (9428) Windows: The database engine is initiating recovery steps.
Information	9/23/2018 11:28:59 AM	ESENT	102	General	Windows (9428) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/23/2018 11:28:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2018 11:28:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/23/2018 11:28:54 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9023.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/23/2018 11:26:28 AM	Service1	0	None	Service started successfully.
Error	9/23/2018 11:26:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/23/2018 11:26:10 AM	MTAService	0	None	Service started successfully.
Information	9/23/2018 11:26:08 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/23/2018 11:26:04 AM	PostgreSQL	0	None	"2018-09-23 11:26:04 IST LOG:  redirecting log output to logging collector process
2018-09-23 11:26:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Error	9/23/2018 11:25:52 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/23/2018 11:25:51 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/23/2018 11:25:50 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/23/2018 11:25:48 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/23/2018 11:25:45 AM	MTAService.OnStart	0	None	11:25:45 AM - User is already logged in : 212558710
Information	9/23/2018 11:25:26 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/23/2018 11:25:26 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/23/2018 11:25:26 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/23/2018 11:25:26 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/23/2018 11:25:25 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/23/2018 11:25:25 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/23/2018 11:25:18 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/23/2018 11:25:17 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/23/2018 11:25:16 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/23/2018 11:25:15 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4348 at 9/22/2018 6:13:19 PM (local) 9/22/2018 12:43:19 PM (UTC). This is an informational message only; no user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/23/2018 11:25:13 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4668.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/23/2018 11:25:03 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/23/2018 11:24:32 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/23/2018 11:24:26 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/23/2018 11:24:17 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/22/2018 6:13:26 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/23/2018 11:24:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/23/2018 11:24:17 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/22/2018 6:13:19 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	9/22/2018 6:13:16 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1004 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2096 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/22/2018 6:13:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/22/2018 6:13:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/22/2018 6:13:15 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/22/2018 6:13:11 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/22/2018 4:24:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2018 4:24:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:33Z. Reason: GVLK.
Information	9/22/2018 4:19:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2018 4:19:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 4:19:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 4:19:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 4:05:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9023.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/22/2018 3:54:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2018 3:54:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:33Z. Reason: GVLK.
Information	9/22/2018 3:49:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2018 3:49:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 3:49:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 3:49:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 3:30:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/22/2018 3:25:08 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/22/2018 3:25:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20309)(?)])(1 )(2 )]

"
Information	9/22/2018 3:25:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/22/2018 3:25:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20309)(?)])(1 )(2 )]

"
Information	9/22/2018 3:25:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20309)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 3:25:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2018 3:25:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 3:25:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 3:24:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2018 3:24:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:36Z. Reason: GVLK.
Information	9/22/2018 3:19:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2018 3:19:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 3:19:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 3:19:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 3:12:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2018 3:12:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:28Z. Reason: GVLK.
Information	9/22/2018 3:11:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/22/2018 3:10:43 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/22/2018 3:10:42 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	9/22/2018 3:06:47 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x80070057; CorrelationId: {A264A749-4E91-4EF6-875C-4AF83272EB21}
Information	9/22/2018 3:06:41 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	9/22/2018 3:06:37 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/22/2018 3:06:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20328)(?)])(1 )(2 )]

"
Information	9/22/2018 3:06:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/22/2018 3:06:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20328)(?)])(1 )(2 )]

"
Information	9/22/2018 3:06:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20328)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 3:06:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2018 3:06:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 3:06:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 3:05:44 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/22/2018 3:05:42 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/22/2018 3:05:40 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/22/2018 3:05:37 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/22/2018 3:05:19 PM	ESENT	302	Logging/Recovery	Windows (8136) Windows: The database engine has successfully completed recovery steps.
Information	9/22/2018 3:05:18 PM	ESENT	301	Logging/Recovery	Windows (8136) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/22/2018 3:05:14 PM	ESENT	301	Logging/Recovery	Windows (8136) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS011C4.log.
Information	9/22/2018 3:05:14 PM	ESENT	300	Logging/Recovery	Windows (8136) Windows: The database engine is initiating recovery steps.
Information	9/22/2018 3:05:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2018 3:05:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2018 3:05:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2018 3:05:14 PM	ESENT	102	General	Windows (8136) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/22/2018 3:04:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2018 3:04:44 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/22/2018 3:04:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9022.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/22/2018 3:04:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/22/2018 3:04:16 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/22/2018 3:04:16 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/22/2018 3:04:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/22/2018 3:04:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/22/2018 3:04:03 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/22/2018 3:04:02 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/22/2018 3:04:02 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/22/2018 3:04:02 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/22/2018 3:04:02 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/22/2018 3:04:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/22/2018 3:04:01 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/22/2018 3:04:00 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/22/2018 3:03:36 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/22/2018 3:03:35 PM	PostgreSQL	0	None	"2018-09-22 15:03:35 IST LOG:  redirecting log output to logging collector process
2018-09-22 15:03:35 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Error	9/22/2018 3:03:35 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/22/2018 3:03:34 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/22/2018 3:03:33 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/22/2018 3:03:31 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4316 at 9/21/2018 3:39:31 PM (local) 9/21/2018 10:09:31 AM (UTC). This is an informational message only; no user action is required.
Information	9/22/2018 3:02:51 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/22/2018 3:02:30 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/22/2018 3:02:30 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/22/2018 3:02:30 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/22/2018 3:02:30 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/22/2018 3:02:30 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4348.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/22/2018 3:02:20 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/22/2018 3:01:04 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/22/2018 3:01:00 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/22/2018 3:00:27 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/22/2018 3:00:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/22/2018 3:00:27 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/21/2018 3:39:40 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/21/2018 3:39:31 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	9/21/2018 3:39:21 PM	McLogEvent	257	None	The scan of C:\Program Files\MTA\GUI\node.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 9022.0000.
Warning	9/21/2018 3:39:18 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 556 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
"
Information	9/21/2018 3:39:16 PM	MTAService.OnSessionChange	0	None	3:39:16 PM - Logoff
Information	9/21/2018 3:39:16 PM	MTAService.OnSessionChange	0	None	3:39:16 PM - Session change notice received: SessionLogoff Session ID: 1
Information	9/21/2018 3:39:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/21/2018 3:39:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/21/2018 3:39:15 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/21/2018 3:39:09 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/21/2018 3:37:18 PM	MTAService.OnSessionChange	0	None	3:37:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 3:28:28 PM	MTAService.OnSessionChange	0	None	3:28:28 PM - Session change notice received: SessionLock Session ID: 1
Information	9/21/2018 3:07:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eaa385e8-bd81-11e8-ad25-204747d02364
Report Status: 0"
Information	9/21/2018 2:53:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9022.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/21/2018 2:30:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/21/2018 2:25:24 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/21/2018 2:25:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21809)(?)])(1 )(2 )]

"
Information	9/21/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21809)(?)])(1 )(2 )]

"
Information	9/21/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21809)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 2:25:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2018 2:25:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/21/2018 2:07:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 2:06:44 PM	MTAService.OnSessionChange	0	None	2:06:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 2:01:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 2:00:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 1:47:27 PM	MTAService.OnSessionChange	0	None	1:47:27 PM - Session change notice received: SessionLock Session ID: 1
Information	9/21/2018 1:46:21 PM	MTAService.OnSessionChange	0	None	1:46:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 1:20:47 PM	MTAService.OnSessionChange	0	None	1:20:47 PM - Session change notice received: SessionLock Session ID: 1
Information	9/21/2018 12:51:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/21/2018 12:51:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/21/2018 12:25:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 11:46:40 AM	MTAService.OnSessionChange	0	None	11:46:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 11:29:05 AM	MTAService.OnSessionChange	0	None	11:29:05 AM - Session change notice received: SessionLock Session ID: 1
Information	9/21/2018 11:00:17 AM	McLogEvent	257	None	The scan of C:\Users\212558710\Desktop\Extra_Matter\setup\ISSetupPrerequisites\{40B3EFEE-AB85-46CB-8E97-B609BF8E681A}\jdk-8u77-windows-i586.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 9021.0000.
Warning	9/21/2018 10:50:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 10:26:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 10:26:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:18Z. Reason: GVLK.
Information	9/21/2018 10:21:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 10:21:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 10:21:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 10:21:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 10:07:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 00cdd5b5-bd58-11e8-ad25-204747d02364
Report Status: 0"
Information	9/21/2018 10:06:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 10:06:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 13, Deleted: 0, Modified: 3, Compared: 27343, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/21/2018 10:01:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 10:01:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/21/2018 10:01:24 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 577

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 47

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 718

Information	9/21/2018 10:00:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 10:00:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22074)(?)])(1 )(2 )]

"
Information	9/21/2018 10:00:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2018 10:00:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22074)(?)])(1 )(2 )]

"
Information	9/21/2018 10:00:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22074)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 10:00:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2018 10:00:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 10:00:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 9:57:01 AM	MTAService.OnSessionChange	0	None	9:57:01 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 9:56:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 9:56:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:17Z. Reason: GVLK.
Information	9/21/2018 9:51:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 9:51:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 9:51:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 9:51:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 9:26:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 9:26:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:18Z. Reason: GVLK.
Information	9/21/2018 9:24:54 AM	MTAService.OnSessionChange	0	None	9:24:54 AM - Session change notice received: SessionLock Session ID: 1
Information	9/21/2018 9:21:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 9:21:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 9:21:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 9:21:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 9:13:05 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 9:11:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 9:11:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:17Z. Reason: GVLK.
Warning	9/21/2018 9:09:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 9:08:01 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	9/21/2018 9:07:52 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/21/2018 9:07:51 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	9/21/2018 9:07:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/21/2018 9:07:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22127)(?)])(1 )(2 )]

"
Information	9/21/2018 9:07:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2018 9:07:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22127)(?)])(1 )(2 )]

"
Information	9/21/2018 9:07:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 22127)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 9:07:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2018 9:07:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 9:07:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 9:05:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/21/2018 9:05:59 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/21/2018 9:05:58 AM	MTAService.OnSessionChange	0	None	9:05:58 AM - Logon : 212558710
Information	9/21/2018 9:05:58 AM	MTAService.OnSessionChange	0	None	9:05:58 AM - Session change notice received: SessionLogon Session ID: 1
Information	9/21/2018 9:05:58 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/21/2018 9:05:58 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/21/2018 9:05:39 AM	MTAService.OnSessionChange	0	None	9:05:39 AM - Session change notice received: ConsoleConnect Session ID: 1
Warning	9/21/2018 9:05:39 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 114 second(s) to handle the notification event (CreateSession).
Warning	9/21/2018 9:04:45 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	9/21/2018 9:04:33 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/21/2018 9:04:22 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/21/2018 9:04:21 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/21/2018 9:04:19 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/21/2018 9:03:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 9:03:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 9:03:26 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	9/21/2018 9:03:24 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (WorkstationService)
License Id=e4daf208-1ebb-9632-b278-f4266c29924f"
Information	9/21/2018 9:03:24 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (Microsoft-Windows-OfflineFiles-Core)
License Id=fde9a948-da42-4dda-8551-5bc37d07ed22"
Information	9/21/2018 9:03:24 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	9/21/2018 9:03:24 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	9/21/2018 9:03:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 9:03:19 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/21/2018 9:03:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2018 9:02:51 AM	ESENT	302	Logging/Recovery	Windows (7488) Windows: The database engine has successfully completed recovery steps.
Information	9/21/2018 9:02:48 AM	ESENT	301	Logging/Recovery	Windows (7488) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/21/2018 9:02:42 AM	ESENT	301	Logging/Recovery	Windows (7488) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00ADD.log.
Information	9/21/2018 9:02:42 AM	ESENT	300	Logging/Recovery	Windows (7488) Windows: The database engine is initiating recovery steps.
Information	9/21/2018 9:02:41 AM	ESENT	102	General	Windows (7488) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/21/2018 9:02:16 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9021.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/21/2018 9:01:33 AM	Service1	0	None	Service started successfully.
Error	9/21/2018 9:01:24 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/21/2018 9:01:21 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/21/2018 9:01:02 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/21/2018 9:00:54 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/21/2018 9:00:52 AM	PostgreSQL	0	None	"2018-09-21 09:00:52 IST LOG:  redirecting log output to logging collector process
2018-09-21 09:00:52 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/21/2018 9:00:48 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/21/2018 9:00:38 AM	MTAService	0	None	Service started successfully.
Information	9/21/2018 9:00:38 AM	MTAService.OnStart	0	None	9:00:38 AM - Waiting for user to Logon
Information	9/21/2018 9:00:38 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:38 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/21/2018 9:00:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/21/2018 9:00:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/21/2018 9:00:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/21/2018 9:00:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:37 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/21/2018 9:00:37 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/21/2018 9:00:36 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/21/2018 9:00:35 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/21/2018 9:00:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/21/2018 9:00:35 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:35 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/21/2018 9:00:34 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/21/2018 9:00:34 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/21/2018 9:00:33 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/21/2018 9:00:31 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/21/2018 9:00:27 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:27 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:27 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4544 at 9/21/2018 8:52:33 AM (local) 9/21/2018 3:22:33 AM (UTC). This is an informational message only; no user action is required.
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/21/2018 9:00:26 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/21/2018 9:00:25 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/21/2018 9:00:25 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/21/2018 9:00:25 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/21/2018 9:00:25 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4316.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/21/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/21/2018 8:59:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/21/2018 8:58:42 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/21/2018 8:57:10 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/21/2018 8:57:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/21/2018 8:57:10 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/21/2018 8:52:33 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	9/21/2018 8:51:24 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 39 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 412 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1008 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1008 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4840 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4840 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1000 (\Device\HarddiskVolume1\Windows\System32\services.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1008 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1008 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1008 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4840 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4840 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/21/2018 8:51:24 AM	MTAService.OnSessionChange	0	None	8:51:23 AM - Logoff
Information	9/21/2018 8:51:23 AM	MTAService.OnSessionChange	0	None	8:51:23 AM - Session change notice received: SessionLogoff Session ID: 1
Information	9/21/2018 8:51:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/21/2018 8:51:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/21/2018 8:51:21 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/21/2018 8:51:14 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/21/2018 8:50:42 AM	MTAService.OnSessionChange	0	None	8:50:42 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/21/2018 8:47:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 8:47:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 8:17:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 8:17:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:16Z. Reason: GVLK.
Information	9/21/2018 8:12:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 8:12:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 8:12:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 8:12:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/21/2018 7:16:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/21/2018 5:40:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 5:07:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 179b14e6-bd2e-11e8-b123-204747d02364
Report Status: 0"
Information	9/21/2018 4:47:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 4:47:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/21/2018 4:03:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 3:31:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2018 3:31:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:16Z. Reason: GVLK.
Information	9/21/2018 3:26:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2018 3:26:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2018 3:26:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2018 3:26:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/21/2018 2:03:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 1:05:32 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/21/2018 1:05:30 AM	ESENT	102	General	Windows (21824) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/21/2018 1:01:43 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 22484.
Information	9/21/2018 1:01:43 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20063. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	9/21/2018 1:01:43 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	9/21/2018 1:01:43 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20063. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20063). Installation success or error status: 0.
Information	9/21/2018 1:01:43 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20063)' installed successfully.
Information	9/21/2018 1:01:42 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/21/2018 1:01:25 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	9/21/2018 1:01:25 AM	ESENT	103	General	Windows (9104) Windows: The database engine stopped the instance (0).
Information	9/21/2018 1:01:24 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	9/21/2018 1:01:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 22484.
Information	9/21/2018 1:01:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13876.
Information	9/21/2018 1:01:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20063. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	9/21/2018 1:01:06 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	9/21/2018 1:00:57 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13876.
Information	9/21/2018 12:47:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 12:47:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 12:46:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2018 12:46:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	9/21/2018 12:31:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/21/2018 12:07:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2de16b53-bd04-11e8-b123-204747d02364
Report Status: 0"
Information	9/20/2018 11:09:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2018 11:09:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:11Z. Reason: GVLK.
Information	9/20/2018 11:04:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2018 11:04:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 11:04:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 11:04:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/20/2018 10:57:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 10:35:48 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/20/2018 10:33:18 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/20/2018 10:17:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/20/2018 8:59:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 8:47:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 8:46:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 8:00:05 PM	MTAService.OnSessionChange	0	None	8:00:05 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/20/2018 7:24:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 7:07:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43a7104a-bcda-11e8-b123-204747d02364
Report Status: 0"
Information	9/20/2018 6:08:32 PM	MTAService.OnSessionChange	0	None	6:08:32 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/20/2018 5:36:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 4:46:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 4:46:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 4:03:06 PM	MTAService.OnSessionChange	0	None	4:03:06 PM - Session change notice received: SessionLock Session ID: 1
Information	9/20/2018 4:00:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23159)(?)])(1 )(2 )]

"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23159)(?)])(1 )(2 )]

"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23159)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/20/2018 3:55:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 3:55:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/20/2018 3:36:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 2:37:05 PM	MTAService.OnSessionChange	0	None	2:37:05 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/20/2018 2:30:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/20/2018 2:25:54 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/20/2018 2:25:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23248)(?)])(1 )(2 )]

"
Information	9/20/2018 2:25:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/20/2018 2:25:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23248)(?)])(1 )(2 )]

"
Information	9/20/2018 2:25:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23248)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 2:25:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/20/2018 2:25:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 2:25:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/20/2018 2:07:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 56d75e6a-bcb0-11e8-b123-204747d02364
Report Status: 0"
Information	9/20/2018 1:57:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 1:57:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/20/2018 1:49:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 1:37:52 PM	MTAService.OnSessionChange	0	None	1:37:52 PM - Session change notice received: SessionLock Session ID: 1
Information	9/20/2018 1:27:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 1:26:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 1:22:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 1:22:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:46:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 12:46:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 12:46:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/20/2018 12:46:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2018 12:46:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:44:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 12:44:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:41:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 12:41:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:33:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 12:32:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:29:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 12:29:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 12:25:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9021.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	9/20/2018 12:09:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 11:59:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 11:59:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 11:49:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/20/2018 11:49:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 27286, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/20/2018 11:47:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 11:46:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 11:46:35 AM	MTAService.OnSessionChange	0	None	11:46:34 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/20/2018 11:41:21 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/20/2018 11:41:21 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/20/2018 11:40:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/20/2018 11:40:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/20/2018 11:36:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 11:36:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 11:33:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 11:33:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 11:30:59 AM	MTAService.OnSessionChange	0	None	11:30:59 AM - Session change notice received: SessionLock Session ID: 1
Information	9/20/2018 11:29:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2018 11:29:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2018 11:26:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	9/20/2018 10:34:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 10:33:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2018 10:33:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:38Z. Reason: GVLK.
Information	9/20/2018 10:28:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2018 10:28:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 10:28:38 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	9/20/2018 10:28:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 10:28:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2018 10:27:21 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/20/2018 10:20:21 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/20/2018 10:10:13 AM	MTAService.OnSessionChange	0	None	10:10:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/20/2018 10:09:19 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎20T04:31:26.676843500Z.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 14572.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/20/2018 10:09:19 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4457035. Installation success or error status: 0.
Information	9/20/2018 10:09:19 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4457035' installed successfully.
Information	9/20/2018 10:06:24 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:24 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:24 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:23 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:21 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:20 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:19 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:18 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:17 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:17 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:06:05 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00005.log
Information	9/20/2018 10:06:02 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/20/2018 10:05:58 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/20/2018 10:05:57 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:05:47 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	9/20/2018 10:05:45 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00004.log
Information	9/20/2018 10:05:40 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/20/2018 10:05:36 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/20/2018 10:05:36 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:05:16 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/20/2018 10:05:14 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/20/2018 10:04:56 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	9/20/2018 10:04:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:04:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 10:04:09 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 14564.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 5168.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 14564.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 5168.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 5168.
Information	9/20/2018 10:04:07 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:04:06 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5760.
Information	9/20/2018 10:04:06 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 5168.
Information	9/20/2018 10:04:06 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 4840.
Information	9/20/2018 10:03:20 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	9/20/2018 10:03:20 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 7648) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/20/2018 10:03:20 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 16396) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/20/2018 10:03:20 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 18912) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/20/2018 10:03:19 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 15484) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/20/2018 10:03:19 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5760) cannot be restarted - Application SID does not match Conductor SID..
Warning	9/20/2018 10:03:19 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 5168) cannot be restarted - Application SID does not match Conductor SID..
Error	9/20/2018 10:02:19 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/20/2018 10:01:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎20T04:31:26.676843500Z.
Information	9/20/2018 10:01:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 14572.
Information	9/20/2018 9:58:55 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/20/2018 9:55:15 AM	MTAService.OnSessionChange	0	None	9:55:15 AM - Session change notice received: SessionLock Session ID: 1
Information	9/20/2018 9:33:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/20/2018 9:28:33 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23546)(?)])(1 )(2 )]

"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23546)(?)])(1 )(2 )]

"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23546)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/20/2018 9:28:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 9:28:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/20/2018 9:17:15 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/20/2018 9:12:14 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎20T03:38:32.587714500Z.
Information	9/20/2018 9:12:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 18496.
Information	9/20/2018 9:12:14 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/20/2018 9:12:14 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	9/20/2018 9:12:14 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4457027. Installation success or error status: 0.
Information	9/20/2018 9:12:14 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4457027' installed successfully.
Information	9/20/2018 9:09:40 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:09:39 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:09:38 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:09:38 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:09:37 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:09:37 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/20/2018 9:08:32 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎20T03:38:32.587714500Z.
Information	9/20/2018 9:08:29 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 18496.
Information	9/20/2018 9:07:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2018 9:07:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:34Z. Reason: GVLK.
Information	9/20/2018 9:06:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 688803ef-bc86-11e8-b123-204747d02364
Report Status: 0"
Information	9/20/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 9:02:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2018 8:54:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2018 8:54:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:56:28Z. Reason: GVLK.
Error	9/20/2018 8:50:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/20/2018 8:49:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2018 8:49:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2018 8:49:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2018 8:49:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/20/2018 8:48:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/20/2018 8:48:02 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/20/2018 8:47:41 AM	MTAService.OnSessionChange	0	None	8:47:41 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/20/2018 8:46:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/20/2018 8:46:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/19/2018 1:05:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2018 1:05:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:49Z. Reason: GVLK.
Information	9/19/2018 1:00:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2018 1:00:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 1:00:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2018 1:00:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/19/2018 1:00:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 12:50:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/19/2018 12:50:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/19/2018 12:42:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9020.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/19/2018 12:20:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/19/2018 12:20:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/19/2018 12:18:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/19/2018 12:18:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/19/2018 11:50:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/19/2018 11:50:25 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/19/2018 11:06:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 10:50:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/19/2018 10:50:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/19/2018 10:50:25 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/19/2018 10:50:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/19/2018 10:16:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb4919ee-bbc6-11e8-b123-204747d02364
Report Status: 0"
Information	9/19/2018 9:31:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2018 9:31:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-26T03:55:46Z. Reason: GVLK.
Information	9/19/2018 9:26:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 9:26:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 9:26:45 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/09/19 03:56"
Information	9/19/2018 9:26:45 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/09/19 03:56, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	9/19/2018 9:22:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 9:21:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2018 9:21:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 9:21:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2018 9:21:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/19/2018 7:43:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 6:50:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2018 6:50:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/19/2018 6:10:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 6:07:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2018 6:07:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:41Z. Reason: GVLK.
Information	9/19/2018 6:02:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2018 6:02:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 6:02:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2018 6:02:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/19/2018 5:16:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 016fbcd0-bb9d-11e8-b123-204747d02364
Report Status: 0"
Information	9/19/2018 4:51:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2018 4:51:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:15Z. Reason: GVLK.
Information	9/19/2018 4:46:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2018 4:46:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 4:46:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2018 4:46:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/19/2018 4:43:53 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/19/2018 4:40:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2018 4:40:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:55Z. Reason: GVLK.
Error	9/19/2018 4:36:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/19/2018 4:35:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2018 4:35:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2018 4:35:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2018 4:35:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/19/2018 4:16:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 2:50:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2018 2:49:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/19/2018 2:22:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 2:10:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/19/2018 2:08:51 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/19/2018 1:33:10 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824298644_320029711122652500536388101450481110.msi. Client Process Id: 11296.
Information	9/19/2018 1:33:10 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	9/19/2018 1:33:10 AM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	9/19/2018 1:33:09 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/19/2018 1:33:06 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	9/19/2018 1:32:58 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824298644_320029711122652500536388101450481110.msi. Client Process Id: 11296.
Warning	9/19/2018 12:48:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/19/2018 12:16:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17a92215-bb73-11e8-b123-204747d02364
Report Status: 0"
Information	9/19/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/18/2018 11:13:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 10:55:45 PM	MTAService.OnSessionChange	0	None	10:55:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 10:49:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 10:49:54 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/18/2018 10:49:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/18/2018 9:32:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 9:12:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 9:12:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:07Z. Reason: GVLK.
Information	9/18/2018 9:07:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2018 9:07:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 9:07:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 9:07:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/18/2018 7:39:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 7:16:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2dacfbf6-bb49-11e8-b123-204747d02364
Report Status: 0"
Information	9/18/2018 6:54:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 6:49:47 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 967

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1310

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 748

Information	9/18/2018 6:49:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 6:48:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 25866)(?)])(1 )(2 )]

"
Information	9/18/2018 6:48:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2018 6:48:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 25866)(?)])(1 )(2 )]

"
Information	9/18/2018 6:48:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 25866)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 6:48:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2018 6:48:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 6:48:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2018 6:38:09 PM	MTAService.OnSessionChange	0	None	6:38:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 6:12:18 PM	MTAService.OnSessionChange	0	None	6:12:18 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/18/2018 6:00:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 5:54:27 PM	MTAService.OnSessionChange	0	None	5:54:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 5:01:32 PM	MTAService.OnSessionChange	0	None	5:01:32 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 5:00:22 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.4.0.10518. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	9/18/2018 5:00:22 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	9/18/2018 5:00:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:29:53.038116700Z.
Information	9/18/2018 5:00:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2BA199A0-78FE-4143-90FA-63B051896844}\DeviceManager.msi. Client Process Id: 16280.
Information	9/18/2018 4:59:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:29:53.038116700Z.
Information	9/18/2018 4:59:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2BA199A0-78FE-4143-90FA-63B051896844}\DeviceManager.msi. Client Process Id: 16280.
Information	9/18/2018 4:59:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:28:11.537267800Z.
Information	9/18/2018 4:59:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{34C4499E-7609-4ADA-8BCB-1A0D28F6FB76}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 17608.
Information	9/18/2018 4:59:48 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.10518. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	9/18/2018 4:59:48 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	9/18/2018 4:58:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:28:11.537267800Z.
Information	9/18/2018 4:58:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{34C4499E-7609-4ADA-8BCB-1A0D28F6FB76}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 17608.
Information	9/18/2018 4:58:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:28:06.139807600Z.
Information	9/18/2018 4:58:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{A9755188-A598-32E6-8144-484F02D69961}v2.1.13029.0\aspnetcore-runtime-2.1.2-win-x86.msi. Client Process Id: 17640.
Information	9/18/2018 4:58:09 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft ASP.NET Core 2.1.2 Shared Framework (x86). Product Version: 2.1.13029.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	9/18/2018 4:58:09 PM	MsiInstaller	11707	None	Product: Microsoft ASP.NET Core 2.1.2 Shared Framework (x86) -- Installation completed successfully.
Information	9/18/2018 4:58:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:28:06.139807600Z.
Information	9/18/2018 4:58:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{A9755188-A598-32E6-8144-484F02D69961}v2.1.13029.0\aspnetcore-runtime-2.1.2-win-x86.msi. Client Process Id: 17640.
Information	9/18/2018 4:57:49 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:27:41.266181000Z.
Information	9/18/2018 4:57:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{CB629434-E249-4221-A823-FCB9955528ED}v16.72.26629\dotnet-host-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:57:49 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Host - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	9/18/2018 4:57:49 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Host - 2.1.2 (x86) -- Installation completed successfully.
Information	9/18/2018 4:57:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:27:41.266181000Z.
Information	9/18/2018 4:57:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:27:38.758435500Z.
Information	9/18/2018 4:57:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{CB629434-E249-4221-A823-FCB9955528ED}v16.72.26629\dotnet-host-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:57:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{992AD548-D862-452B-996D-4D1373BE163A}v16.72.26629\dotnet-hostfxr-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:57:41 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Host FX Resolver - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	9/18/2018 4:57:41 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Host FX Resolver - 2.1.2 (x86) -- Installation completed successfully.
Information	9/18/2018 4:57:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:27:38.758435500Z.
Information	9/18/2018 4:57:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{992AD548-D862-452B-996D-4D1373BE163A}v16.72.26629\dotnet-hostfxr-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:57:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{D992B414-0108-47B8-9872-CEEF6DD8253A}v16.72.26629\dotnet-runtime-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:57:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:27:34.632499500Z.
Information	9/18/2018 4:57:38 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Core Runtime - 2.1.2 (x86). Product Version: 16.72.26629. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	9/18/2018 4:57:38 PM	MsiInstaller	11707	None	Product: Microsoft .NET Core Runtime - 2.1.2 (x86) -- Installation completed successfully.
Information	9/18/2018 4:57:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:27:34.632499500Z.
Information	9/18/2018 4:57:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{D992B414-0108-47B8-9872-CEEF6DD8253A}v16.72.26629\dotnet-runtime-2.1.2-win-x86.msi. Client Process Id: 16720.
Information	9/18/2018 4:53:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:23:33.919916000Z.
Information	9/18/2018 4:53:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15484.
Information	9/18/2018 4:53:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	9/18/2018 4:53:38 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	9/18/2018 4:53:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:23:33.919916000Z.
Information	9/18/2018 4:53:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15484.
Information	9/18/2018 4:52:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:22:10.274116600Z.
Information	9/18/2018 4:52:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:52:34 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	9/18/2018 4:52:34 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	9/18/2018 4:52:28 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:52:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:22:10.274116600Z.
Information	9/18/2018 4:52:08 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:47:08 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	9/18/2018 4:47:08 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	9/18/2018 4:47:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:16:34.387574200Z.
Information	9/18/2018 4:47:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3E6BA960-366C-401C-88A7-1122E219AB93}\DeviceManager.msi. Client Process Id: 19116.
Information	9/18/2018 4:46:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:16:34.387574200Z.
Information	9/18/2018 4:46:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3E6BA960-366C-401C-88A7-1122E219AB93}\DeviceManager.msi. Client Process Id: 19116.
Information	9/18/2018 4:45:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:15:12.292365500Z.
Information	9/18/2018 4:45:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{09B2B74E-5CB8-4BA8-98B8-C184E9BF9D28}\DeviceDriver.msi. Client Process Id: 5704.
Information	9/18/2018 4:45:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	9/18/2018 4:45:20 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	9/18/2018 4:45:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:15:12.292365500Z.
Information	9/18/2018 4:45:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{09B2B74E-5CB8-4BA8-98B8-C184E9BF9D28}\DeviceDriver.msi. Client Process Id: 5704.
Information	9/18/2018 4:44:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:14:13.482485100Z.
Information	9/18/2018 4:44:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15484.
Information	9/18/2018 4:44:18 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	9/18/2018 4:44:18 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	9/18/2018 4:44:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:14:13.482485100Z.
Information	9/18/2018 4:44:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15484.
Information	9/18/2018 4:44:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Reconfiguration success or error status: 1602.
Information	9/18/2018 4:44:08 PM	MsiInstaller	11729	None	Product: DeviceDriver -- Configuration failed.
Information	9/18/2018 4:43:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:13:42.451382300Z.
Information	9/18/2018 4:43:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:43:54 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	9/18/2018 4:43:54 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	9/18/2018 4:43:51 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:13:42.451382300Z.
Information	9/18/2018 4:43:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:43:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:34.157553000Z.
Information	9/18/2018 4:43:34 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:34.157553000Z.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:33.809518200Z.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:33.809518200Z.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:33.611498400Z.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:33.611498400Z.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:32.825419800Z.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:32.825419800Z.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:32.561393400Z.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:32.561393400Z.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:28.874024700Z.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:28.874024700Z.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:28.090946400Z.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:28.090946400Z.
Information	9/18/2018 4:43:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎18T11:13:26.397777100Z.
Information	9/18/2018 4:43:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:43:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎18T11:13:26.397777100Z.
Information	9/18/2018 4:42:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T11:11:29.168055300Z.
Information	9/18/2018 4:42:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:42:09 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 1602.
Information	9/18/2018 4:42:09 PM	MsiInstaller	11725	None	Product: DeviceManager -- Removal failed.
Information	9/18/2018 4:41:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	9/18/2018 4:41:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T11:11:29.168055300Z.
Information	9/18/2018 4:41:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15484.
Information	9/18/2018 4:31:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	9/18/2018 4:31:11 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	9/18/2018 4:30:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T10:59:56.427788200Z.
Information	9/18/2018 4:30:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1557DE7F-8A23-4DA3-9EA2-96F719F16535}\DeviceManager.msi. Client Process Id: 19256.
Information	9/18/2018 4:29:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T10:59:56.427788200Z.
Information	9/18/2018 4:29:55 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1557DE7F-8A23-4DA3-9EA2-96F719F16535}\DeviceManager.msi. Client Process Id: 19256.
Error	9/18/2018 4:29:54 PM	MsiInstaller	11500	None	Product: DeviceManager -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.
Information	9/18/2018 4:29:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T10:59:31.408286500Z.
Information	9/18/2018 4:29:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DDDDB3AE-D6B9-41A8-A5A1-6F90763B6A82}\DeviceDriver.msi. Client Process Id: 17016.
Information	9/18/2018 4:29:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	9/18/2018 4:29:42 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	9/18/2018 4:29:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T10:59:31.408286500Z.
Information	9/18/2018 4:29:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DDDDB3AE-D6B9-41A8-A5A1-6F90763B6A82}\DeviceDriver.msi. Client Process Id: 17016.
Warning	9/18/2018 4:24:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 4:15:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T10:45:10.715225800Z.
Information	9/18/2018 4:15:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 11160.
Information	9/18/2018 4:15:18 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.191. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	9/18/2018 4:15:18 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	9/18/2018 4:15:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T10:45:10.715225800Z.
Information	9/18/2018 4:15:08 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 11160.
Information	9/18/2018 3:59:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T10:28:07.206885200Z.
Information	9/18/2018 3:59:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 11160.
Information	9/18/2018 3:59:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.3.0.191. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	9/18/2018 3:59:11 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	9/18/2018 3:58:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T10:28:07.206885200Z.
Information	9/18/2018 3:57:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 11160.
Information	9/18/2018 3:56:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎09‎-‎18T10:26:33.848550300Z.
Information	9/18/2018 3:56:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 11160.
Information	9/18/2018 3:56:54 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Driver Manager. Product Version: 1.3.0.0. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	9/18/2018 3:56:54 PM	MsiInstaller	11724	None	Product: Driver Manager -- Removal completed successfully.
Information	9/18/2018 3:56:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎09‎-‎18T10:26:33.848550300Z.
Information	9/18/2018 3:56:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 11160.
Information	9/18/2018 3:54:32 PM	MTAService.OnSessionChange	0	None	3:54:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 3:37:40 PM	MTAService.OnSessionChange	0	None	3:37:40 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 3:35:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/18/2018 3:24:48 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/18/2018 3:24:47 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/18/2018 3:16:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26083)(?)])(1 )(2 )]

"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26083)(?)])(1 )(2 )]

"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26083)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2018 3:11:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 3:11:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/18/2018 2:50:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 2:50:18 PM	MTAService.OnSessionChange	0	None	2:50:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 2:46:10 PM	MTAService.OnSessionChange	0	None	2:46:10 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 2:41:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:41:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:41:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:40:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/18/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26129)(?)])(1 )(2 )]

"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26129)(?)])(1 )(2 )]

"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26129)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2018 2:17:00 PM	MTAService.OnSessionChange	0	None	2:17:00 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 2:16:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43e5edba-bb1f-11e8-b123-204747d02364
Report Status: 0"
Information	9/18/2018 2:12:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 2:11:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:54:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:54:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:48:31 PM	MTAService.OnSessionChange	0	None	1:48:31 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 1:45:57 PM	MTAService.OnSessionChange	0	None	1:45:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 1:45:49 PM	MTAService.OnSessionChange	0	None	1:45:49 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 1:39:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:39:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:36:09 PM	MTAService.OnSessionChange	0	None	1:36:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 1:24:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:23:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:21:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:20:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:19:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:19:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 1:13:29 PM	MTAService.OnSessionChange	0	None	1:13:29 PM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 1:09:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 1:09:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:54:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:54:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/18/2018 12:51:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 12:49:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:49:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:47:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:46:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:43:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:43:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:19:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:17:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:04:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9019.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/18/2018 12:01:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 12:00:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 12:00:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 11:59:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 11:57:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 11:56:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 11:49:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 11:48:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 11:44:24 AM	MTAService.OnSessionChange	0	None	11:44:24 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 11:42:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 11:41:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 11:40:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 11:39:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 11:30:18 AM	MTAService.OnSessionChange	0	None	11:30:18 AM - Session change notice received: SessionLock Session ID: 1
Information	9/18/2018 11:16:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	9/18/2018 11:16:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 11:16:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 10:51:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2018 10:51:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2018 10:41:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 10:41:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 10:41:13 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/18/2018 10:40:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	9/18/2018 10:40:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/18/2018 9:45:05 AM	MTAService.OnSessionChange	0	None	9:45:05 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 9:23:25 AM	MTAService.OnSessionChange	0	None	9:23:25 AM - Session change notice received: SessionLock Session ID: 1
Warning	9/18/2018 9:18:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 9:15:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 59e2ee1e-baf5-11e8-b123-204747d02364
Report Status: 0"
Information	9/18/2018 9:01:58 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	9/18/2018 8:54:12 AM	MTAService.OnSessionChange	0	None	8:54:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/18/2018 8:12:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 8:12:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:23Z. Reason: GVLK.
Information	9/18/2018 8:07:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2018 8:07:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 8:07:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 8:07:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/18/2018 7:20:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 6:41:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 6:40:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/18/2018 5:30:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 4:15:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7008ad10-bacb-11e8-b123-204747d02364
Report Status: 0"
Information	9/18/2018 4:13:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 4:13:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:52Z. Reason: GVLK.
Information	9/18/2018 4:08:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2018 4:08:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 4:08:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 4:08:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/18/2018 3:52:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 3:21:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 3:21:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:13Z. Reason: GVLK.
Information	9/18/2018 3:16:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2018 3:16:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 3:16:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 3:16:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/18/2018 3:13:23 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/18/2018 3:05:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2018 3:05:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:15Z. Reason: GVLK.
Error	9/18/2018 3:01:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/18/2018 3:00:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2018 3:00:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2018 3:00:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2018 3:00:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2018 2:41:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:40:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2018 2:40:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/18/2018 1:58:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/18/2018 12:10:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/18/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/17/2018 11:15:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 85ff2301-baa1-11e8-b123-204747d02364
Report Status: 0"
Information	9/17/2018 10:41:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 10:40:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 10:40:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/17/2018 10:40:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/17/2018 10:17:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 10:03:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2018 10:03:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:49Z. Reason: GVLK.
Information	9/17/2018 9:58:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2018 9:58:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 9:58:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 9:58:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/17/2018 8:43:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 7:55:23 PM	MTAService.OnSessionChange	0	None	7:55:23 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/17/2018 7:05:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 7:01:26 PM	MTAService.OnSessionChange	0	None	7:01:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 6:50:47 PM	MTAService.OnSessionChange	0	None	6:50:47 PM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 6:41:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 6:40:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 6:40:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/17/2018 6:16:19 PM	MTAService.OnSessionChange	0	None	6:16:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 6:15:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9bd9402a-ba77-11e8-b123-204747d02364
Report Status: 0"
Information	9/17/2018 5:48:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2018 5:48:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:04Z. Reason: GVLK.
Information	9/17/2018 5:43:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2018 5:43:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 5:43:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 5:43:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/17/2018 5:34:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 4:43:14 PM	MTAService.OnSessionChange	0	None	4:43:14 PM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 4:02:15 PM	MTAService.OnSessionChange	0	None	4:02:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 3:57:43 PM	MTAService.OnSessionChange	0	None	3:57:43 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/17/2018 3:57:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 3:24:23 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/17/2018 3:24:23 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/17/2018 2:41:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 2:40:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 2:30:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/17/2018 2:25:24 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/17/2018 2:25:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27569)(?)])(1 )(2 )]

"
Information	9/17/2018 2:25:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/17/2018 2:25:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27569)(?)])(1 )(2 )]

"
Information	9/17/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27569)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 2:25:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/17/2018 2:25:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 2:25:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/17/2018 2:23:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 2:17:47 PM	MTAService.OnSessionChange	0	None	2:17:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 1:56:36 PM	MTAService.OnSessionChange	0	None	1:56:36 PM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 1:48:57 PM	MTAService.OnSessionChange	0	None	1:48:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 1:30:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2018 1:30:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:41Z. Reason: GVLK.
Information	9/17/2018 1:25:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2018 1:25:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 1:25:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 1:25:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2018 1:22:58 PM	MTAService.OnSessionChange	0	None	1:22:58 PM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 1:15:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1b0d1be-ba4d-11e8-b123-204747d02364
Report Status: 0"
Information	9/17/2018 12:54:36 PM	MTAService.OnSessionChange	0	None	12:54:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 12:33:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9018.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Warning	9/17/2018 12:32:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 12:30:03 PM	MTAService.OnSessionChange	0	None	12:30:03 PM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 11:56:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/17/2018 11:56:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/17/2018 11:55:12 AM	MTAService.OnSessionChange	0	None	11:55:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 11:53:13 AM	MTAService.OnSessionChange	0	None	11:53:13 AM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 11:46:30 AM	MTAService.OnSessionChange	0	None	11:46:30 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 11:43:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2018 11:43:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:44Z. Reason: GVLK.
Information	9/17/2018 11:38:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2018 11:38:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 11:38:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 11:38:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2018 11:30:37 AM	MTAService.OnSessionChange	0	None	11:30:37 AM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 11:29:20 AM	MTAService.OnSessionChange	0	None	11:29:20 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 11:20:54 AM	MTAService.OnSessionChange	0	None	11:20:54 AM - Session change notice received: SessionLock Session ID: 1
Information	9/17/2018 10:46:50 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 61, Deleted: 0, Modified: 221, Compared: 27092, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/17/2018 10:45:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	9/17/2018 10:41:44 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x80940819). If this error continues, contact Microsoft Support.
Information	9/17/2018 10:41:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 10:41:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/17/2018 10:41:00 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 421

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 296

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Warning	9/17/2018 10:40:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/17/2018 10:40:47 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/17/2018 10:40:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/17/2018 10:40:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/17/2018 10:40:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/17/2018 10:40:46 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/17/2018 10:40:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/17/2018 10:40:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/17/2018 10:40:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/17/2018 10:39:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/17/2018 10:39:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27795)(?)])(1 )(2 )]

"
Information	9/17/2018 10:39:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/17/2018 10:39:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27795)(?)])(1 )(2 )]

"
Information	9/17/2018 10:39:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27795)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 10:39:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/17/2018 10:39:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 10:39:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/17/2018 10:37:41 AM	MTAService.OnSessionChange	0	None	10:37:41 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/17/2018 3:47:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2018 3:47:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:46Z. Reason: GVLK.
Error	9/17/2018 3:42:20 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	9/17/2018 3:41:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/17/2018 3:41:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2018 3:41:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2018 3:41:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2018 3:41:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/16/2018 2:30:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/16/2018 2:25:21 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/16/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29009)(?)])(1 )(2 )]

"
Information	9/16/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/16/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29009)(?)])(1 )(2 )]

"
Information	9/16/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29009)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2018 2:25:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2018 2:25:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2018 2:25:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2018 4:32:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/16/2018 4:32:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:29Z. Reason: GVLK.
Error	9/16/2018 4:27:01 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	9/16/2018 4:25:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/16/2018 4:24:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/16/2018 4:24:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2018 4:24:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2018 4:24:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/16/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/15/2018 2:30:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/15/2018 2:25:21 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/15/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 30449)(?)])(1 )(2 )]

"
Information	9/15/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 30449)(?)])(1 )(2 )]

"
Information	9/15/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 30449)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2018 2:25:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2018 2:25:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2018 2:25:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2018 3:30:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/15/2018 3:30:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:29Z. Reason: GVLK.
Error	9/15/2018 3:25:03 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	9/15/2018 3:23:46 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/15/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/15/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2018 3:23:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/15/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/14/2018 2:30:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/14/2018 2:25:21 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/14/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 31889)(?)])(1 )(2 )]

"
Information	9/14/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 31889)(?)])(1 )(2 )]

"
Information	9/14/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 31889)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2018 2:25:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/14/2018 2:25:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2018 2:25:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/14/2018 6:46:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2018 6:46:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:46Z. Reason: GVLK.
Information	9/14/2018 6:41:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2018 6:41:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2018 6:41:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2018 6:41:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2018 4:57:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2018 4:57:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:37Z. Reason: GVLK.
Error	9/14/2018 4:52:06 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	9/14/2018 4:50:29 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/14/2018 4:50:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2018 4:50:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2018 4:50:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2018 4:50:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/13/2018 2:30:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/13/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/13/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 33329)(?)])(1 )(2 )]

"
Information	9/13/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/13/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 33329)(?)])(1 )(2 )]

"
Information	9/13/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 33329)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2018 2:25:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/13/2018 2:25:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/13/2018 4:04:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2018 4:04:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:41Z. Reason: GVLK.
Information	9/13/2018 3:59:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2018 3:59:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2018 3:59:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2018 3:59:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/13/2018 3:58:25 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/13/2018 3:57:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2018 3:57:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:14Z. Reason: GVLK.
Error	9/13/2018 3:52:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/13/2018 3:52:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2018 3:52:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2018 3:52:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2018 3:52:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/12/2018 4:40:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 4:40:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:13Z. Reason: GVLK.
Information	9/12/2018 4:35:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 4:35:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 4:35:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 4:35:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 4:29:00 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/12/2018 4:26:52 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/12/2018 4:10:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 4:10:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:12Z. Reason: GVLK.
Information	9/12/2018 4:09:36 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/12/2018 4:01:41 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	9/12/2018 4:01:41 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	9/12/2018 4:01:41 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	9/12/2018 4:01:41 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	9/12/2018 4:01:41 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	9/12/2018 4:01:40 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	9/12/2018 4:01:38 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	9/12/2018 4:01:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 4:01:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 4:01:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 4:01:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 4:01:36 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	9/12/2018 3:40:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 3:40:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:13Z. Reason: GVLK.
Information	9/12/2018 3:35:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 3:35:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 3:35:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 3:35:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 3:30:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 3:30:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:59Z. Reason: GVLK.
Information	9/12/2018 3:30:04 PM	MTAService.OnSessionChange	0	None	3:30:04 PM - Session change notice received: SessionLock Session ID: 1
Information	9/12/2018 3:29:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 3:25:13 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/12/2018 3:24:13 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/12/2018 3:24:12 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/12/2018 3:24:08 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	9/12/2018 3:24:07 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {048E215A-34F2-4390-9A0C-D9DBEA02C67B}
Error	9/12/2018 3:24:07 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {048E215A-34F2-4390-9A0C-D9DBEA02C67B}
Information	9/12/2018 3:24:06 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/12/2018 3:23:49 PM	ESENT	302	Logging/Recovery	Windows (9104) Windows: The database engine has successfully completed recovery steps.
Information	9/12/2018 3:23:47 PM	ESENT	301	Logging/Recovery	Windows (9104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Error	9/12/2018 3:23:32 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/12/2018 3:23:23 PM	ESENT	301	Logging/Recovery	Windows (9104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00AB5.log.
Information	9/12/2018 3:23:23 PM	ESENT	300	Logging/Recovery	Windows (9104) Windows: The database engine is initiating recovery steps.
Information	9/12/2018 3:23:23 PM	ESENT	102	General	Windows (9104) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/12/2018 3:23:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 3:23:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 3:23:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 3:23:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34711)(?)])(1 )(2 )]

"
Information	9/12/2018 3:23:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2018 3:23:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34711)(?)])(1 )(2 )]

"
Information	9/12/2018 3:23:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34711)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 3:23:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2018 3:23:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 3:23:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 3:23:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 3:23:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9013.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Error	9/12/2018 3:21:56 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	9/12/2018 3:21:27 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/12/2018 3:21:24 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/12/2018 3:21:13 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/12/2018 3:21:04 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/12/2018 3:21:02 PM	PostgreSQL	0	None	"2018-09-12 15:21:02 IST LOG:  redirecting log output to logging collector process
2018-09-12 15:21:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Error	9/12/2018 3:20:38 PM	Service1	0	None	"Service cannot be started. System.Runtime.InteropServices.COMException (0x80010002): Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementScope.InitializeGuts(Object o)
   at System.Management.ManagementScope.Initialize()
   at System.Management.ManagementObjectSearcher.Initialize()
   at System.Management.ManagementObjectSearcher.Get()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)"
Information	9/12/2018 3:20:10 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/12/2018 3:19:57 PM	MTAService	0	None	Service started successfully.
Information	9/12/2018 3:19:26 PM	MTAService.OnStart	0	None	3:19:26 PM - User is already logged in : 212558710
Information	9/12/2018 3:19:26 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:26 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/12/2018 3:19:26 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/12/2018 3:19:26 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/12/2018 3:19:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/12/2018 3:19:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/12/2018 3:19:24 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database msdb (database ID 4) in 1 second(s) (analysis 496 ms, redo 0 ms, undo 352 ms.) This is an informational message only. No user action is required.
Information	9/12/2018 3:19:24 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:24 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/12/2018 3:19:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/12/2018 3:19:21 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/12/2018 3:19:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/12/2018 3:19:20 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:20 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/12/2018 3:19:20 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/12/2018 3:19:19 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/12/2018 3:19:19 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/12/2018 3:19:19 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/12/2018 3:19:17 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/12/2018 3:19:17 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/12/2018 3:19:17 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4536 at 9/12/2018 3:09:03 PM (local) 9/12/2018 9:39:03 AM (UTC). This is an informational message only; no user action is required.
Information	9/12/2018 3:19:15 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/12/2018 3:19:14 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/12/2018 3:19:13 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/12/2018 3:19:13 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/12/2018 3:19:13 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/12/2018 3:19:13 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4544.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/12/2018 3:19:01 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	9/12/2018 3:18:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/12/2018 3:18:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	9/12/2018 3:18:15 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/12/2018 3:17:55 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/12/2018 3:17:19 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/12/2018 3:17:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/12/2018 3:17:19 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/12/2018 3:09:03 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	9/12/2018 3:08:18 PM	Application Error	1000	(100)	"Faulting application name: ge_runasuser.exe, version: 2.2.3.0, time stamp: 0x5a0b6741
Faulting module name: RPCRT4.dll, version: 6.1.7601.24150, time stamp: 0x5b0cb981
Exception code: 0xc0000005
Fault offset: 0x000276f4
Faulting process id: 0x48e0
Faulting application start time: 0x01d44a7c4cf2dac7
Faulting application path: C:\Program Files\MTA\Tools\RunAsUser\ge_runasuser.exe
Faulting module path: C:\Windows\syswow64\RPCRT4.dll
Report Id: 93d65847-b66f-11e8-bd95-204747d02364"
Warning	9/12/2018 3:07:38 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 19832 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Information	9/12/2018 3:07:36 PM	MTAService.OnSessionChange	0	None	3:07:36 PM - Logoff
Information	9/12/2018 3:07:36 PM	MTAService.OnSessionChange	0	None	3:07:36 PM - Session change notice received: SessionLogoff Session ID: 1
Warning	9/12/2018 3:07:35 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 30 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 180 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 19832 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2260 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/12/2018 3:07:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/12/2018 3:07:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/12/2018 3:07:24 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/12/2018 3:06:56 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/12/2018 3:06:43 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	9/12/2018 2:34:59 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 41059 milliseconds
Information	9/12/2018 2:34:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 2:34:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:52:30Z. Reason: GVLK.
Information	9/12/2018 2:32:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	9/12/2018 2:30:10 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 3132 did not respond and is being forcibly terminated {filter host process 4748}. 

Information	9/12/2018 2:29:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 2:29:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 2:29:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 2:29:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/12/2018 2:26:41 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/12/2018 2:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34768)(?)])(1 )(2 )]

"
Information	9/12/2018 2:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2018 2:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34768)(?)])(1 )(2 )]

"
Information	9/12/2018 2:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 34768)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 2:26:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2018 2:26:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 2:26:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 2:25:22 PM	MTAService.OnSessionChange	0	None	2:25:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/12/2018 2:19:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/12/2018 1:46:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 1:15:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: db3c3027-b65f-11e8-bd95-204747d02364
Report Status: 0"
Information	9/12/2018 12:54:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9013.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/12/2018 12:51:04 PM	MTAService.OnSessionChange	0	None	12:51:04 PM - Session change notice received: SessionLock Session ID: 1
Information	9/12/2018 12:49:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/12/2018 12:49:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/12/2018 11:50:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 11:47:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/12/2018 11:47:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/12/2018 11:36:35 AM	MTAService.OnSessionChange	0	None	11:36:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/12/2018 11:35:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/12/2018 11:35:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/12/2018 11:12:30 AM	MTAService.OnSessionChange	0	None	11:12:30 AM - Session change notice received: SessionLock Session ID: 1
Information	9/12/2018 11:03:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/12/2018 11:03:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/12/2018 10:53:13 AM	MTAService.OnSessionChange	0	None	10:53:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/12/2018 10:45:15 AM	MTAService.OnSessionChange	0	None	10:45:15 AM - Session change notice received: SessionLock Session ID: 1
Information	9/12/2018 10:35:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 10:30:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 35004)(?)])(1 )(2 )]

"
Information	9/12/2018 10:30:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2018 10:30:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 35004)(?)])(1 )(2 )]

"
Information	9/12/2018 10:30:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 35004)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 10:30:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2018 10:30:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 10:30:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 10:19:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2018 10:19:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/12/2018 10:08:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 10:07:43 AM	Outlook	54	None	An appointment has been deleted from the calendar because the corresponding meeting request was deleted without responding. Subject: Declined: ERT team meeting Current User: Dole, Abhijit (BHGE) Flags: 0x00000000 Start Time: 9/12/2018 4:00 PM End Time: 9/12/2018 5:00 PM EntryID: .
Information	9/12/2018 10:06:25 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/12/2018 10:04:36 AM	MTAService.OnSessionChange	0	None	10:04:36 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/12/2018 9:34:45 AM	MTAService.OnSessionChange	0	None	9:34:45 AM - Session change notice received: SessionLock Session ID: 1
Information	9/12/2018 9:27:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 9:27:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-19T03:51:34Z. Reason: GVLK.
Information	9/12/2018 9:22:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 9:22:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 9:22:33 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/09/12 03:52"
Information	9/12/2018 9:22:32 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/09/12 03:52, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/12/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2018 9:12:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/12/2018 9:12:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/12/2018 8:55:23 AM	MTAService.OnSessionChange	0	None	8:55:23 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/12/2018 8:27:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 8:15:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f1434bd1-b635-11e8-bd95-204747d02364
Report Status: 0"
Information	9/12/2018 6:58:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 6:58:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:29Z. Reason: GVLK.
Information	9/12/2018 6:53:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 6:53:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 6:53:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 6:53:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/12/2018 6:32:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 6:19:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2018 5:15:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 5:15:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:15Z. Reason: GVLK.
Information	9/12/2018 5:10:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 5:10:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 5:10:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 5:10:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/12/2018 5:08:24 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/12/2018 5:04:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2018 5:04:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:38Z. Reason: GVLK.
Error	9/12/2018 4:59:53 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/12/2018 4:59:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2018 4:59:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2018 4:59:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2018 4:59:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/12/2018 4:50:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 3:15:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0762eb98-b60c-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/12/2018 3:13:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 2:19:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/12/2018 1:16:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/12/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/11/2018 11:23:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 10:24:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 10:24:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:21Z. Reason: GVLK.
Information	9/11/2018 10:19:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 10:19:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 10:19:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 10:19:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2018 10:18:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 10:15:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1d8d0ba4-b5e2-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/11/2018 9:52:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/11/2018 7:52:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 7:09:45 PM	MTAService.OnSessionChange	0	None	7:09:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/11/2018 6:18:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 6:15:46 PM	MTAService.OnSessionChange	0	None	6:15:46 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/11/2018 6:11:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 5:39:37 PM	MTAService.OnSessionChange	0	None	5:39:37 PM - Session change notice received: SessionLock Session ID: 1
Information	9/11/2018 5:15:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 33b53407-b5b8-11e8-bd95-204747d02364
Report Status: 0"
Information	9/11/2018 5:08:39 PM	MTAService.OnSessionChange	0	None	5:08:39 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/11/2018 4:40:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 3:19:41 PM	MTAService.OnSessionChange	0	None	3:19:41 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/11/2018 3:08:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 2:31:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 2:30:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 2:30:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/11/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 36209)(?)])(1 )(2 )]

"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 36209)(?)])(1 )(2 )]

"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 36209)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/11/2018 2:25:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/11/2018 2:18:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 2:05:24 PM	MTAService.OnSessionChange	0	None	2:05:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/11/2018 1:36:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 1:36:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:15Z. Reason: GVLK.
Warning	9/11/2018 1:35:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 1:31:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 1:31:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 1:31:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 1:31:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2018 1:13:12 PM	MTAService.OnSessionChange	0	None	1:13:12 PM - Session change notice received: SessionLock Session ID: 1
Information	9/11/2018 12:56:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 12:56:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 12:41:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 12:40:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 12:37:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 12:37:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 12:35:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 12:34:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 12:15:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 49d4c0e7-b58e-11e8-bd95-204747d02364
Report Status: 0"
Information	9/11/2018 12:08:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9012.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/11/2018 12:08:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 12:07:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 11:50:12 AM	MTAService.OnSessionChange	0	None	11:50:12 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/11/2018 11:49:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 11:30:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 11:30:22 AM	MTAService.OnSessionChange	0	None	11:30:22 AM - Session change notice received: SessionLock Session ID: 1
Information	9/11/2018 11:30:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 10:56:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2018 10:56:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2018 10:18:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/11/2018 10:12:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 9:46:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/11/2018 9:45:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/11/2018 9:45:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/11/2018 9:45:20 AM	MTAService.OnSessionChange	0	None	9:45:20 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/11/2018 9:00:52 AM	MTAService.OnSessionChange	0	None	9:00:52 AM - Session change notice received: SessionLock Session ID: 1
Information	9/11/2018 8:45:35 AM	MTAService.OnSessionChange	0	None	8:45:35 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/11/2018 8:36:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 7:43:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 7:43:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:18Z. Reason: GVLK.
Information	9/11/2018 7:38:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 7:38:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 7:38:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 7:38:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2018 7:15:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5fe1e185-b564-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/11/2018 6:39:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 6:18:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 6:18:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 5:08:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 5:08:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:23Z. Reason: GVLK.
Information	9/11/2018 5:03:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 5:03:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 5:03:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 5:03:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/11/2018 5:01:28 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	9/11/2018 5:01:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 4:57:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 4:57:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:32Z. Reason: GVLK.
Error	9/11/2018 4:52:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/11/2018 4:52:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 4:52:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 4:52:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 4:52:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2018 3:52:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2018 3:52:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:48:01Z. Reason: GVLK.
Information	9/11/2018 3:47:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2018 3:47:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2018 3:47:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2018 3:47:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/11/2018 3:19:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 2:18:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 2:18:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2018 2:15:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 761ee26c-b53a-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/11/2018 1:21:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/11/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/10/2018 11:50:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 10:18:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2018 10:18:06 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/10/2018 10:18:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/10/2018 9:52:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 9:15:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c73337d-b510-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/10/2018 8:05:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 7:51:26 PM	MTAService.OnSessionChange	0	None	7:51:26 PM - Session change notice received: SessionLock Session ID: 1
Information	9/10/2018 7:50:54 PM	MTAService.OnSessionChange	0	None	7:50:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/10/2018 7:50:13 PM	MTAService.OnSessionChange	0	None	7:50:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/10/2018 6:19:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 6:18:33 PM	MTAService.OnSessionChange	0	None	6:18:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/10/2018 6:17:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2018 5:13:37 PM	MTAService.OnSessionChange	0	None	5:13:37 PM - Session change notice received: SessionLock Session ID: 1
Information	9/10/2018 4:47:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 4:42:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37512)(?)])(1 )(2 )]

"
Information	9/10/2018 4:42:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/10/2018 4:42:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37512)(?)])(1 )(2 )]

"
Information	9/10/2018 4:42:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37512)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 4:42:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2018 4:42:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 4:42:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/10/2018 4:35:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 4:15:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2b8e72d-b4e6-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/10/2018 2:59:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 2:54:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9011.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!040cd888e971 (ED)
"
Information	9/10/2018 2:32:52 PM	MTAService.OnSessionChange	0	None	2:32:52 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/10/2018 2:30:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/10/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/10/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37649)(?)])(1 )(2 )]

"
Information	9/10/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/10/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37649)(?)])(1 )(2 )]

"
Information	9/10/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37649)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/10/2018 2:17:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/10/2018 1:19:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 12:56:02 PM	MTAService.OnSessionChange	0	None	12:56:02 PM - Session change notice received: SessionLock Session ID: 1
Information	9/10/2018 12:55:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9011.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/10/2018 12:48:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/10/2018 12:48:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/10/2018 11:56:27 AM	MTAService.OnSessionChange	0	None	11:56:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/10/2018 11:29:15 AM	MTAService.OnSessionChange	0	None	11:29:15 AM - Session change notice received: SessionLock Session ID: 1
Warning	9/10/2018 11:28:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 11:15:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b8e84dfe-b4bc-11e8-bd95-204747d02364
Report Status: 0"
Information	9/10/2018 10:22:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 10:17:44 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 172

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	9/10/2018 10:17:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2018 10:17:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37897)(?)])(1 )(2 )]

"
Information	9/10/2018 10:17:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/10/2018 10:17:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37897)(?)])(1 )(2 )]

"
Information	9/10/2018 10:17:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37897)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 10:17:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2018 10:17:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 10:17:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/10/2018 10:08:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 10:08:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:55Z. Reason: GVLK.
Information	9/10/2018 10:03:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2018 10:03:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 10:03:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 10:03:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/10/2018 9:54:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 9:52:10 AM	MTAService.OnSessionChange	0	None	9:52:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/10/2018 9:24:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/10/2018 9:24:43 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/10/2018 9:24:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/10/2018 9:24:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/10/2018 9:24:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/10/2018 9:24:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 27173, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/10/2018 9:22:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/10/2018 9:22:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/10/2018 9:22:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/10/2018 9:12:36 AM	MTAService.OnSessionChange	0	None	9:12:36 AM - Session change notice received: SessionLock Session ID: 1
Information	9/10/2018 8:43:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 8:38:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/10/2018 8:38:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2018 8:38:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/10/2018 8:38:23 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/10/2018 8:38:23 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/10/2018 8:38:22 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 561

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 421

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 219

Information	9/10/2018 8:37:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2018 8:37:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37997)(?)])(1 )(2 )]

"
Information	9/10/2018 8:37:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/10/2018 8:37:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37997)(?)])(1 )(2 )]

"
Information	9/10/2018 8:37:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 37997)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 8:37:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2018 8:37:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 8:37:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/10/2018 8:34:59 AM	MTAService.OnSessionChange	0	None	8:34:59 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/10/2018 7:57:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 6:15:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cea40ffe-b492-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/10/2018 6:09:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/10/2018 4:16:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 4:00:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 4:00:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:10Z. Reason: GVLK.
Information	9/10/2018 3:55:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2018 3:55:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 3:55:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 3:55:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/10/2018 3:53:33 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/10/2018 3:51:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 3:51:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:52Z. Reason: GVLK.
Error	9/10/2018 3:47:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/10/2018 3:46:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2018 3:46:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 3:46:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 3:46:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2018 3:42:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2018 3:42:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:24Z. Reason: GVLK.
Information	9/10/2018 3:37:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2018 3:37:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2018 3:37:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2018 3:37:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/10/2018 2:39:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 1:15:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e4f5c79f-b468-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/10/2018 12:56:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/10/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/9/2018 11:09:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 9:32:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 8:15:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fb4e8501-b43e-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/9/2018 7:39:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 5:53:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 3:59:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 3:15:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 119c28c1-b415-11e8-bd95-204747d02364
Report Status: 0"
Information	9/9/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/9/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39089)(?)])(1 )(2 )]

"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39089)(?)])(1 )(2 )]

"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 39089)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/9/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/9/2018 2:24:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 1:28:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2018 1:28:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:58Z. Reason: GVLK.
Information	9/9/2018 1:23:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2018 1:23:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 1:23:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 1:23:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/9/2018 12:43:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9010.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	9/9/2018 12:37:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 11:02:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 10:15:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27e4a993-b3eb-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/9/2018 9:31:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 8:15:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2018 8:15:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:48:03Z. Reason: GVLK.
Information	9/9/2018 8:10:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2018 8:10:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 8:10:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 8:10:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/9/2018 7:37:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 5:41:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 5:15:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3e3ece73-b3c1-11e8-bd95-204747d02364
Report Status: 0"
Information	9/9/2018 4:39:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2018 4:39:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:49Z. Reason: GVLK.
Information	9/9/2018 4:34:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2018 4:34:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 4:34:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 4:34:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/9/2018 4:32:18 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/9/2018 4:30:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2018 4:30:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:08Z. Reason: GVLK.
Error	9/9/2018 4:25:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/9/2018 4:21:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2018 4:21:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 4:21:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 4:21:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/9/2018 4:10:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 2:59:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2018 2:59:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:58Z. Reason: GVLK.
Information	9/9/2018 2:54:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2018 2:54:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2018 2:54:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2018 2:54:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/9/2018 2:19:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/9/2018 12:43:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/9/2018 12:15:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53d167e2-b397-11e8-bd95-204747d02364
Report Status: 0"
Information	9/9/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/8/2018 11:11:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 9:35:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 8:04:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 7:15:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a27218b-b36d-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/8/2018 6:12:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 5:42:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2018 5:42:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:46Z. Reason: GVLK.
Information	9/8/2018 5:37:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2018 5:37:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2018 5:37:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2018 5:37:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/8/2018 4:30:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 2:33:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/8/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/8/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40529)(?)])(1 )(2 )]

"
Information	9/8/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/8/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40529)(?)])(1 )(2 )]

"
Information	9/8/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 40529)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/8/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/8/2018 2:15:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 808e3825-b343-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/8/2018 12:39:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 12:27:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9009.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	9/8/2018 10:42:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 9:15:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96d0423d-b319-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/8/2018 8:53:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 7:15:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 5:26:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 4:15:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad255876-b2ef-11e8-bd95-204747d02364
Report Status: 0"
Information	9/8/2018 3:48:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2018 3:48:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:12Z. Reason: GVLK.
Information	9/8/2018 3:43:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2018 3:43:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2018 3:43:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2018 3:43:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/8/2018 3:41:29 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/8/2018 3:38:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2018 3:38:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:09Z. Reason: GVLK.
Error	9/8/2018 3:33:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/8/2018 3:33:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2018 3:33:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2018 3:33:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2018 3:33:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/8/2018 3:32:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/8/2018 1:59:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 1:48:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2018 1:48:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:46Z. Reason: GVLK.
Information	9/8/2018 1:43:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2018 1:43:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2018 1:43:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2018 1:43:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/8/2018 12:22:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/8/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/7/2018 11:15:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c38856f6-b2c5-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/7/2018 10:51:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/7/2018 9:06:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/7/2018 7:08:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 6:15:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9d83020-b29b-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/7/2018 5:36:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/7/2018 3:59:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 3:14:51 PM	MTAService.OnSessionChange	0	None	3:14:51 PM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 2:54:47 PM	MTAService.OnSessionChange	0	None	2:54:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 2:52:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 2:52:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 2:51:02 PM	MTAService.OnSessionChange	0	None	2:51:02 PM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/7/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41969)(?)])(1 )(2 )]

"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41969)(?)])(1 )(2 )]

"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 41969)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/7/2018 2:09:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 1:53:50 PM	MTAService.OnSessionChange	0	None	1:53:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 1:15:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f0179918-b271-11e8-bd95-204747d02364
Report Status: 0"
Information	9/7/2018 1:08:17 PM	MTAService.OnSessionChange	0	None	1:08:17 PM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 1:06:53 PM	MTAService.OnSessionChange	0	None	1:06:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 12:49:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9008.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/7/2018 12:47:47 PM	MTAService.OnSessionChange	0	None	12:47:47 PM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 12:33:52 PM	MTAService.OnSessionChange	0	None	12:33:52 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 12:30:04 PM	MTAService.OnSessionChange	0	None	12:30:04 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/7/2018 12:24:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 12:08:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/7/2018 12:07:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/7/2018 11:45:22 AM	MTAService.OnSessionChange	0	None	11:45:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 11:32:47 AM	MTAService.OnSessionChange	0	None	11:32:47 AM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 11:20:58 AM	MTAService.OnSessionChange	0	None	11:20:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 11:17:45 AM	MTAService.OnSessionChange	0	None	11:17:45 AM - Session change notice received: SessionLock Session ID: 1
Information	9/7/2018 10:52:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 10:52:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 10:50:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 10:45:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42189)(?)])(1 )(2 )]

"
Information	9/7/2018 10:45:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/7/2018 10:45:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42189)(?)])(1 )(2 )]

"
Information	9/7/2018 10:45:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 42189)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 10:45:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2018 10:45:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 10:45:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/7/2018 10:34:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 10:08:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/7/2018 10:07:56 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/7/2018 10:07:45 AM	MTAService.OnSessionChange	0	None	10:07:45 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/7/2018 10:05:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	9/7/2018 8:49:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 8:41:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 8:41:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:44Z. Reason: GVLK.
Information	9/7/2018 8:36:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2018 8:36:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 8:36:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 8:36:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2018 8:15:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0639491c-b248-11e8-bd95-204747d02364
Report Status: 0"
Information	9/7/2018 6:52:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 6:52:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/7/2018 6:50:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 6:08:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 6:08:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:05Z. Reason: GVLK.
Information	9/7/2018 6:03:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2018 6:03:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 6:03:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 6:03:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/7/2018 5:18:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 4:46:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 4:46:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:42Z. Reason: GVLK.
Information	9/7/2018 4:41:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2018 4:41:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 4:41:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 4:41:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2018 3:31:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 3:31:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:12Z. Reason: GVLK.
Warning	9/7/2018 3:26:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 3:26:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2018 3:26:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 3:26:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 3:26:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/7/2018 3:24:27 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/7/2018 3:20:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2018 3:20:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:48Z. Reason: GVLK.
Error	9/7/2018 3:16:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2018 3:15:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2018 3:15:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1c84e1b0-b21e-11e8-bd95-204747d02364
Report Status: 0"
Information	9/7/2018 2:52:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2018 2:52:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/7/2018 1:40:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/7/2018 12:04:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/6/2018 10:52:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 10:52:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/6/2018 10:21:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 10:15:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 32d0aeb0-b1f4-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/6/2018 8:46:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 7:55:25 PM	MTAService.OnSessionChange	0	None	7:55:25 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 6:57:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 6:57:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:28Z. Reason: GVLK.
Warning	9/6/2018 6:55:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 6:52:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 6:52:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 6:52:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 6:52:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 6:52:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 6:52:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 5:53:30 PM	MTAService.OnSessionChange	0	None	5:53:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 5:15:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 490995cb-b1ca-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/6/2018 5:05:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 4:51:48 PM	MTAService.OnSessionChange	0	None	4:51:48 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 4:51:35 PM	MTAService.OnSessionChange	0	None	4:51:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 4:50:58 PM	MTAService.OnSessionChange	0	None	4:50:58 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 4:17:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎06T10:47:36.836122400Z.
Information	9/6/2018 4:17:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎06T10:47:36.836122400Z.
Information	9/6/2018 4:17:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎09‎-‎06T10:47:34.230861900Z.
Information	9/6/2018 4:17:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎09‎-‎06T10:47:34.230861900Z.
Information	9/6/2018 4:16:39 PM	MTAService.OnSessionChange	0	None	4:16:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 4:09:47 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/6/2018 4:09:45 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/6/2018 4:09:39 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 27211, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/6/2018 4:07:47 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/6/2018 3:58:22 PM	MTAService.OnSessionChange	0	None	3:58:22 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 3:40:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 3:35:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2018 3:35:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43339)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/6/2018 3:35:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 3:35:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 3:20:15 PM	MTAService.OnSessionChange	0	None	3:20:15 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/6/2018 3:08:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 3:07:14 PM	MTAService.OnSessionChange	0	None	3:07:14 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 3:02:56 PM	MTAService.OnSessionChange	0	None	3:02:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 2:56:31 PM	MTAService.OnSessionChange	0	None	2:56:31 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 2:52:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 2:51:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 2:34:57 PM	MTAService.OnSessionChange	0	None	2:34:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/6/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/6/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43409)(?)])(1 )(2 )]

"
Information	9/6/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43409)(?)])(1 )(2 )]

"
Information	9/6/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43409)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/6/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 2:01:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/6/2018 2:01:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/6/2018 1:41:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/6/2018 1:41:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/6/2018 1:27:58 PM	MTAService.OnSessionChange	0	None	1:27:58 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/6/2018 1:16:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 1:03:26 PM	MTAService.OnSessionChange	0	None	1:03:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 1:00:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/6/2018 12:59:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/6/2018 12:55:59 PM	MTAService.OnSessionChange	0	None	12:55:59 PM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 12:36:09 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9007.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/6/2018 12:15:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 12:15:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:48:02Z. Reason: GVLK.
Information	9/6/2018 12:14:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5f3e9e3f-b1a0-11e8-bd95-204747d02364
Report Status: 0"
Information	9/6/2018 12:10:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 12:10:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 12:10:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 12:09:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 11:53:38 AM	MTAService.OnSessionChange	0	None	11:53:38 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 11:36:11 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/6/2018 11:36:10 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/6/2018 11:31:11 AM	MTAService.OnSessionChange	0	None	11:31:11 AM - Session change notice received: SessionLock Session ID: 1
Warning	9/6/2018 11:18:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 10:52:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 10:52:12 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/6/2018 10:51:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2018 10:19:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 10:14:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43660)(?)])(1 )(2 )]

"
Information	9/6/2018 10:14:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2018 10:14:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43660)(?)])(1 )(2 )]

"
Information	9/6/2018 10:14:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43660)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 10:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43661)(?)])(1 )(2 )]

"
Information	9/6/2018 10:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2018 10:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43661)(?)])(1 )(2 )]

"
Information	9/6/2018 10:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 43661)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 10:13:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/6/2018 10:13:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 10:13:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 10:04:15 AM	MTAService.OnSessionChange	0	None	10:04:15 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 10:00:57 AM	MTAService.OnSessionChange	0	None	10:00:57 AM - Session change notice received: SessionLock Session ID: 1
Information	9/6/2018 9:50:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/6/2018 9:49:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/6/2018 9:49:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/6/2018 9:49:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/6/2018 9:49:18 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/6/2018 9:49:13 AM	MTAService.OnSessionChange	0	None	9:49:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/6/2018 9:49:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 9:49:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:48:01Z. Reason: GVLK.
Information	9/6/2018 9:44:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 9:44:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 9:44:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 9:44:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/6/2018 9:43:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/6/2018 8:10:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 7:14:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7595424e-b176-11e8-bd95-204747d02364
Report Status: 0"
Information	9/6/2018 6:51:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/6/2018 6:16:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 4:40:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 4:40:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:31Z. Reason: GVLK.
Information	9/6/2018 4:35:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 4:35:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 4:35:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 4:35:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/6/2018 4:33:34 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/6/2018 4:30:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 4:30:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:23Z. Reason: GVLK.
Error	9/6/2018 4:25:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 4:25:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 4:25:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/6/2018 4:19:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 2:52:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2018 2:52:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:47Z. Reason: GVLK.
Information	9/6/2018 2:51:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/6/2018 2:48:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 2:47:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2018 2:47:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2018 2:47:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2018 2:47:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2018 2:26:20 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/6/2018 2:24:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/6/2018 2:14:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8bf3579f-b14c-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/6/2018 1:17:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/6/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/5/2018 11:33:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 10:51:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/5/2018 9:51:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 9:17:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 9:14:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2495f6a-b122-11e8-bd95-204747d02364
Report Status: 0"
Information	9/5/2018 9:12:39 PM	MTAService.OnSessionChange	0	None	9:12:39 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 9:12:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/5/2018 9:12:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 9:12:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/5/2018 8:02:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 6:51:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2018 6:16:21 PM	MTAService.OnSessionChange	0	None	6:16:21 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/5/2018 6:11:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 5:41:00 PM	MTAService.OnSessionChange	0	None	5:41:00 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 5:20:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 5:15:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44679)(?)])(1 )(2 )]

"
Information	9/5/2018 5:15:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/5/2018 5:15:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44679)(?)])(1 )(2 )]

"
Information	9/5/2018 5:15:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44679)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 5:15:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/5/2018 5:15:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 5:15:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/5/2018 5:00:31 PM	MTAService.OnSessionChange	0	None	5:00:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 4:58:44 PM	MTAService.OnSessionChange	0	None	4:58:44 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/5/2018 4:18:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 4:14:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b856fdc4-b0f8-11e8-bd95-204747d02364
Report Status: 0"
Information	9/5/2018 4:05:58 PM	MTAService.OnSessionChange	0	None	4:05:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 3:49:40 PM	MTAService.OnSessionChange	0	None	3:49:40 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 3:37:32 PM	MTAService.OnSessionChange	0	None	3:37:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 2:58:51 PM	MTAService.OnSessionChange	0	None	2:58:51 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 2:56:12 PM	MTAService.OnSessionChange	0	None	2:56:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 2:51:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2018 2:41:47 PM	MTAService.OnSessionChange	0	None	2:41:47 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 2:32:48 PM	MTAService.OnSessionChange	0	None	2:32:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 2:30:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/5/2018 2:25:51 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/5/2018 2:25:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44849)(?)])(1 )(2 )]

"
Information	9/5/2018 2:25:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/5/2018 2:25:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44849)(?)])(1 )(2 )]

"
Information	9/5/2018 2:25:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 44849)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 2:25:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/5/2018 2:25:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 2:25:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/5/2018 2:19:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 1:33:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 1:33:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/5/2018 1:28:52 PM	MTAService.OnSessionChange	0	None	1:28:52 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 1:25:19 PM	MTAService.OnSessionChange	0	None	1:25:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 1:23:31 PM	MTAService.OnSessionChange	0	None	1:23:31 PM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 12:31:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 12:30:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/5/2018 12:29:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 12:28:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 12:28:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/5/2018 12:24:24 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9006.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/5/2018 12:20:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 12:20:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/5/2018 12:18:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 12:18:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/5/2018 11:49:54 AM	MTAService.OnSessionChange	0	None	11:49:54 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 11:30:12 AM	MTAService.OnSessionChange	0	None	11:30:12 AM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 11:21:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/5/2018 11:21:13 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/5/2018 11:14:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ce735654-b0ce-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/5/2018 10:52:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 10:51:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2018 9:49:23 AM	MTAService.OnSessionChange	0	None	9:49:23 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/5/2018 9:26:53 AM	MTAService.OnSessionChange	0	None	9:26:53 AM - Session change notice received: SessionLock Session ID: 1
Information	9/5/2018 9:23:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 9:23:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-12T03:47:05Z. Reason: GVLK.
Information	9/5/2018 9:20:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/5/2018 9:19:51 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/5/2018 9:18:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 9:18:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 9:18:04 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/09/05 03:48"
Information	9/5/2018 9:18:03 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/09/05 03:48, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/5/2018 9:14:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/5/2018 9:03:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2018 9:03:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 9:03:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 9:03:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2018 9:02:24 AM	MTAService.OnSessionChange	0	None	9:02:24 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/5/2018 8:58:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 7:27:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 7:27:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:14Z. Reason: GVLK.
Information	9/5/2018 7:22:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2018 7:22:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 7:22:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 7:22:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/5/2018 7:14:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 6:50:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2018 6:14:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e4cbb754-b0a4-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/5/2018 5:25:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 5:05:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 5:05:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:11Z. Reason: GVLK.
Information	9/5/2018 5:00:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2018 5:00:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 5:00:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 5:00:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/5/2018 4:58:18 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/5/2018 4:55:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2018 4:55:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:11Z. Reason: GVLK.
Error	9/5/2018 4:50:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/5/2018 4:50:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2018 4:50:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2018 4:50:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2018 4:50:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/5/2018 3:53:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 2:50:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2018 2:44:30 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/5/2018 2:42:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	9/5/2018 2:02:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 1:14:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fb3025fa-b07a-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/5/2018 12:20:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/5/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/4/2018 10:50:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/4/2018 10:33:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/4/2018 8:36:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 8:14:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1168dc6e-b051-11e8-bd95-204747d02364
Report Status: 0"
Information	9/4/2018 8:00:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 7:55:06 PM	MTAService.OnSessionChange	0	None	7:55:06 PM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 7:55:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2018 7:55:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 7:55:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 6:50:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	9/4/2018 6:37:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 6:32:16 PM	MTAService.OnSessionChange	0	None	6:32:16 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 6:17:51 PM	MTAService.OnSessionChange	0	None	6:17:51 PM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 6:08:22 PM	MTAService.OnSessionChange	0	None	6:08:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 5:06:49 PM	MTAService.OnSessionChange	0	None	5:06:49 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/4/2018 5:00:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 4:13:04 PM	MTAService.OnSessionChange	0	None	4:13:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 4:04:09 PM	MTAService.OnSessionChange	0	None	4:04:09 PM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 3:14:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27a4e75b-b027-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/4/2018 3:12:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 2:50:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/4/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46289)(?)])(1 )(2 )]

"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46289)(?)])(1 )(2 )]

"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46289)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 2:14:55 PM	MTAService.OnSessionChange	0	None	2:14:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 1:34:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 1:34:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 1:26:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 1:26:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:50Z. Reason: GVLK.
Warning	9/4/2018 1:22:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 1:21:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2018 1:21:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 1:21:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 1:21:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 1:07:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 1:07:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:49:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:49:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:40:45 PM	MTAService.OnSessionChange	0	None	12:40:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 12:39:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:39:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:37:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9005.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/4/2018 12:32:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:31:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:31:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 12:26:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46408)(?)])(1 )(2 )]

"
Information	9/4/2018 12:26:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/4/2018 12:26:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46408)(?)])(1 )(2 )]

"
Information	9/4/2018 12:26:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46408)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 12:26:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2018 12:26:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 12:26:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 12:25:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:25:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:21:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:20:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:18:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:17:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 12:04:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 12:03:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 11:50:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:50:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 11:48:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:47:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 11:47:11 AM	MTAService.OnSessionChange	0	None	11:47:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 11:43:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:43:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 11:41:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:40:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/4/2018 11:38:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 11:35:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:35:12 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 11:31:26 AM	MTAService.OnSessionChange	0	None	11:31:26 AM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 11:23:40 AM	MTAService.OnSessionChange	0	None	11:23:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/4/2018 11:11:33 AM	MTAService.OnSessionChange	0	None	11:11:33 AM - Session change notice received: SessionLock Session ID: 1
Information	9/4/2018 11:01:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/4/2018 11:01:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/4/2018 10:55:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 10:53:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 10:53:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:41Z. Reason: GVLK.
Information	9/4/2018 10:51:12 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/4/2018 10:50:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/4/2018 10:50:45 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/4/2018 10:50:42 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	9/4/2018 10:50:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2018 10:50:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46504)(?)])(1 )(2 )]

"
Information	9/4/2018 10:50:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/4/2018 10:50:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46504)(?)])(1 )(2 )]

"
Information	9/4/2018 10:50:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 46504)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 10:49:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2018 10:49:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 10:49:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 10:48:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2018 10:48:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 10:48:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 10:48:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 10:14:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3de105bf-affd-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/4/2018 10:05:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	9/4/2018 9:57:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	9/4/2018 9:57:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/4/2018 9:54:00 AM	MTAService.OnSessionChange	0	None	9:54:00 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	9/4/2018 8:25:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/4/2018 6:31:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 5:14:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 541a0054-afd3-11e8-bd95-204747d02364
Report Status: 0"
Warning	9/4/2018 4:40:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 4:25:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 4:25:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:22Z. Reason: GVLK.
Information	9/4/2018 4:20:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2018 4:20:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 4:20:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 4:20:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/4/2018 4:18:43 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/4/2018 4:15:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 4:15:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:24Z. Reason: GVLK.
Error	9/4/2018 4:10:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/4/2018 4:10:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2018 4:10:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 4:10:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 4:10:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2018 3:53:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2018 3:53:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:43Z. Reason: GVLK.
Information	9/4/2018 3:48:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2018 3:48:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2018 3:48:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2018 3:48:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/4/2018 2:56:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/4/2018 1:15:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/4/2018 12:14:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a3a42f1-afa9-11e8-bd95-204747d02364
Report Status: 0"
Information	9/4/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	9/3/2018 11:15:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	9/3/2018 9:31:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 8:20:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 8:20:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:21Z. Reason: GVLK.
Information	9/3/2018 8:15:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 8:15:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 8:15:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 8:15:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 8:06:27 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/3/2018 7:33:48 PM	MTAService.OnSessionChange	0	None	7:33:48 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/3/2018 7:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 7:14:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 805eac23-af7f-11e8-bd95-204747d02364
Report Status: 0"
Information	9/3/2018 6:59:49 PM	MTAService.OnSessionChange	0	None	6:59:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 6:43:32 PM	MTAService.OnSessionChange	0	None	6:43:32 PM - Session change notice received: SessionLock Session ID: 1
Warning	9/3/2018 5:56:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 5:54:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 5:54:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 5:49:57 PM	MTAService.OnSessionChange	0	None	5:49:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 5:08:53 PM	MTAService.OnSessionChange	0	None	5:08:53 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 4:55:28 PM	MTAService.OnSessionChange	0	None	4:55:28 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 4:32:14 PM	MTAService.OnSessionChange	0	None	4:32:14 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 4:10:06 PM	MTAService.OnSessionChange	0	None	4:10:06 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 4:09:01 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/3/2018 4:09:00 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/3/2018 4:08:27 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 14, Compared: 26982, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Warning	9/3/2018 4:07:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 4:06:55 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/3/2018 3:56:45 PM	MTAService.OnSessionChange	0	None	3:56:45 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 3:09:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 3:04:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 47690)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 3:04:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 47690)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 3:04:28 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/3/2018 3:04:28 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/3/2018 3:04:28 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	9/3/2018 3:04:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2018 3:04:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 3:04:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/3/2018 2:35:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/3/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/3/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 47729)(?)])(1 )(2 )]

"
Information	9/3/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 47729)(?)])(1 )(2 )]

"
Information	9/3/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 47729)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 2:14:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96781d96-af55-11e8-bd95-204747d02364
Report Status: 0"
Information	9/3/2018 2:05:37 PM	MTAService.OnSessionChange	0	None	2:05:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 1:54:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 1:54:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 1:24:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/3/2018 1:24:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/3/2018 1:13:02 PM	MTAService.OnSessionChange	0	None	1:13:02 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 1:00:06 PM	MTAService.OnSessionChange	0	None	1:00:06 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 12:57:02 PM	MTAService.OnSessionChange	0	None	12:57:02 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 12:54:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/3/2018 12:54:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/3/2018 12:49:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 12:33:29 PM	MTAService.OnSessionChange	0	None	12:33:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 12:32:16 PM	MTAService.OnSessionChange	0	None	12:32:16 PM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 12:22:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/3/2018 12:22:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/3/2018 12:21:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/3/2018 12:20:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/3/2018 11:48:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	9/3/2018 11:48:32 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/3/2018 11:42:47 AM	MTAService.OnSessionChange	0	None	11:42:47 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 11:33:48 AM	MTAService.OnSessionChange	0	None	11:33:48 AM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 11:32:56 AM	MTAService.OnSessionChange	0	None	11:32:56 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 11:29:29 AM	MTAService.OnSessionChange	0	None	11:29:29 AM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 11:10:15 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/3/2018 11:09:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	9/3/2018 10:57:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	9/3/2018 10:51:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 10:51:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:50Z. Reason: GVLK.
Information	9/3/2018 10:46:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 10:46:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 10:46:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 10:46:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 10:28:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 10:28:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:39Z. Reason: GVLK.
Information	9/3/2018 10:23:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 10:23:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 10:23:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 10:23:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:59:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:58:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:58:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:41Z. Reason: GVLK.
Information	9/3/2018 9:54:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 9:54:34 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 437

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 483

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 32

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 561

Information	9/3/2018 9:54:33 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/3/2018 9:54:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2018 9:53:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 9:53:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:53:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:53:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48001)(?)])(1 )(2 )]

"
Information	9/3/2018 9:53:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2018 9:53:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48001)(?)])(1 )(2 )]

"
Information	9/3/2018 9:53:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48001)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:53:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:53:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2018 9:53:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:53:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:51:56 AM	MTAService.OnSessionChange	0	None	9:51:56 AM - Session change notice received: SessionUnlock Session ID: 1
Information	9/3/2018 9:50:22 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9004.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/3/2018 9:38:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:38:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:00Z. Reason: GVLK.
Information	9/3/2018 9:33:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 9:33:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:33:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:32:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	9/3/2018 9:31:12 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/3/2018 9:30:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:30:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:33Z. Reason: GVLK.
Information	9/3/2018 9:30:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/3/2018 9:25:17 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	9/3/2018 9:25:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48029)(?)])(1 )(2 )]

"
Information	9/3/2018 9:25:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2018 9:25:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48029)(?)])(1 )(2 )]

"
Information	9/3/2018 9:25:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48029)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:25:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2018 9:25:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:25:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:20:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 9:20:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:20:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:20:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:18:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:18:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:58Z. Reason: GVLK.
Information	9/3/2018 9:17:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2018 9:17:12 AM	MTAService.OnSessionChange	0	None	9:17:12 AM - Session change notice received: SessionLock Session ID: 1
Information	9/3/2018 9:14:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: abc662e1-af2b-11e8-bd95-204747d02364
Report Status: 0"
Error	9/3/2018 9:13:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/3/2018 9:13:12 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/3/2018 9:11:55 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2018 9:11:54 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2018 9:11:53 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	9/3/2018 9:11:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/3/2018 9:11:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/3/2018 9:11:25 AM	ESENT	302	Logging/Recovery	Windows (8280) Windows: The database engine has successfully completed recovery steps.
Information	9/3/2018 9:11:23 AM	ESENT	301	Logging/Recovery	Windows (8280) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/3/2018 9:11:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2018 9:11:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:11:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:11:16 AM	ESENT	301	Logging/Recovery	Windows (8280) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00A8A.log.
Information	9/3/2018 9:11:16 AM	ESENT	300	Logging/Recovery	Windows (8280) Windows: The database engine is initiating recovery steps.
Information	9/3/2018 9:11:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:11:15 AM	ESENT	102	General	Windows (8280) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/3/2018 9:11:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48043)(?)])(1 )(2 )]

"
Information	9/3/2018 9:11:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2018 9:11:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48043)(?)])(1 )(2 )]

"
Information	9/3/2018 9:11:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 48043)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2018 9:11:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2018 9:11:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2018 9:11:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2018 9:11:06 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9001.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	9/3/2018 9:09:40 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/3/2018 9:09:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/3/2018 9:09:28 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Error	9/3/2018 9:09:02 AM	Service1	0	None	"Service cannot be started. System.Runtime.InteropServices.COMException (0x80010002): Call was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementScope.InitializeGuts(Object o)
   at System.Management.ManagementScope.Initialize()
   at System.Management.ManagementObjectSearcher.Initialize()
   at System.Management.ManagementObjectSearcher.Get()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)"
Information	9/3/2018 9:08:51 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/3/2018 9:08:49 AM	PostgreSQL	0	None	"2018-09-03 09:08:49 IST LOG:  redirecting log output to logging collector process
2018-09-03 09:08:49 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/3/2018 9:08:20 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/3/2018 9:08:13 AM	MTAService	0	None	Service started successfully.
Information	9/3/2018 9:07:54 AM	MTAService.OnStart	0	None	9:07:54 AM - User is already logged in : 212558710
Information	9/3/2018 9:07:51 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:51 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/3/2018 9:07:51 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/3/2018 9:07:51 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/3/2018 9:07:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/3/2018 9:07:49 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/3/2018 9:07:48 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/3/2018 9:07:47 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/3/2018 9:07:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/3/2018 9:07:47 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:47 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/3/2018 9:07:46 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/3/2018 9:07:45 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/3/2018 9:07:45 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/3/2018 9:07:45 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/3/2018 9:07:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/3/2018 9:07:42 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/3/2018 9:07:42 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4228 at 8/31/2018 4:15:26 PM (local) 8/31/2018 10:45:26 AM (UTC). This is an informational message only; no user action is required.
Information	9/3/2018 9:07:37 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/3/2018 9:07:36 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/3/2018 9:07:36 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/3/2018 9:07:36 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/3/2018 9:07:36 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/3/2018 9:07:36 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4536.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/3/2018 9:07:26 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	9/3/2018 9:07:24 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/3/2018 9:07:24 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	9/3/2018 9:06:34 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/3/2018 9:06:26 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2018 9:06:02 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/3/2018 9:06:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/31/2018 4:15:36 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/3/2018 9:06:02 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/31/2018 4:15:26 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	8/31/2018 4:15:05 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 21 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 12424 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4280 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 532 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4280 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/31/2018 4:15:06 PM	MTAService.OnSessionChange	0	None	4:15:06 PM - Logoff
Information	8/31/2018 4:15:06 PM	MTAService.OnSessionChange	0	None	4:15:06 PM - Session change notice received: SessionLogoff Session ID: 2
Information	8/31/2018 4:15:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 2

"
Information	8/31/2018 4:15:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/31/2018 4:15:03 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/31/2018 4:14:48 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	8/31/2018 4:14:37 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	8/31/2018 3:48:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2018 3:42:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2018 3:11:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 3:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52008)(?)])(1 )(2 )]

"
Information	8/31/2018 3:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/31/2018 3:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52008)(?)])(1 )(2 )]

"
Information	8/31/2018 3:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52008)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 3:06:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/31/2018 3:06:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 3:06:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/31/2018 3:00:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 2:30:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/31/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/31/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52049)(?)])(1 )(2 )]

"
Information	8/31/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/31/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52049)(?)])(1 )(2 )]

"
Information	8/31/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52049)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/31/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/31/2018 2:24:47 PM	MTAService.OnSessionChange	0	None	2:24:47 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 1:20:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/31/2018 1:20:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/31/2018 1:12:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a0545aa-acf1-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/31/2018 1:11:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 12:41:21 PM	MTAService.OnSessionChange	0	None	12:41:21 PM - Session change notice received: SessionLock Session ID: 2
Information	8/31/2018 12:39:37 PM	MTAService.OnSessionChange	0	None	12:39:37 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 12:35:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9001.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/31/2018 12:33:12 PM	MTAService.OnSessionChange	0	None	12:33:12 PM - Session change notice received: SessionLock Session ID: 2
Information	8/31/2018 11:48:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2018 11:45:27 AM	MTAService.OnSessionChange	0	None	11:45:27 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 11:42:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/31/2018 11:33:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 11:26:25 AM	MTAService.OnSessionChange	0	None	11:26:25 AM - Session change notice received: SessionLock Session ID: 2
Information	8/31/2018 11:17:09 AM	MTAService.OnSessionChange	0	None	11:17:09 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 11:13:25 AM	MTAService.OnSessionChange	0	None	11:13:25 AM - Session change notice received: SessionLock Session ID: 2
Information	8/31/2018 10:38:30 AM	MTAService.OnSessionChange	0	None	10:38:30 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 10:30:01 AM	MTAService.OnSessionChange	0	None	10:30:01 AM - Session change notice received: SessionLock Session ID: 2
Information	8/31/2018 10:13:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 10:13:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:20Z. Reason: GVLK.
Information	8/31/2018 10:11:59 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/31/2018 10:11:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/31/2018 10:09:15 AM	MTAService.OnSessionChange	0	None	10:09:15 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/31/2018 10:08:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 10:08:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 10:08:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 10:08:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/31/2018 9:39:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 9:13:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/31/2018 8:12:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 703d3c8a-acc7-11e8-ab22-204747d02364
Report Status: 0"
Information	8/31/2018 7:47:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/31/2018 7:42:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 7:42:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/31/2018 5:59:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 4:46:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 4:46:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:41Z. Reason: GVLK.
Information	8/31/2018 4:41:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 4:41:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 4:41:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 4:41:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2018 4:27:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 4:27:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:58Z. Reason: GVLK.
Information	8/31/2018 4:22:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 4:22:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 4:22:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 4:22:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/31/2018 4:21:16 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/31/2018 4:18:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 4:18:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:03Z. Reason: GVLK.
Error	8/31/2018 4:13:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/31/2018 4:13:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 4:13:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 4:13:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 4:13:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/31/2018 4:00:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 3:47:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2018 3:42:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2018 3:28:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 3:28:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:43Z. Reason: GVLK.
Information	8/31/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 3:23:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2018 3:12:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8682a629-ac9d-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/31/2018 2:07:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 2:02:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2018 2:02:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:01Z. Reason: GVLK.
Information	8/31/2018 1:57:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2018 1:57:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2018 1:57:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2018 1:57:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/31/2018 12:17:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/31/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/30/2018 11:47:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 11:41:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/30/2018 10:40:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 10:11:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cd6b217-ac73-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/30/2018 8:52:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 7:55:58 PM	MTAService.OnSessionChange	0	None	7:55:58 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 7:47:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 7:41:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/30/2018 7:08:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 6:54:26 PM	MTAService.OnSessionChange	0	None	6:54:26 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 6:18:05 PM	MTAService.OnSessionChange	0	None	6:18:05 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 6:10:32 PM	MTAService.OnSessionChange	0	None	6:10:32 PM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/30/2018 5:28:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 5:11:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b30f168e-ac49-11e8-ab22-204747d02364
Report Status: 0"
Information	8/30/2018 5:06:39 PM	MTAService.OnSessionChange	0	None	5:06:39 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 5:03:58 PM	MTAService.OnSessionChange	0	None	5:03:58 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 4:47:20 PM	MTAService.OnSessionChange	0	None	4:47:20 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 4:45:57 PM	MTAService.OnSessionChange	0	None	4:45:57 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 4:43:32 PM	MTAService.OnSessionChange	0	None	4:43:32 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 4:21:13 PM	MTAService.OnSessionChange	0	None	4:21:13 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 4:12:50 PM	MTAService.OnSessionChange	0	None	4:12:50 PM - Session change notice received: SessionLock Session ID: 2
Warning	8/30/2018 3:54:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 3:47:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 3:46:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 3:46:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/30/2018 3:42:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53412)(?)])(1 )(2 )]

"
Information	8/30/2018 3:42:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/30/2018 3:42:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53412)(?)])(1 )(2 )]

"
Information	8/30/2018 3:42:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53412)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 3:41:37 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 110

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	8/30/2018 3:41:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 3:40:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53414)(?)])(1 )(2 )]

"
Information	8/30/2018 3:40:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/30/2018 3:40:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53414)(?)])(1 )(2 )]

"
Information	8/30/2018 3:40:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53414)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 3:40:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/30/2018 3:40:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 3:40:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/30/2018 3:39:43 PM	MTAService.OnSessionChange	0	None	3:39:43 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 3:36:28 PM	MTAService.OnSessionChange	0	None	3:36:28 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 3:12:53 PM	MTAService.OnSessionChange	0	None	3:12:53 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 2:54:10 PM	MTAService.OnSessionChange	0	None	2:54:10 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 2:25:39 PM	MTAService.OnSessionChange	0	None	2:25:39 PM - Session change notice received: SessionUnlock Session ID: 2
Error	8/30/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/30/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53489)(?)])(1 )(2 )]

"
Information	8/30/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/30/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53489)(?)])(1 )(2 )]

"
Information	8/30/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53489)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/30/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/30/2018 2:20:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 1:25:43 PM	MTAService.OnSessionChange	0	None	1:25:43 PM - Session change notice received: SessionLock Session ID: 2
Information	8/30/2018 12:46:00 PM	MTAService.OnSessionChange	0	None	12:46:00 PM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/30/2018 12:31:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 12:18:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 9000.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/30/2018 12:11:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c94c8ca8-ac1f-11e8-ab22-204747d02364
Report Status: 0"
Information	8/30/2018 11:02:18 AM	MTAService.OnSessionChange	0	None	11:02:18 AM - Session change notice received: SessionLock Session ID: 2
Warning	8/30/2018 10:48:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 10:40:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 10:40:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:59Z. Reason: GVLK.
Information	8/30/2018 10:34:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2018 10:34:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 10:34:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 10:34:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2018 9:57:12 AM	MTAService.OnSessionChange	0	None	9:57:12 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 9:44:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/30/2018 9:44:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/30/2018 9:25:51 AM	MTAService.OnSessionChange	0	None	9:25:51 AM - Session change notice received: SessionLock Session ID: 2
Warning	8/30/2018 9:09:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 9:09:23 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/30/2018 9:08:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/30/2018 9:08:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/30/2018 9:06:21 AM	MTAService.OnSessionChange	0	None	9:06:21 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/30/2018 8:32:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/30/2018 8:31:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 26837, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/30/2018 8:30:17 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/30/2018 8:30:17 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/30/2018 8:01:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 8:01:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/30/2018 7:19:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 7:11:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df8e6e45-abf5-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/30/2018 5:43:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 4:06:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 4:06:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:35Z. Reason: GVLK.
Information	8/30/2018 4:01:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 4:01:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2018 4:01:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 4:01:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 4:01:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2018 4:01:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 3:52:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:58Z. Reason: GVLK.
Warning	8/30/2018 3:52:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 3:47:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2018 3:47:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 3:47:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 3:47:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/30/2018 3:46:36 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/30/2018 3:46:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2018 3:46:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:25Z. Reason: GVLK.
Error	8/30/2018 3:41:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/30/2018 3:41:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2018 3:41:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2018 3:41:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2018 3:41:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2018 2:11:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5e7f6e5-abcb-11e8-ab22-204747d02364
Report Status: 0"
Information	8/30/2018 2:03:25 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/30/2018 2:01:30 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	8/30/2018 1:56:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/30/2018 12:01:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/30/2018 12:01:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/30/2018 12:01:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/29/2018 10:23:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 9:11:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c3788a8-aba2-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/29/2018 8:51:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 8:01:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 8:01:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/29/2018 8:01:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 7:54:01 PM	MTAService.OnSessionChange	0	None	7:54:01 PM - Session change notice received: SessionLock Session ID: 2
Warning	8/29/2018 7:08:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 6:42:07 PM	MTAService.OnSessionChange	0	None	6:42:07 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 6:40:21 PM	MTAService.OnSessionChange	0	None	6:40:21 PM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 6:25:14 PM	MTAService.OnSessionChange	0	None	6:25:14 PM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/29/2018 5:21:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 5:13:53 PM	MTAService.OnSessionChange	0	None	5:13:53 PM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 4:29:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 4:29:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:12Z. Reason: GVLK.
Information	8/29/2018 4:24:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 4:24:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 4:24:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 4:24:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 4:18:09 PM	MTAService.OnSessionChange	0	None	4:18:09 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 4:11:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2288a434-ab78-11e8-ab22-204747d02364
Report Status: 0"
Information	8/29/2018 4:01:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 3:53:46 PM	MTAService.OnSessionChange	0	None	3:53:46 PM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 3:48:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 3:48:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:32Z. Reason: GVLK.
Information	8/29/2018 3:43:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 3:43:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 3:43:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 3:43:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 3:39:13 PM	MTAService.OnSessionChange	0	None	3:39:13 PM - Session change notice received: SessionUnlock Session ID: 2
Error	8/29/2018 3:37:13 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/29/2018 3:32:04 PM	MTAService.OnSessionChange	0	None	3:32:04 PM - Session change notice received: SessionLock Session ID: 2
Warning	8/29/2018 3:28:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 3:23:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 3:23:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:32Z. Reason: GVLK.
Error	8/29/2018 3:17:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/29/2018 3:16:26 PM	MTAService.OnSessionChange	0	None	3:16:26 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 3:16:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 3:16:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 3:16:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 3:16:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 3:05:24 PM	MTAService.OnSessionChange	0	None	3:05:24 PM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 2:30:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/29/2018 2:25:26 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/29/2018 2:25:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54929)(?)])(1 )(2 )]

"
Information	8/29/2018 2:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/29/2018 2:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54929)(?)])(1 )(2 )]

"
Information	8/29/2018 2:25:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54929)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 2:25:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/29/2018 2:25:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 2:25:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 2:08:35 PM	MTAService.OnSessionChange	0	None	2:08:35 PM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/29/2018 1:47:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 12:54:03 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8999.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/29/2018 12:45:50 PM	MTAService.OnSessionChange	0	None	12:45:50 PM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 12:00:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 11:59:26 AM	MTAService.OnSessionChange	0	None	11:59:26 AM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/29/2018 11:52:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 11:42:19 AM	MTAService.OnSessionChange	0	None	11:42:19 AM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 11:31:29 AM	MTAService.OnSessionChange	0	None	11:31:29 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 11:29:17 AM	MTAService.OnSessionChange	0	None	11:29:17 AM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 11:28:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/29/2018 11:27:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/29/2018 11:11:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38ca2992-ab4e-11e8-ab22-204747d02364
Report Status: 0"
Information	8/29/2018 10:08:22 AM	MTAService.OnSessionChange	0	None	10:08:22 AM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/29/2018 9:58:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 9:34:21 AM	MTAService.OnSessionChange	0	None	9:34:21 AM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 9:29:31 AM	MTAService.OnSessionChange	0	None	9:29:31 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 9:26:39 AM	MTAService.OnSessionChange	0	None	9:26:39 AM - Session change notice received: SessionLock Session ID: 2
Information	8/29/2018 9:23:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 9:23:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-09-05T03:47:01Z. Reason: GVLK.
Information	8/29/2018 9:18:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/29/2018 9:18:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/29/2018 9:18:42 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/29/2018 9:18:37 AM	MTAService.OnSessionChange	0	None	9:18:37 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/29/2018 9:18:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 9:18:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 9:18:00 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/08/29 03:47"
Information	8/29/2018 9:17:59 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/29 03:47, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/29/2018 9:12:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 9:12:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 9:12:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 9:12:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 8:43:45 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Tuesday, August 21, 2018 5:42:57 AM.
Warning	8/29/2018 8:11:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 8:00:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 6:11:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4f0c5fe1-ab24-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/29/2018 6:11:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 5:30:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 5:30:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:56Z. Reason: GVLK.
Information	8/29/2018 5:25:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 5:25:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 5:25:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 5:25:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/29/2018 4:36:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 4:00:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2018 3:24:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 3:24:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:52Z. Reason: GVLK.
Information	8/29/2018 3:19:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 3:19:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 3:19:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 3:19:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/29/2018 3:17:30 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/29/2018 3:13:06 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/29/2018 3:12:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 3:12:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:13Z. Reason: GVLK.
Information	8/29/2018 3:10:17 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Error	8/29/2018 3:07:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/29/2018 3:07:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 3:07:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 3:07:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 3:07:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 2:46:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2018 2:46:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:20Z. Reason: GVLK.
Warning	8/29/2018 2:43:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 2:41:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2018 2:41:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2018 2:41:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2018 2:41:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2018 1:11:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 65504c88-aafa-11e8-ab22-204747d02364
Report Status: 0"
Warning	8/29/2018 12:59:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/29/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/29/2018 12:00:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/28/2018 11:21:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/28/2018 9:25:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 8:11:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7b9aa245-aad0-11e8-ab22-204747d02364
Report Status: 0"
Information	8/28/2018 8:00:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/28/2018 7:30:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 6:46:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 6:46:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:25Z. Reason: GVLK.
Information	8/28/2018 6:41:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 6:41:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 6:41:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 6:41:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 5:59:12 PM	MTAService.OnSessionChange	0	None	5:59:12 PM - Session change notice received: SessionLock Session ID: 2
Warning	8/28/2018 5:51:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 5:47:00 PM	MTAService.OnSessionChange	0	None	5:47:00 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/28/2018 5:18:52 PM	MTAService.OnSessionChange	0	None	5:18:52 PM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 5:06:47 PM	MTAService.OnSessionChange	0	None	5:06:47 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/28/2018 4:00:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/28/2018 3:57:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 3:22:26 PM	MTAService.OnSessionChange	0	None	3:22:26 PM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 3:22:20 PM	MTAService.OnSessionChange	0	None	3:22:20 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/28/2018 3:17:40 PM	MTAService.OnSessionChange	0	None	3:17:40 PM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 3:11:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 912b54cb-aaa6-11e8-ab22-204747d02364
Report Status: 0"
Information	8/28/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/28/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56369)(?)])(1 )(2 )]

"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56369)(?)])(1 )(2 )]

"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56369)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 2:05:08 PM	MTAService.OnSessionChange	0	None	2:05:08 PM - Session change notice received: SessionUnlock Session ID: 2
Warning	8/28/2018 1:57:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 1:17:14 PM	MTAService.OnSessionChange	0	None	1:17:14 PM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 1:17:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 1:16:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 1:10:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 1:09:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 1:06:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 1:05:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 1:03:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 1:02:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 1:00:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 1:00:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 12:46:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8998.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/28/2018 12:30:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 12:30:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 12:24:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 12:24:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 12:22:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 12:21:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 12:06:56 PM	MTAService.OnSessionChange	0	None	12:06:56 PM - Session change notice received: SessionUnlock Session ID: 2
Information	8/28/2018 12:05:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 12:05:03 PM	MTAService.OnSessionChange	0	None	12:05:03 PM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 12:00:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 12:00:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 12:00:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2018 12:00:05 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 46

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	8/28/2018 11:59:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56515)(?)])(1 )(2 )]

"
Information	8/28/2018 11:59:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2018 11:59:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56515)(?)])(1 )(2 )]

"
Information	8/28/2018 11:59:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56515)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 11:59:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2018 11:59:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 11:59:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/28/2018 11:58:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 11:24:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 11:24:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 11:17:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 11:17:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2018 11:11:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2018 11:11:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/28/2018 10:27:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/28/2018 10:11:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a7606d77-aa7c-11e8-ab22-204747d02364
Report Status: 0"
Information	8/28/2018 10:10:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 10:10:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:29Z. Reason: GVLK.
Information	8/28/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 10:05:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 9:41:45 AM	MTAService.OnSessionChange	0	None	9:41:45 AM - Session change notice received: SessionUnlock Session ID: 2
Information	8/28/2018 9:40:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 9:40:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:28Z. Reason: GVLK.
Information	8/28/2018 9:35:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 9:35:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 9:35:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 9:35:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 9:15:20 AM	MTAService.OnSessionChange	0	None	9:15:20 AM - Session change notice received: SessionLock Session ID: 2
Information	8/28/2018 9:10:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 9:10:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:28Z. Reason: GVLK.
Information	8/28/2018 9:08:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/28/2018 9:08:30 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/28/2018 9:08:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/28/2018 9:05:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 9:00:58 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 437

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 343

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 561

Information	8/28/2018 9:00:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2018 9:00:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56694)(?)])(1 )(2 )]

"
Information	8/28/2018 9:00:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2018 9:00:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56694)(?)])(1 )(2 )]

"
Information	8/28/2018 9:00:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56694)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 9:00:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2018 9:00:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 9:00:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 8:55:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 8:55:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 8:55:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:28Z. Reason: GVLK.
Warning	8/28/2018 8:52:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	8/28/2018 8:50:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/28/2018 8:50:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56704)(?)])(1 )(2 )]

"
Information	8/28/2018 8:50:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2018 8:50:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56704)(?)])(1 )(2 )]

"
Information	8/28/2018 8:50:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56704)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 8:50:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2018 8:50:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 8:50:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 8:50:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 8:50:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 8:50:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 8:50:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 8:50:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 2

"
Information	8/28/2018 8:50:11 AM	MTAService.OnSessionChange	0	None	8:50:11 AM - Logon : 212558710
Information	8/28/2018 8:50:11 AM	MTAService.OnSessionChange	0	None	8:50:11 AM - Session change notice received: SessionLogon Session ID: 2
Information	8/28/2018 8:50:11 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/28/2018 8:50:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 2

"
Information	8/28/2018 8:50:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/28/2018 5:03:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 5:03:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:08Z. Reason: GVLK.
Information	8/28/2018 4:56:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 4:56:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 4:56:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 4:56:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/28/2018 4:55:21 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/28/2018 4:51:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2018 4:51:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:45Z. Reason: GVLK.
Error	8/28/2018 4:47:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/28/2018 4:46:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2018 4:46:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2018 4:46:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2018 4:46:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/27/2018 7:59:09 PM	MTAService.OnSessionChange	0	None	7:59:09 PM - Session change notice received: ConsoleConnect Session ID: 2
Warning	8/27/2018 7:58:47 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4280 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 308 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4280 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2244 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/27/2018 7:58:48 PM	MTAService.OnSessionChange	0	None	7:58:48 PM - Session change notice received: ConsoleDisconnect Session ID: 1
Information	8/27/2018 7:58:47 PM	MTAService.OnSessionChange	0	None	7:58:47 PM - Logoff
Information	8/27/2018 7:58:47 PM	MTAService.OnSessionChange	0	None	7:58:47 PM - Session change notice received: SessionLogoff Session ID: 1
Information	8/27/2018 7:58:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/27/2018 7:58:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/27/2018 7:58:46 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/27/2018 7:58:38 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	8/27/2018 7:47:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 7:11:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ebdf22c9-a9fe-11e8-ab22-204747d02364
Report Status: 0"
Information	8/27/2018 6:13:12 PM	MTAService.OnSessionChange	0	None	6:13:12 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	8/27/2018 6:03:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 5:16:22 PM	MTAService.OnSessionChange	0	None	5:16:22 PM - Session change notice received: SessionLock Session ID: 1
Information	8/27/2018 5:16:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/27/2018 5:15:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/27/2018 4:07:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 3:08:43 PM	MTAService.OnSessionChange	0	None	3:08:43 PM - Session change notice received: SessionUnlock Session ID: 1
Information	8/27/2018 2:44:02 PM	MTAService.OnSessionChange	0	None	2:44:02 PM - Session change notice received: SessionLock Session ID: 1
Information	8/27/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	8/27/2018 2:25:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	8/27/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/27/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57809)(?)])(1 )(2 )]

"
Information	8/27/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/27/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57809)(?)])(1 )(2 )]

"
Information	8/27/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57809)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 2:25:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/27/2018 2:25:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 2:25:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 2:23:44 PM	MTAService.OnSessionChange	0	None	2:23:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	8/27/2018 2:11:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02254b30-a9d5-11e8-ab22-204747d02364
Report Status: 0"
Information	8/27/2018 2:06:45 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/27/2018 1:46:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/27/2018 1:46:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/27/2018 1:22:05 PM	MTAService.OnSessionChange	0	None	1:22:05 PM - Session change notice received: SessionLock Session ID: 1
Information	8/27/2018 1:16:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/27/2018 1:15:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/27/2018 1:14:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/27/2018 1:13:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/27/2018 12:45:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 12:34:11 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8997.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/27/2018 12:30:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/27/2018 12:30:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/27/2018 12:05:33 PM	MTAService.OnSessionChange	0	None	12:05:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	8/27/2018 11:32:30 AM	MTAService.OnSessionChange	0	None	11:32:30 AM - Session change notice received: SessionLock Session ID: 1
Warning	8/27/2018 10:51:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:06Z. Reason: GVLK.
Information	8/27/2018 10:24:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 10:24:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 10:24:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 10:24:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 10:07:57 AM	MTAService.OnSessionChange	0	None	10:07:57 AM - Session change notice received: SessionUnlock Session ID: 1
Information	8/27/2018 9:59:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:59:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:07Z. Reason: GVLK.
Information	8/27/2018 9:54:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 9:54:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:54:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:54:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:47:55 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/27/2018 9:47:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/27/2018 9:42:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:42:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:33Z. Reason: GVLK.
Information	8/27/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:37:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:37:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:37:26 AM	MTAService.OnSessionChange	0	None	9:37:26 AM - Session change notice received: SessionLock Session ID: 1
Error	8/27/2018 9:31:46 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/27/2018 9:29:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:29:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:13Z. Reason: GVLK.
Information	8/27/2018 9:24:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 9:24:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:24:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:24:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:22:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:22:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:29Z. Reason: GVLK.
Information	8/27/2018 9:21:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 72, Deleted: 50, Modified: 432, Compared: 26736, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/27/2018 9:20:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:17:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:17:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:16:33 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/27/2018 9:16:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/27/2018 9:16:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/27/2018 9:16:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:23Z. Reason: GVLK.
Information	8/27/2018 9:16:05 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/27/2018 9:16:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/27/2018 9:16:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/27/2018 9:16:00 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 358

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1077

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 499

Information	8/27/2018 9:15:59 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/27/2018 9:15:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/27/2018 9:15:14 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/27/2018 9:15:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58119)(?)])(1 )(2 )]

"
Information	8/27/2018 9:15:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/27/2018 9:15:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58119)(?)])(1 )(2 )]

"
Information	8/27/2018 9:15:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58119)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	8/27/2018 9:14:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/27/2018 9:14:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58120)(?)])(1 )(2 )]

"
Information	8/27/2018 9:14:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/27/2018 9:14:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58120)(?)])(1 )(2 )]

"
Information	8/27/2018 9:14:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58120)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:12:26 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	8/27/2018 9:11:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/27/2018 9:11:38 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/27/2018 9:11:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58123)(?)])(1 )(2 )]

"
Information	8/27/2018 9:11:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/27/2018 9:11:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58123)(?)])(1 )(2 )]

"
Information	8/27/2018 9:11:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 58123)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:11:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/27/2018 9:11:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:11:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:10:21 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	8/27/2018 9:10:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/27/2018 9:09:57 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/27/2018 9:09:45 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/27/2018 9:09:41 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/27/2018 9:09:00 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/27/2018 9:08:50 AM	MTAService.OnSessionChange	0	None	9:08:50 AM - Logon : 212558710
Information	8/27/2018 9:08:50 AM	MTAService.OnSessionChange	0	None	9:08:50 AM - Session change notice received: SessionLogon Session ID: 1
Information	8/27/2018 9:08:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/27/2018 9:08:48 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/27/2018 9:08:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/27/2018 9:08:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/27/2018 9:08:33 AM	ESENT	302	Logging/Recovery	Windows (7600) Windows: The database engine has successfully completed recovery steps.
Information	8/27/2018 9:08:31 AM	ESENT	301	Logging/Recovery	Windows (7600) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/27/2018 9:08:28 AM	MTAService.OnSessionChange	0	None	9:08:28 AM - Session change notice received: ConsoleConnect Session ID: 1
Information	8/27/2018 9:08:24 AM	ESENT	301	Logging/Recovery	Windows (7600) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00A67.log.
Information	8/27/2018 9:08:24 AM	ESENT	300	Logging/Recovery	Windows (7600) Windows: The database engine is initiating recovery steps.
Information	8/27/2018 9:08:23 AM	ESENT	102	General	Windows (7600) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/27/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/27/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/27/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	8/27/2018 9:08:21 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	8/27/2018 9:08:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/27/2018 9:08:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/27/2018 9:08:05 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8995.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/27/2018 9:07:21 AM	Service1	0	None	Service started successfully.
Error	8/27/2018 9:07:13 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/27/2018 9:07:11 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/27/2018 9:06:47 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/27/2018 9:06:32 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/27/2018 9:06:31 AM	PostgreSQL	0	None	"2018-08-27 09:06:31 IST LOG:  redirecting log output to logging collector process
2018-08-27 09:06:31 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/27/2018 9:06:28 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/27/2018 9:06:21 AM	MTAService	0	None	Service started successfully.
Information	8/27/2018 9:06:21 AM	MTAService.OnStart	0	None	9:06:21 AM - Waiting for user to Logon
Information	8/27/2018 9:06:13 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/27/2018 9:06:11 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:11 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/27/2018 9:06:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/27/2018 9:06:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/27/2018 9:06:10 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database msdb (database ID 4) in 1 second(s) (analysis 407 ms, redo 0 ms, undo 1022 ms.) This is an informational message only. No user action is required.
Information	8/27/2018 9:06:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/27/2018 9:06:09 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/27/2018 9:06:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/27/2018 9:06:07 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:07 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/27/2018 9:06:07 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/27/2018 9:06:07 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/27/2018 9:06:07 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4580 at 8/27/2018 8:57:44 AM (local) 8/27/2018 3:27:44 AM (UTC). This is an informational message only; no user action is required.
Information	8/27/2018 9:06:01 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/27/2018 9:06:00 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/27/2018 9:05:59 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/27/2018 9:05:59 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/27/2018 9:05:59 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/27/2018 9:05:59 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4228.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/27/2018 9:05:49 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/27/2018 9:04:44 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/27/2018 9:04:36 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/27/2018 9:00:42 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/27/2018 8:57:52 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	8/27/2018 9:00:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/27/2018 9:00:42 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/27/2018 8:57:45 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/27/2018 8:57:44 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	8/27/2018 8:57:20 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1056 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 176 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 176 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2688 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 176 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 176 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 176 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2280 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/27/2018 8:57:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/27/2018 8:57:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/27/2018 8:57:19 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	8/26/2018 10:27:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/26/2018 8:52:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 8:52:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:03Z. Reason: GVLK.
Information	8/26/2018 8:47:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 8:47:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 8:47:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 8:47:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/26/2018 8:37:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/26/2018 7:59:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb1c8b35-a8d7-11e8-9b34-204747d02364
Report Status: 0"
Information	8/26/2018 6:53:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 6:53:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:06Z. Reason: GVLK.
Information	8/26/2018 6:48:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 6:48:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 6:48:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 6:48:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/26/2018 6:37:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/26/2018 4:57:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/26/2018 4:56:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 4:56:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:10Z. Reason: GVLK.
Information	8/26/2018 4:51:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 4:51:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 4:51:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 4:51:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/26/2018 4:49:33 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/26/2018 4:47:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 4:47:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:26Z. Reason: GVLK.
Error	8/26/2018 4:42:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/26/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/26/2018 3:24:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/26/2018 3:21:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 3:21:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:08Z. Reason: GVLK.
Information	8/26/2018 3:16:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 3:16:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 3:16:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 3:16:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/26/2018 2:59:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 01630c6b-a8ae-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/26/2018 1:31:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/26/2018 12:30:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 12:30:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:19Z. Reason: GVLK.
Information	8/26/2018 12:26:07 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2018 12:25:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 12:25:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 12:25:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 12:25:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/26/2018 12:22:06 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2018 12:20:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎25T18:49:18.386445900Z.
Information	8/26/2018 12:20:30 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 9128.
Information	8/26/2018 12:20:30 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/26/2018 12:20:30 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	8/26/2018 12:20:30 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4344146. Installation success or error status: 0.
Information	8/26/2018 12:20:30 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4344146' installed successfully.
Information	8/26/2018 12:20:12 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:11 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:11 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:09 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:09 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:20:07 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:19:58 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/26/2018 12:19:58 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00003.log
Information	8/26/2018 12:19:54 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/26/2018 12:19:54 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:19:53 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	8/26/2018 12:19:52 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00002.log
Information	8/26/2018 12:19:52 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/26/2018 12:19:50 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/26/2018 12:19:50 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:19:47 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/26/2018 12:19:47 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/26/2018 12:19:44 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	8/26/2018 12:19:37 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:19:36 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:19:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2018 12:19:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:35Z. Reason: GVLK.
Information	8/26/2018 12:19:18 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎25T18:49:18.386445900Z.
Information	8/26/2018 12:19:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 9128.
Information	8/26/2018 12:18:58 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2018 12:17:40 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎25T18:46:10.780845900Z.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 16964.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/26/2018 12:17:40 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4344167. Installation success or error status: 0.
Information	8/26/2018 12:17:40 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4344167' installed successfully.
Information	8/26/2018 12:16:35 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:16:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 5992.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 5992.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 5992.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5544.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 6120.
Information	8/26/2018 12:16:22 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 5992.
Information	8/26/2018 12:16:15 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	8/26/2018 12:16:15 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5544) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/26/2018 12:16:15 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 5992) cannot be restarted - Application SID does not match Conductor SID..
Information	8/26/2018 12:16:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎25T18:46:10.780845900Z.
Information	8/26/2018 12:16:10 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 16964.
Information	8/26/2018 12:14:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2018 12:14:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2018 12:14:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2018 12:14:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/26/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/25/2018 11:41:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/25/2018 10:04:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 9:59:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17a1ba0b-a884-11e8-9b34-204747d02364
Report Status: 0"
Information	8/25/2018 8:51:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2018 8:51:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:49Z. Reason: GVLK.
Information	8/25/2018 8:46:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2018 8:46:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 8:46:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 8:46:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/25/2018 8:07:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/25/2018 6:36:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 4:59:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2de0bb32-a85a-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/25/2018 4:41:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/25/2018 3:09:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/25/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/25/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60689)(?)])(1 )(2 )]

"
Information	8/25/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/25/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60689)(?)])(1 )(2 )]

"
Information	8/25/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60689)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/25/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/25/2018 1:32:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 12:17:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8995.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/25/2018 11:59:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43b0869a-a830-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/25/2018 11:57:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/25/2018 10:23:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 10:16:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2018 10:16:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:56Z. Reason: GVLK.
Information	8/25/2018 10:11:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2018 10:11:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 10:11:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 10:11:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/25/2018 8:44:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 6:59:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 59f53446-a806-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/25/2018 6:57:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/25/2018 5:06:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 4:39:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2018 4:39:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:53Z. Reason: GVLK.
Information	8/25/2018 4:34:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2018 4:34:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 4:34:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 4:34:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/25/2018 4:33:14 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/25/2018 4:30:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2018 4:30:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:00Z. Reason: GVLK.
Error	8/25/2018 4:25:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/25/2018 4:25:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2018 4:25:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 4:25:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 4:24:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/25/2018 3:25:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 2:49:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2018 2:49:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:01Z. Reason: GVLK.
Information	8/25/2018 2:44:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2018 2:44:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2018 2:44:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2018 2:44:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/25/2018 1:59:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 704793f4-a7dc-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/25/2018 1:27:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/25/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/24/2018 11:40:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/24/2018 9:54:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 8:59:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 866c6e63-a7b2-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/24/2018 8:02:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/24/2018 6:29:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/24/2018 4:51:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 4:49:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 4:48:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 3:59:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cb6c1f0-a788-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/24/2018 3:04:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 2:30:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/24/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/24/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]

"
Information	8/24/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/24/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]

"
Information	8/24/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62129)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 2:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/24/2018 2:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 2:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/24/2018 1:32:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 12:49:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 12:48:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 12:01:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8994.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/24/2018 11:52:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 10:59:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b30501dd-a75e-11e8-9b34-204747d02364
Report Status: 0"
Warning	8/24/2018 10:06:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 8:53:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/24/2018 8:50:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14681, Queries: 0, Results: 0, Version: 16.0.9126.2275.
Information	8/24/2018 8:50:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/24/2018 8:49:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/24/2018 8:49:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 8:49:01 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/24/2018 8:48:59 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 421

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 171

Information	8/24/2018 8:48:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2018 8:48:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62466)(?)])(1 )(2 )]

"
Information	8/24/2018 8:48:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/24/2018 8:48:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62466)(?)])(1 )(2 )]

"
Information	8/24/2018 8:48:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62466)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 8:48:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/24/2018 8:48:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 8:48:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/24/2018 8:27:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 8:27:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2018 8:27:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:13Z. Reason: GVLK.
Information	8/24/2018 8:22:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2018 8:22:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 8:22:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 8:22:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/24/2018 6:29:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 5:59:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c95f892c-a734-11e8-9b34-204747d02364
Report Status: 0"
Information	8/24/2018 5:32:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2018 5:32:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:19Z. Reason: GVLK.
Information	8/24/2018 5:27:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2018 5:27:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 5:27:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 5:27:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/24/2018 4:54:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 3:41:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2018 3:41:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:07Z. Reason: GVLK.
Information	8/24/2018 3:36:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2018 3:36:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 3:36:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 3:36:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/24/2018 3:34:31 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/24/2018 3:30:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2018 3:30:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:28Z. Reason: GVLK.
Error	8/24/2018 3:25:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/24/2018 3:25:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2018 3:25:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2018 3:25:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2018 3:25:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/24/2018 3:05:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/24/2018 1:29:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/24/2018 12:59:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dfbdb564-a70a-11e8-9b34-204747d02364
Report Status: 0"
Information	8/24/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/23/2018 11:39:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/23/2018 9:51:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 9:36:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 9:36:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:59Z. Reason: GVLK.
Information	8/23/2018 9:31:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 9:31:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 9:31:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 9:31:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 8:55:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/23/2018 8:07:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 7:59:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5f827fc-a6e0-11e8-9b34-204747d02364
Report Status: 0"
Information	8/23/2018 6:27:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 6:23:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 6:23:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:19Z. Reason: GVLK.
Information	8/23/2018 6:22:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:55 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2275. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:22:55 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	8/23/2018 6:22:55 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/23/2018 6:22:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63331)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 6:22:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/23/2018 6:22:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/23/2018 6:22:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 6:22:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/23/2018 6:22:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 6:22:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 6:22:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 6:22:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:25 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2275. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:22:25 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	8/23/2018 6:22:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2275. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:22:20 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	8/23/2018 6:22:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:17 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2275. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:22:17 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	8/23/2018 6:22:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:09 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/23/2018 6:22:08 PM	ESENT	102	General	Windows (9400) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/23/2018 6:22:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:22:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2275. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:22:08 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	8/23/2018 6:21:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:21:40 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/23/2018 6:21:40 PM	ESENT	103	General	Windows (10560) Windows: The database engine stopped the instance (0).
Information	8/23/2018 6:21:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:21:40 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2275. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/23/2018 6:21:40 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	8/23/2018 6:20:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10148.
Information	8/23/2018 6:19:29 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/23/2018 6:19:12 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/23/2018 6:19:11 PM	ESENT	102	General	Windows (10560) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/23/2018 6:19:08 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/23/2018 6:19:08 PM	ESENT	103	General	Windows (7300) Windows: The database engine stopped the instance (0).
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:07 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:06 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:06 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/23/2018 6:19:06 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:06 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/23/2018 6:19:06 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	8/23/2018 6:18:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/23/2018 6:18:10 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/23/2018 6:18:09 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/23/2018 6:18:08 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/23/2018 6:18:05 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/23/2018 6:18:02 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/23/2018 6:17:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63336)(?)])(1 )(2 )]

"
Information	8/23/2018 6:17:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/23/2018 6:17:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63336)(?)])(1 )(2 )]

"
Information	8/23/2018 6:17:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63336)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 6:17:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/23/2018 6:17:53 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/23/2018 6:17:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	8/23/2018 6:17:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	8/23/2018 6:17:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	8/23/2018 6:17:51 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	8/23/2018 6:17:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	8/23/2018 6:17:49 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	8/23/2018 6:17:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	8/23/2018 6:17:47 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	8/23/2018 6:17:46 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	8/23/2018 6:17:45 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	8/23/2018 6:17:45 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	8/23/2018 6:17:45 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	8/23/2018 6:17:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	8/23/2018 6:17:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	8/23/2018 6:17:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	8/23/2018 6:17:44 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	8/23/2018 6:17:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/23/2018 6:17:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	8/23/2018 6:17:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 6:17:39 PM	ESENT	302	Logging/Recovery	Windows (7300) Windows: The database engine has successfully completed recovery steps.
Information	8/23/2018 6:17:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 6:17:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 6:17:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 6:17:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 6:17:36 PM	ESENT	301	Logging/Recovery	Windows (7300) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/23/2018 6:17:35 PM	ESENT	300	Logging/Recovery	Windows (7300) Windows: The database engine is initiating recovery steps.
Information	8/23/2018 6:17:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 6:17:35 PM	ESENT	102	General	Windows (7300) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/23/2018 6:17:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8993.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/23/2018 6:15:36 PM	Service1	0	None	Service started successfully.
Error	8/23/2018 6:15:29 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/23/2018 6:15:28 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	8/23/2018 6:15:21 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/23/2018 6:14:52 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/23/2018 6:14:49 PM	PostgreSQL	0	None	"2018-08-23 18:14:49 IST LOG:  redirecting log output to logging collector process
2018-08-23 18:14:49 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/23/2018 6:14:41 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/23/2018 6:14:41 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/23/2018 6:14:34 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/23/2018 6:14:29 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/23/2018 6:14:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/23/2018 6:14:20 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/23/2018 6:14:20 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/23/2018 6:14:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/23/2018 6:14:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/23/2018 6:14:07 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:07 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/23/2018 6:14:07 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/23/2018 6:14:07 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/23/2018 6:14:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/23/2018 6:14:06 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/23/2018 6:14:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/23/2018 6:14:05 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/23/2018 6:14:04 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/23/2018 6:14:02 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4260 at 8/23/2018 6:10:47 PM (local) 8/23/2018 12:40:47 PM (UTC). This is an informational message only; no user action is required.
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/23/2018 6:14:01 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4580.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/23/2018 6:13:52 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/23/2018 6:12:58 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/23/2018 6:12:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/23/2018 6:12:34 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/23/2018 6:12:34 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/23/2018 6:10:53 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	8/23/2018 6:10:47 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	8/23/2018 6:10:46 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Warning	8/23/2018 6:10:37 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 444 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
"
Information	8/23/2018 6:10:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/23/2018 6:10:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/23/2018 6:10:36 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/23/2018 6:10:26 PM	ESENT	302	Logging/Recovery	Windows (5112) Windows: The database engine has successfully completed recovery steps.
Information	8/23/2018 6:10:20 PM	ESENT	301	Logging/Recovery	Windows (5112) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/23/2018 6:10:09 PM	ESENT	301	Logging/Recovery	Windows (5112) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00A5A.log.
Information	8/23/2018 6:10:09 PM	ESENT	300	Logging/Recovery	Windows (5112) Windows: The database engine is initiating recovery steps.
Information	8/23/2018 6:10:08 PM	ESENT	102	General	Windows (5112) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Warning	8/23/2018 6:09:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 6:09:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 6:09:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 6:09:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 6:09:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/23/2018 6:09:33 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	8/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/23/2018 6:09:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/23/2018 6:09:11 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/23/2018 6:09:11 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/23/2018 6:09:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/23/2018 6:09:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/23/2018 6:08:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8993.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	8/23/2018 6:08:50 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/23/2018 6:08:49 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/23/2018 6:08:27 PM	PostgreSQL	0	None	"2018-08-23 18:08:27 IST LOG:  redirecting log output to logging collector process
2018-08-23 18:08:27 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/23/2018 6:08:26 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/23/2018 6:08:24 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/23/2018 6:08:13 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/23/2018 6:08:10 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/23/2018 6:08:10 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/23/2018 6:08:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/23/2018 6:08:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/23/2018 6:08:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/23/2018 6:08:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/23/2018 6:08:08 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4740 at 8/23/2018 5:48:18 PM (local) 8/23/2018 12:18:18 PM (UTC). This is an informational message only; no user action is required.
Information	8/23/2018 6:07:43 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/23/2018 6:07:29 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/23/2018 6:07:29 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/23/2018 6:07:29 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/23/2018 6:07:29 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/23/2018 6:07:29 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4260.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/23/2018 6:07:22 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/23/2018 6:06:00 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/23/2018 6:05:21 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/23/2018 6:05:20 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/23/2018 6:05:21 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/23/2018 5:48:18 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	8/23/2018 5:48:13 PM	MsiInstaller	1015	None	Failed to connect to server. Error: 0x80040153
Warning	8/23/2018 5:45:36 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 788 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2152 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/23/2018 5:45:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/23/2018 5:45:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/23/2018 5:45:35 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/23/2018 5:44:13 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	8/23/2018 5:44:11 PM	GE Software	0	(1)	++ Full script command ran:  C:\Windows\Options\Packages\DigitalGuardian_DG-WinWK_732-0742-PROD_V02\dgainstmgr-732_0742-WinWK-PROD.vbs /DGMC:PROD02 
Information	8/23/2018 5:44:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎23T12:09:59.236459300Z.
Information	8/23/2018 5:44:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Options\Packages\DigitalGuardian_DG-WinWK_732-0742-PROD_V02\DG-732_0742-WinWK-PROD.msi. Client Process Id: 16420.
Information	8/23/2018 5:44:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Digital Guardian Agent. Product Version: 7.3.2.0742. Product Language: 1033. Manufacturer: Digital Guardian, Inc.. Installation success or error status: 0.
Information	8/23/2018 5:44:11 PM	MsiInstaller	11707	None	Product: Digital Guardian Agent -- Installation completed successfully.
Information	8/23/2018 5:39:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎23T12:09:59.236459300Z.
Information	8/23/2018 5:39:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Options\Packages\DigitalGuardian_DG-WinWK_732-0742-PROD_V02\DG-732_0742-WinWK-PROD.msi. Client Process Id: 16420.
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++No Install Check was performed.
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++++++++++++++++++++++++ App Owner request that the Install Check be turned off on this package.
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++Started the installation of DigitalGuardian DG WinWK 732-0742-PROD V02 with the following commandline: /DGMC=PROD02 /REBOOT
Information	8/23/2018 5:39:40 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	8/23/2018 5:39:39 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	8/23/2018 5:18:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 5:16:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/23/2018 4:03:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 3:36:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 3:36:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:53Z. Reason: GVLK.
Information	8/23/2018 3:31:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 3:31:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 3:31:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 3:31:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 2:59:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0cc4a9a9-a6b7-11e8-82e1-204747d02364
Report Status: 0"
Warning	8/23/2018 2:28:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	8/23/2018 2:25:23 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/23/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63569)(?)])(1 )(2 )]

"
Information	8/23/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/23/2018 2:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63569)(?)])(1 )(2 )]

"
Information	8/23/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63569)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 2:17:09 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/23/2018 1:36:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 1:36:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:43Z. Reason: GVLK.
Information	8/23/2018 1:31:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 1:31:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 1:31:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 1:31:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 1:18:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 1:16:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 1:01:26 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8993.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/23/2018 12:33:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/23/2018 10:43:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 9:59:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 22f71a5e-a68d-11e8-82e1-204747d02364
Report Status: 0"
Information	8/23/2018 9:18:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 9:16:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/23/2018 9:14:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	8/23/2018 8:51:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/23/2018 7:11:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/23/2018 5:39:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 5:18:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 5:16:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 5:00:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 5:00:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:44Z. Reason: GVLK.
Information	8/23/2018 4:59:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38ea3a04-a663-11e8-82e1-204747d02364
Report Status: 0"
Information	8/23/2018 4:55:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 4:55:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 4:55:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 4:55:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/23/2018 4:53:04 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/23/2018 4:51:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 4:51:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:05Z. Reason: GVLK.
Error	8/23/2018 4:46:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/23/2018 4:46:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 4:46:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 4:46:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 4:46:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/23/2018 4:01:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 3:57:22 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/23/2018 3:54:56 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/23/2018 3:01:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2018 3:01:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:43Z. Reason: GVLK.
Information	8/23/2018 2:56:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2018 2:56:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2018 2:56:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2018 2:56:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2018 2:45:41 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/23/2018 2:17:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/23/2018 1:18:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2018 1:16:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/23/2018 12:47:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 11:59:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4f1f53be-a639-11e8-82e1-204747d02364
Report Status: 0"
Warning	8/22/2018 10:56:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 9:18:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2018 9:16:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/22/2018 9:04:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 7:21:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 7:21:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:23Z. Reason: GVLK.
Warning	8/22/2018 7:19:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 7:16:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 7:16:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 7:16:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 7:16:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 6:59:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 653f573b-a60f-11e8-82e1-204747d02364
Report Status: 0"
Information	8/22/2018 5:44:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64810)(?)])(1 )(2 )]

"
Information	8/22/2018 5:44:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 5:44:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64810)(?)])(1 )(2 )]

"
Information	8/22/2018 5:44:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64810)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	8/22/2018 5:37:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 5:18:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2018 5:16:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/22/2018 4:00:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 2:36:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64998)(?)])(1 )(2 )]

"
Information	8/22/2018 2:36:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 2:36:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64998)(?)])(1 )(2 )]

"
Information	8/22/2018 2:36:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 64998)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 2:28:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Error	8/22/2018 2:25:22 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/22/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65009)(?)])(1 )(2 )]

"
Information	8/22/2018 2:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65009)(?)])(1 )(2 )]

"
Information	8/22/2018 2:25:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65009)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 2:23:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/22/2018 2:19:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 1:59:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7b78687f-a5e5-11e8-82e1-204747d02364
Report Status: 0"
Information	8/22/2018 1:29:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/22/2018 1:29:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/22/2018 1:18:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2018 1:16:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/22/2018 12:48:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 12:41:51 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/22/2018 11:47:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/22/2018 11:46:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/22/2018 10:48:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/22/2018 10:13:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 10:13:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:50Z. Reason: GVLK.
Information	8/22/2018 10:10:53 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8992.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/22/2018 10:08:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	8/22/2018 10:08:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 8824) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 10:08:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 10976) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 10:08:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 3404) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 10:08:55 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5964) cannot be restarted - Application SID does not match Conductor SID..
Information	8/22/2018 10:08:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎22T04:38:55.679541700Z.
Information	8/22/2018 10:08:54 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎22T04:38:54.022376000Z.
Information	8/22/2018 10:08:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 10:08:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 10:08:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 10:08:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 9:43:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 9:43:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:42:52Z. Reason: GVLK.
Information	8/22/2018 9:38:58 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	8/22/2018 9:38:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 8824) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:38:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 10976) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:38:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 3404) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:38:58 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5964) cannot be restarted - Application SID does not match Conductor SID..
Information	8/22/2018 9:38:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎22T04:08:57.939873600Z.
Information	8/22/2018 9:38:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎22T04:08:56.329873600Z.
Information	8/22/2018 9:38:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 9:38:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:38:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 9:38:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 8824) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 10976) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 3404) cannot be restarted - Application SID does not match Conductor SID..
Warning	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5964) cannot be restarted - Application SID does not match Conductor SID..
Information	8/22/2018 9:34:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎22T04:04:27.532998500Z.
Information	8/22/2018 9:34:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎22T04:04:25.822586600Z.
Information	8/22/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 9:30:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:19Z. Reason: GVLK.
Information	8/22/2018 9:28:38 AM	McLogEvent	257	None	The scan of D:\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8984.0000.
Information	8/22/2018 9:25:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 9:25:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:25:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 9:25:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 9:24:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/22/2018 9:24:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/22/2018 9:24:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/22/2018 9:24:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 156, Deleted: 0, Modified: 663, Compared: 26472, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/22/2018 9:22:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 9:22:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:43:00Z. Reason: GVLK.
Information	8/22/2018 9:18:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2018 9:18:30 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/22/2018 9:17:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 10840.
Information	8/22/2018 9:17:16 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	8/22/2018 9:17:16 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	8/22/2018 9:17:16 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20058). Installation success or error status: 0.
Information	8/22/2018 9:17:16 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20058)' installed successfully.
Information	8/22/2018 9:17:10 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/22/2018 9:17:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/22/2018 9:17:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/22/2018 9:16:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/22/2018 9:16:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 9:16:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65317)(?)])(1 )(2 )]

"
Information	8/22/2018 9:16:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65317)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:16:56 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/22/2018 9:16:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65317)(?)])(1 )(2 )]

"
Information	8/22/2018 9:16:52 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/22/2018 9:16:52 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=108517  Grace type=8.
Information	8/22/2018 9:16:52 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 421

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 359

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 452

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	8/22/2018 9:16:51 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=077b63e0-0ab9-466e-817a-d0961321f8c6"
Information	8/22/2018 9:16:51 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=0ecb7018-22aa-4bba-9ec3-8abccecfd350"
Information	8/22/2018 9:16:51 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/22/2018 9:16:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2018 9:15:47 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/22/2018 9:15:44 AM	ESENT	102	General	Windows (11748) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/22/2018 9:15:17 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/22/2018 9:15:17 AM	ESENT	103	General	Windows (8432) Windows: The database engine stopped the instance (0).
Information	8/22/2018 9:15:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19239)(?)])(1 )(2 )]

"
Information	8/22/2018 9:15:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 9:15:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19239)(?)])(1 )(2 )]

"
Information	8/22/2018 9:15:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19239)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:15:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2018 9:15:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 9:15:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 9:15:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 10840.
Information	8/22/2018 9:14:54 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4988.
Information	8/22/2018 9:14:54 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	8/22/2018 9:14:54 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	8/22/2018 9:14:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4988.
Information	8/22/2018 9:13:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:13:42 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/08/22 03:43"
Information	8/22/2018 9:13:41 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/22 03:43, 0, 1, 247800, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/22/2018 9:13:35 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/22/2018 9:13:35 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/22 03:43, 0, 1, 247800, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Error	8/22/2018 9:10:42 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/22/2018 9:08:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 9:08:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 247800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:08:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 9:08:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 9:06:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 9:06:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-29T03:30:30Z. Reason: GVLK.
Information	8/22/2018 9:02:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/22/2018 9:01:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 247800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 9:01:30 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/22/2018 9:01:30 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/22 03:31, 0, 1, 247800, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/22/2018 8:58:27 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	8/22/2018 8:57:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	8/22/2018 8:57:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {691F76F9-C8D9-456C-ABE6-49D1E5212CF1}
Error	8/22/2018 8:57:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {691F76F9-C8D9-456C-ABE6-49D1E5212CF1}
Information	8/22/2018 8:57:11 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	8/22/2018 8:57:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/22/2018 8:57:07 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/22/2018 8:57:06 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/22/2018 8:57:04 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/22/2018 8:56:37 AM	ESENT	302	Logging/Recovery	Windows (8432) Windows: The database engine has successfully completed recovery steps.
Information	8/22/2018 8:56:36 AM	ESENT	301	Logging/Recovery	Windows (8432) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/22/2018 8:56:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2018 8:56:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 247800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 8:56:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 8:56:26 AM	ESENT	301	Logging/Recovery	Windows (8432) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00A41.log.
Information	8/22/2018 8:56:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19258)(?)])(1 )(2 )]

"
Information	8/22/2018 8:56:26 AM	ESENT	300	Logging/Recovery	Windows (8432) Windows: The database engine is initiating recovery steps.
Information	8/22/2018 8:56:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2018 8:56:25 AM	ESENT	102	General	Windows (8432) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/22/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19258)(?)])(1 )(2 )]

"
Information	8/22/2018 8:56:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19258)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2018 8:56:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2018 8:56:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2018 8:56:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 8:56:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2018 8:56:21 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8984.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/22/2018 8:56:01 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	8/22/2018 8:54:46 AM	Service1	0	None	Service started successfully.
Error	8/22/2018 8:54:33 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/22/2018 8:54:31 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	8/22/2018 8:54:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/22/2018 8:54:02 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/22/2018 8:53:58 AM	PostgreSQL	0	None	"2018-08-22 08:53:58 IST LOG:  redirecting log output to logging collector process
2018-08-22 08:53:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/22/2018 8:53:43 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/22/2018 8:53:39 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/22/2018 8:53:26 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/22/2018 8:53:15 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:15 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/22/2018 8:53:15 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/22/2018 8:53:15 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/22/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/22/2018 8:53:14 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/22/2018 8:53:13 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:11 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/22/2018 8:53:10 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/22/2018 8:53:10 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/22/2018 8:53:10 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4716 at 8/15/2018 10:16:27 AM (local) 8/15/2018 4:46:27 AM (UTC). This is an informational message only; no user action is required.
Information	8/22/2018 8:53:03 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/22/2018 8:53:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/22/2018 8:53:01 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/22/2018 8:53:01 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/22/2018 8:53:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/22/2018 8:53:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/22/2018 8:53:00 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/22/2018 8:53:00 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/22/2018 8:53:00 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/22/2018 8:53:00 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/22/2018 8:53:00 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4740.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/22/2018 8:52:51 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/22/2018 8:51:48 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/22/2018 8:51:42 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/22/2018 8:51:20 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/22/2018 8:51:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/22/2018 8:51:20 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/15/2018 10:16:32 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/15/2018 10:16:27 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	8/15/2018 10:16:21 AM	McLogEvent	257	None	The scan of C:\Windows\System32\input.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8984.0000.
Warning	8/15/2018 10:16:18 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1048 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2144 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/15/2018 10:16:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/15/2018 10:16:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/15/2018 10:16:16 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Installation complete
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Installation complete with an exit code of: 
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Started the installation of GE Reboot 1.0 V02 with the following commandline: /IC /Q
Information	8/15/2018 10:14:45 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	8/15/2018 10:14:44 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	8/15/2018 9:51:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b49bc7a5-a042-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/15/2018 9:45:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 9:45:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/15/2018 9:29:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/15/2018 7:57:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/15/2018 7:40:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/15/2018 5:59:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/15/2018 5:45:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 5:45:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 4:51:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cae43337-a018-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/15/2018 4:12:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/15/2018 3:40:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 3:18:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/15/2018 3:18:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-21T05:00:38Z. Reason: GVLK.
Information	8/15/2018 3:13:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/15/2018 3:13:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/15/2018 3:13:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/15/2018 3:13:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/15/2018 3:11:45 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/15/2018 3:08:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/15/2018 3:08:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-21T05:01:12Z. Reason: GVLK.
Error	8/15/2018 3:03:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/15/2018 3:03:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/15/2018 3:03:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/15/2018 3:03:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/15/2018 3:03:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/15/2018 2:24:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/15/2018 2:19:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/15/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29735)(?)])(1 )(2 )]

"
Information	8/15/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/15/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29735)(?)])(1 )(2 )]

"
Information	8/15/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29735)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/15/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/15/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/15/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/15/2018 2:12:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/15/2018 1:45:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 1:44:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/15/2018 1:23:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/15/2018 1:23:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-21T05:00:40Z. Reason: GVLK.
Information	8/15/2018 1:18:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/15/2018 1:18:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/15/2018 1:18:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/15/2018 1:18:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/15/2018 12:13:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/15/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/14/2018 11:51:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e11edbe9-9fee-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/14/2018 11:40:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 10:18:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 9:44:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 9:44:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	8/14/2018 8:37:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 7:39:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 6:55:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 6:51:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f751824c-9fc4-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/14/2018 5:44:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 5:44:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 5:13:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 5:13:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/14/2018 5:07:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 3:39:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 3:34:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 1:51:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d83db34-9f9b-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/14/2018 1:44:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 1:43:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 1:36:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 1:35:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/14/2018 1:22:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 1:21:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/14/2018 1:13:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 1:12:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/14/2018 12:25:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8984.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/14/2018 12:20:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 12:19:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/14/2018 12:01:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 11:39:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/14/2018 11:39:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 11:39:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/14/2018 11:08:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/14/2018 10:36:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 10:36:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-21T05:00:19Z. Reason: GVLK.
Information	8/14/2018 10:31:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 10:31:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 10:31:18 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/08/14 05:01"
Information	8/14/2018 10:31:17 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/14 05:01, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/14/2018 10:26:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 10:26:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 10:26:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 10:26:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/14/2018 10:21:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 9:44:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 9:44:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 8:51:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 23a2a255-9f71-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/14/2018 8:36:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 8:36:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:13Z. Reason: GVLK.
Information	8/14/2018 8:31:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 8:31:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 8:31:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 8:31:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/14/2018 8:28:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 7:39:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 6:47:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 5:44:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/14/2018 5:09:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 4:44:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 4:44:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:15Z. Reason: GVLK.
Information	8/14/2018 4:39:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 4:39:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 4:39:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 4:39:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/14/2018 3:53:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 3:53:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:57:01Z. Reason: GVLK.
Information	8/14/2018 3:51:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 39f29a3e-9f47-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/14/2018 3:48:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 3:48:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 3:48:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 3:48:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/14/2018 3:46:04 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/14/2018 3:41:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 3:41:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:35Z. Reason: GVLK.
Warning	8/14/2018 3:39:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 3:39:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/14/2018 3:36:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/14/2018 3:36:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 3:36:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 3:36:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 3:36:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/14/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/14/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/14/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31175)(?)])(1 )(2 )]

"
Information	8/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31175)(?)])(1 )(2 )]

"
Information	8/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31175)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/14/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/14/2018 2:03:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 1:44:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/14/2018 1:20:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/14/2018 1:20:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:41Z. Reason: GVLK.
Information	8/14/2018 1:15:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/14/2018 1:15:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/14/2018 1:15:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/14/2018 1:15:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/14/2018 12:30:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/13/2018 11:38:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 10:51:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 503d43ef-9f1d-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/13/2018 10:43:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 9:44:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/13/2018 8:48:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 7:38:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/13/2018 6:51:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 5:51:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6694031f-9ef3-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/13/2018 5:44:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 5:14:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/13/2018 5:14:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:12Z. Reason: GVLK.
Information	8/13/2018 5:09:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/13/2018 5:09:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/13/2018 5:09:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/13/2018 5:09:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/13/2018 4:57:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 3:38:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/13/2018 3:08:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 1:43:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	8/13/2018 1:12:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 12:51:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7cb9063e-9ec9-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/13/2018 12:40:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/13/2018 12:39:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/13/2018 12:29:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8983.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/13/2018 12:11:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/13/2018 12:11:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/13/2018 12:09:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/13/2018 12:08:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/13/2018 11:38:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 11:38:19 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/13/2018 11:16:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	8/13/2018 11:13:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 9:43:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 9:43:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/13/2018 9:16:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 7:51:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 92eec4d5-9e9f-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/13/2018 7:44:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/13/2018 6:07:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 5:43:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 5:43:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/13/2018 4:07:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 3:27:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/13/2018 3:27:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:46Z. Reason: GVLK.
Information	8/13/2018 3:22:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/13/2018 3:22:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/13/2018 3:22:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/13/2018 3:22:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/13/2018 3:19:47 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/13/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/13/2018 3:15:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:47Z. Reason: GVLK.
Error	8/13/2018 3:11:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/13/2018 3:10:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/13/2018 3:10:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/13/2018 3:10:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/13/2018 3:10:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/13/2018 2:51:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a92e27a2-9e75-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/13/2018 2:24:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/13/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32615)(?)])(1 )(2 )]

"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32615)(?)])(1 )(2 )]

"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32615)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/13/2018 2:19:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/13/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/13/2018 2:06:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 1:43:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 1:43:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/13/2018 1:07:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/13/2018 1:07:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:20Z. Reason: GVLK.
Information	8/13/2018 1:02:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/13/2018 1:02:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/13/2018 1:02:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/13/2018 1:02:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/13/2018 12:13:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/12/2018 10:20:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 9:51:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bf895ed7-9e4b-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/12/2018 9:43:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/12/2018 8:31:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/12/2018 6:35:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 5:43:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/12/2018 4:51:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5dd5b92-9e21-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/12/2018 4:49:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 4:31:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 4:31:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:57:02Z. Reason: GVLK.
Information	8/12/2018 4:26:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 4:26:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 4:26:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 4:26:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/12/2018 3:07:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 2:00:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 2:00:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:45Z. Reason: GVLK.
Information	8/12/2018 1:55:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 1:55:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 1:55:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 1:55:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/12/2018 1:43:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/12/2018 1:27:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 12:27:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8982.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/12/2018 11:51:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec188111-9df7-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/12/2018 11:47:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 11:31:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/12/2018 11:31:31 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/12/2018 11:31:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/12/2018 11:31:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/12/2018 11:31:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/12/2018 11:31:07 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 26191, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/12/2018 11:30:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/12/2018 11:30:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/12/2018 11:30:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	8/12/2018 10:09:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 9:43:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/12/2018 8:25:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 6:51:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 025343e7-9dce-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/12/2018 6:39:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 6:13:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 6:13:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:53Z. Reason: GVLK.
Information	8/12/2018 6:08:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 6:08:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 6:08:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 6:08:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/12/2018 5:47:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 5:47:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:25Z. Reason: GVLK.
Information	8/12/2018 5:42:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/12/2018 5:42:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 5:42:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 5:42:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 5:42:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/12/2018 4:55:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 4:21:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 4:21:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:26Z. Reason: GVLK.
Information	8/12/2018 4:16:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 4:16:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 4:16:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 4:16:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/12/2018 4:14:31 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/12/2018 4:09:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/12/2018 4:09:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:53Z. Reason: GVLK.
Error	8/12/2018 4:05:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/12/2018 4:04:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/12/2018 4:04:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 4:04:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 4:04:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/12/2018 3:01:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/12/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/12/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34055)(?)])(1 )(2 )]

"
Information	8/12/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/12/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34055)(?)])(1 )(2 )]

"
Information	8/12/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34055)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/12/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/12/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/12/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/12/2018 1:51:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 186ab55b-9da4-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/12/2018 1:42:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/12/2018 1:42:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/12/2018 1:23:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/12/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/11/2018 11:26:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 10:45:30 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/11/2018 9:42:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 9:42:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/11/2018 9:33:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 8:51:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e9d3f1c-9d7a-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/11/2018 7:38:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/11/2018 5:44:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 5:42:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 5:42:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/11/2018 4:06:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 3:51:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44f8244d-9d50-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/11/2018 2:31:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 2:19:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/11/2018 2:19:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:21Z. Reason: GVLK.
Information	8/11/2018 2:14:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/11/2018 2:14:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2018 2:14:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2018 2:14:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/11/2018 1:42:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 1:42:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 12:55:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8981.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/11/2018 12:45:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/11/2018 11:00:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 10:51:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b2e11c7-9d26-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/11/2018 9:42:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 9:41:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/11/2018 9:16:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/11/2018 7:24:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 5:51:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71892803-9cfc-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/11/2018 5:44:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 5:42:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 5:41:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/11/2018 3:48:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 3:25:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/11/2018 3:25:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:48Z. Reason: GVLK.
Information	8/11/2018 3:20:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/11/2018 3:20:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2018 3:20:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2018 3:20:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/11/2018 2:24:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/11/2018 2:19:34 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/11/2018 2:19:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35495)(?)])(1 )(2 )]

"
Information	8/11/2018 2:19:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/11/2018 2:19:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35495)(?)])(1 )(2 )]

"
Information	8/11/2018 2:19:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35495)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2018 2:19:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2018 2:19:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2018 2:19:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/11/2018 1:54:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/11/2018 1:42:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 1:41:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2018 12:51:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 87cf9228-9cd2-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/11/2018 12:13:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/10/2018 10:41:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 9:41:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2018 9:41:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/10/2018 8:50:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 7:51:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9df771d0-9ca8-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/10/2018 7:03:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 5:41:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2018 5:41:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/10/2018 5:06:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 4:29:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2018 4:29:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:24Z. Reason: GVLK.
Information	8/10/2018 4:24:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2018 4:24:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2018 4:24:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2018 4:24:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/10/2018 3:15:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 2:51:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b4449139-9c7e-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/10/2018 2:06:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/10/2018 2:06:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/10/2018 1:45:48 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/10/2018 1:41:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2018 1:41:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/10/2018 1:16:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 12:34:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/10/2018 12:34:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/10/2018 12:05:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8980.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/10/2018 11:27:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 10:19:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/10/2018 10:18:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/10/2018 10:18:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/10/2018 10:00:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2018 10:00:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:36Z. Reason: GVLK.
Information	8/10/2018 9:56:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/10/2018 9:53:48 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/10/2018 9:51:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2018 9:51:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2018 9:51:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2018 9:51:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/10/2018 9:51:22 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/10/2018 9:51:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36483)(?)])(1 )(2 )]

"
Information	8/10/2018 9:51:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/10/2018 9:51:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36483)(?)])(1 )(2 )]

"
Information	8/10/2018 9:51:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36483)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2018 9:51:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/10/2018 9:51:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2018 9:51:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/10/2018 9:51:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ca6903fe-9c54-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/10/2018 9:49:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2018 9:49:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:57:06Z. Reason: GVLK.
Error	8/10/2018 9:44:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/10/2018 9:44:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2018 9:44:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2018 9:44:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2018 9:44:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/10/2018 9:42:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/10/2018 9:41:29 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8979.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/10/2018 9:41:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/10/2018 9:41:10 AM	Application Error	1000	(100)	"Faulting application name: mcshield.exe, version: 15.6.0.1551, time stamp: 0x58d45994
Faulting module name: RPCRT4.dll, version: 6.1.7601.24150, time stamp: 0x5b0cbbc6
Exception code: 0xc0000005
Fault offset: 0x000000000002ed20
Faulting process id: 0x1114
Faulting application start time: 0x01d4288963aae52c
Faulting application path: C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
Faulting module path: C:\Windows\system32\RPCRT4.dll
Report Id: 68fb2957-9c53-11e8-9dcc-a12e9f4d6287"
Error	8/10/2018 9:41:07 AM	McLogEvent	5019	None	"Exception in McShield.Exe!
 Exception details follow : 
VSCORE.15.6.0.1551
Exception Code       : 0X00000000C0000005
Exception Address    : 0X000007FEFD2DED20
Exception Parameters : 2
 Param 1 = 0000000000000000
 Param 2 = 0XFFFFFFFFFFFFFFFF

More information :
"
Warning	8/9/2018 6:37:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 5:54:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T12:24:57.828571400Z.
Information	8/9/2018 5:54:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T12:24:57.828571400Z.
Information	8/9/2018 5:54:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T12:24:57.516585400Z.
Information	8/9/2018 5:54:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T12:24:57.516585400Z.
Information	8/9/2018 5:54:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T12:24:56.609826000Z.
Information	8/9/2018 5:54:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T12:24:56.609826000Z.
Information	8/9/2018 5:54:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T12:24:55.892258200Z.
Information	8/9/2018 5:54:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T12:24:55.892258200Z.
Information	8/9/2018 5:54:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T12:24:53.786352700Z.
Information	8/9/2018 5:54:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T12:24:53.786352700Z.
Information	8/9/2018 5:18:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2018 5:18:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/9/2018 5:18:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2018 5:15:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:38.839924500Z.
Information	8/9/2018 5:15:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:38.839924500Z.
Information	8/9/2018 5:15:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:37.545107900Z.
Information	8/9/2018 5:15:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:37.545107900Z.
Information	8/9/2018 5:15:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:35.461874300Z.
Information	8/9/2018 5:15:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:35.461874300Z.
Information	8/9/2018 5:15:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:35.052667300Z.
Information	8/9/2018 5:15:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:35.052667300Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:34.722461800Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:34.722461800Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:34.383256200Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:34.383256200Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:34.034050400Z.
Information	8/9/2018 5:15:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:34.034050400Z.
Information	8/9/2018 5:15:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:33.701245600Z.
Information	8/9/2018 5:15:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:33.701245600Z.
Information	8/9/2018 5:15:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:33.404841800Z.
Information	8/9/2018 5:15:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:33.404841800Z.
Information	8/9/2018 5:15:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:32.827634400Z.
Information	8/9/2018 5:15:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:32.827634400Z.
Information	8/9/2018 5:15:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:31.922822800Z.
Information	8/9/2018 5:15:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:31.922822800Z.
Information	8/9/2018 5:15:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:24.067839000Z.
Information	8/9/2018 5:15:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:24.067839000Z.
Information	8/9/2018 5:15:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:23.668632200Z.
Information	8/9/2018 5:15:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:23.668632200Z.
Information	8/9/2018 5:15:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:23.369427400Z.
Information	8/9/2018 5:15:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:23.369427400Z.
Information	8/9/2018 5:15:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:22.970220600Z.
Information	8/9/2018 5:15:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:22.970220600Z.
Information	8/9/2018 5:15:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:22.521012800Z.
Information	8/9/2018 5:15:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:22.521012800Z.
Information	8/9/2018 5:15:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:22.191006200Z.
Information	8/9/2018 5:15:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:22.191006200Z.
Information	8/9/2018 5:15:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:21.877601500Z.
Information	8/9/2018 5:15:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:21.877601500Z.
Information	8/9/2018 5:15:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:21.113191700Z.
Information	8/9/2018 5:15:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:21.113191700Z.
Information	8/9/2018 5:15:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎08‎-‎09T11:45:13.796697900Z.
Information	8/9/2018 5:15:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎08‎-‎09T11:45:13.796697900Z.
Warning	8/9/2018 4:45:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 3:27:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 943a1410-9bba-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/9/2018 3:09:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 2:47:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/9/2018 2:42:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/9/2018 2:42:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 2:42:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/9/2018 2:26:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2018 2:26:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:14Z. Reason: GVLK.
Information	8/9/2018 2:21:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2018 2:21:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2018 2:21:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 2:21:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2018 1:43:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2018 1:43:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:42Z. Reason: GVLK.
Information	8/9/2018 1:38:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2018 1:38:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2018 1:38:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 1:38:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/9/2018 1:35:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 1:18:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2018 12:40:26 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8979.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/9/2018 12:17:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/9/2018 12:17:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/9/2018 12:03:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 11:43:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/9/2018 11:42:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/9/2018 11:42:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/9/2018 11:42:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 7, Compared: 26023, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/9/2018 11:40:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/9/2018 11:40:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/9/2018 10:52:33 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/9/2018 10:28:37 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/9/2018 10:27:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/9/2018 10:27:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa6ec823-9b90-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/9/2018 10:17:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 9:18:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/9/2018 8:24:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/9/2018 6:26:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 5:27:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0c37614-9b66-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/9/2018 5:17:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2018 4:58:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2018 4:58:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:52Z. Reason: GVLK.
Information	8/9/2018 4:53:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2018 4:53:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2018 4:53:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 4:53:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/9/2018 4:51:47 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	8/9/2018 4:48:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 4:47:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2018 4:47:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:27Z. Reason: GVLK.
Error	8/9/2018 4:42:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/9/2018 4:42:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2018 4:42:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 4:42:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2018 3:09:18 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/9/2018 3:06:41 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	8/9/2018 3:02:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/9/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/9/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38375)(?)])(1 )(2 )]

"
Information	8/9/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/9/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38375)(?)])(1 )(2 )]

"
Information	8/9/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38375)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/9/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/9/2018 1:17:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/9/2018 1:03:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/9/2018 12:27:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d721d016-9b3c-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/9/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/8/2018 11:28:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/8/2018 9:47:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 9:41:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/8/2018 9:41:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:18Z. Reason: GVLK.
Information	8/8/2018 9:36:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/8/2018 9:36:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2018 9:36:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2018 9:36:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/8/2018 9:27:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎08T15:57:31.890123200Z.
Information	8/8/2018 9:27:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎08T15:57:29.831917400Z.
Information	8/8/2018 9:27:35 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{B04E9401-6471-498F-ABBF-EAF2D66B698B}v4.11.7451.0\CsDeviceControl.msi. Client Process Id: 10984.
Information	8/8/2018 9:27:35 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Device Control. Product Version: 4.11.7451.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	8/8/2018 9:27:35 PM	MsiInstaller	11707	None	Product: CrowdStrike Device Control -- Installation completed successfully.
Information	8/8/2018 9:27:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎08T15:57:31.890123200Z.
Information	8/8/2018 9:27:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎08T15:57:29.831917400Z.
Information	8/8/2018 9:27:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎08T15:57:13.235257900Z.
Information	8/8/2018 9:27:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎08T15:57:14.150349400Z.
Information	8/8/2018 9:27:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎08‎-‎08T15:57:11.958130200Z.
Information	8/8/2018 9:27:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{B04E9401-6471-498F-ABBF-EAF2D66B698B}v4.11.7451.0\CsDeviceControl.msi. Client Process Id: 10984.
Information	8/8/2018 9:27:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{A2432BF9-0069-432B-90F2-4FA95C12B0A6}v4.10.7310.0\CsAgent.msi. Client Process Id: 10984.
Information	8/8/2018 9:27:29 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.10.7310.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	8/8/2018 9:27:29 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	8/8/2018 9:27:14 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	8/8/2018 9:27:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎08T15:57:14.150349400Z.
Information	8/8/2018 9:27:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎08T15:57:13.235257900Z.
Information	8/8/2018 9:27:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎08‎-‎08T15:57:11.958130200Z.
Information	8/8/2018 9:27:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{A2432BF9-0069-432B-90F2-4FA95C12B0A6}v4.10.7310.0\CsAgent.msi. Client Process Id: 10984.
Information	8/8/2018 9:17:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/8/2018 8:04:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 7:27:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed76343b-9b12-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/8/2018 7:04:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/8/2018 6:59:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38815)(?)])(1 )(2 )]

"
Information	8/8/2018 6:59:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/8/2018 6:59:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38815)(?)])(1 )(2 )]

"
Information	8/8/2018 6:59:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38815)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2018 6:59:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/8/2018 6:59:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2018 6:59:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/8/2018 6:14:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 5:52:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/8/2018 5:52:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:57:00Z. Reason: GVLK.
Information	8/8/2018 5:47:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/8/2018 5:47:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2018 5:47:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2018 5:46:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/8/2018 5:17:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/8/2018 4:40:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/8/2018 3:00:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 2:27:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0303efd2-9ae9-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/8/2018 1:21:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 1:21:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 1:17:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/8/2018 1:03:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 12:29:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 12:28:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 12:25:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 12:25:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 12:24:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8978.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/8/2018 12:22:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 12:22:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 12:07:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 12:07:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 12:04:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 12:04:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/8/2018 11:03:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 10:52:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2018 10:52:25 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2018 10:41:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/8/2018 10:18:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/8/2018 10:18:20 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/8/2018 9:32:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/8/2018 9:27:19 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/8/2018 9:27:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39387)(?)])(1 )(2 )]

"
Information	8/8/2018 9:27:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/8/2018 9:27:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39387)(?)])(1 )(2 )]

"
Information	8/8/2018 9:27:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39387)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2018 9:27:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/8/2018 9:27:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2018 9:27:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/8/2018 9:26:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 190c4b5d-9abf-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/8/2018 9:21:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	8/8/2018 9:18:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/8/2018 9:17:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/7/2018 6:46:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 6:46:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 6:46:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/7/2018 6:30:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/7/2018 4:56:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/7/2018 4:34:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 4:29:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40405)(?)])(1 )(2 )]

"
Information	8/7/2018 4:29:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 4:29:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40405)(?)])(1 )(2 )]

"
Information	8/7/2018 4:29:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40405)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 4:29:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 4:29:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 4:29:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2018 3:32:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 3:27:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40467)(?)])(1 )(2 )]

"
Information	8/7/2018 3:27:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 3:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40467)(?)])(1 )(2 )]

"
Information	8/7/2018 3:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40467)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 3:27:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 3:27:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 3:27:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/7/2018 3:25:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/7/2018 3:10:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 3:05:50 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 171

Information	8/7/2018 3:05:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2018 3:05:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40489)(?)])(1 )(2 )]

"
Information	8/7/2018 3:05:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 3:05:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40489)(?)])(1 )(2 )]

"
Information	8/7/2018 3:05:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40489)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 3:05:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 3:05:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 3:05:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2018 2:54:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a1583b8d-9a23-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/7/2018 2:24:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 2:19:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40535)(?)])(1 )(2 )]

"
Information	8/7/2018 2:19:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 2:19:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40535)(?)])(1 )(2 )]

"
Information	8/7/2018 2:19:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 2:19:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 2:19:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 2:19:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2018 2:18:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 2:18:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 2:15:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 2:10:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40544)(?)])(1 )(2 )]

"
Information	8/7/2018 2:10:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 2:10:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40544)(?)])(1 )(2 )]

"
Information	8/7/2018 2:10:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40544)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 2:10:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 2:10:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 2:10:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2018 2:05:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 2:05:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 1:52:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	8/7/2018 1:35:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/7/2018 1:22:06 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/7/2018 1:19:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 1:19:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:53:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:52:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:47:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:46:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:29:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8977.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/7/2018 12:17:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:16:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:14:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:13:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:09:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:09:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:09:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:08:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 12:03:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 12:02:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 11:59:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 11:58:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/7/2018 11:58:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 11:52:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 11:52:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 11:47:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 11:46:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/7/2018 11:44:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/7/2018 11:25:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 11:25:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 11:12:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/7/2018 11:12:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/7/2018 10:45:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/7/2018 10:32:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 10:32:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-14T04:56:09Z. Reason: GVLK.
Information	8/7/2018 10:27:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 10:27:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 10:27:08 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/08/07 04:57"
Information	8/7/2018 10:27:07 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/08/07 04:57, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/7/2018 10:22:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/7/2018 10:22:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 10:22:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 10:22:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/7/2018 10:19:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/7/2018 10:04:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 10:04:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:04Z. Reason: GVLK.
Information	8/7/2018 9:59:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/7/2018 9:56:48 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/7/2018 9:54:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/7/2018 9:54:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 9:54:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 9:54:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/7/2018 9:54:13 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/7/2018 9:54:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40800)(?)])(1 )(2 )]

"
Information	8/7/2018 9:54:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 9:54:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40800)(?)])(1 )(2 )]

"
Information	8/7/2018 9:54:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40800)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 9:54:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b7901a04-99f9-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/7/2018 9:52:22 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	8/7/2018 9:52:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/7/2018 9:52:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:05Z. Reason: GVLK.
Information	8/7/2018 9:51:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2018 9:51:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40803)(?)])(1 )(2 )]

"
Information	8/7/2018 9:51:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2018 9:51:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40803)(?)])(1 )(2 )]

"
Information	8/7/2018 9:51:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40803)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 9:51:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2018 9:51:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 9:51:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	8/7/2018 9:47:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/7/2018 9:47:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/7/2018 9:47:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2018 9:47:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2018 9:47:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/7/2018 9:45:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Thursday, July 19, 2018 2:39:13 AM.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Class 3P Primary CA, O=Certplus, C=FR> Sha1 thumbprint: <216B2A29E62A00CE820146D8244141B92511B279>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Certinomis - Autorité Racine, OU=0002 433998903, O=Certinomis, C=FR> Sha1 thumbprint: <2E14DAEC28F0FA1E8E389A4EABEB26C00AD383C3>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Class 3 Primary CA, O=Certplus, C=FR> Sha1 thumbprint: <D2EDF88B41B6FE01461D6E2834EC7C8F6C77721E>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <C=IL, O=ComSign, CN=ComSign CA> Sha1 thumbprint: <E1A45B141A21DA1A79F41A42A961D669CD0634C1>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Class 3TS Primary CA, O=Certplus, C=FR> Sha1 thumbprint: <F44095C238AC73FC4F77BF8F98DF70F8F091BC52>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <C=IL, O=ComSign, CN=ComSign Secured CA> Sha1 thumbprint: <F9CD0E2CDA7624C18FBDF0F0ABB645B8F7FED57A>.
Information	8/7/2018 9:44:40 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Correo Uruguayo - Root CA, OU=SERVICIOS ELECTRONICOS, O=ADMINISTRACION NACIONAL DE CORREOS, C=UY> Sha1 thumbprint: <F9DD19266B2043F1FE4B3DCB0190AFF11F31A69D>.
Warning	8/6/2018 7:06:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 6:28:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 60a3cca2-9978-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/6/2018 6:20:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 6:20:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 6:20:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/6/2018 5:07:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 5:00:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 4:55:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41819)(?)])(1 )(2 )]

"
Information	8/6/2018 4:55:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/6/2018 4:55:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41819)(?)])(1 )(2 )]

"
Information	8/6/2018 4:55:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41819)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 4:53:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41821)(?)])(1 )(2 )]

"
Information	8/6/2018 4:53:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/6/2018 4:53:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41821)(?)])(1 )(2 )]

"
Information	8/6/2018 4:53:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41821)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 4:53:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/6/2018 4:53:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 4:53:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/6/2018 3:11:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 2:20:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 2:20:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 2:20:14 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/6/2018 2:19:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 2:07:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 2:07:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 2:03:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 2:02:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 1:41:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 1:41:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 1:38:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 1:38:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/6/2018 1:34:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 1:28:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 76f12042-994e-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/6/2018 1:00:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 1:00:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 12:53:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 12:53:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:32Z. Reason: GVLK.
Information	8/6/2018 12:48:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/6/2018 12:48:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 12:48:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 12:48:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/6/2018 12:31:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 12:31:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 12:29:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 12:28:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 12:12:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8976.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/6/2018 12:02:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 11:45:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/6/2018 11:44:55 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 25777, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/6/2018 11:43:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/6/2018 11:43:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/6/2018 11:42:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 11:41:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 11:38:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/6/2018 11:38:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/6/2018 11:30:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 11:30:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 11:27:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/6/2018 11:26:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/6/2018 10:22:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/6/2018 10:22:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/6/2018 10:22:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/6/2018 10:20:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 10:20:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 10:20:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 10:19:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/6/2018 10:08:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 9:48:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 9:48:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:08Z. Reason: GVLK.
Information	8/6/2018 9:43:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/6/2018 9:43:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 9:43:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 9:43:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/6/2018 8:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 861dbcbe-9924-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/6/2018 8:24:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 7:00:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 7:00:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:55Z. Reason: GVLK.
Information	8/6/2018 6:55:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/6/2018 6:55:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 6:55:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 6:55:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/6/2018 6:46:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 6:20:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 6:19:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 6:19:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/6/2018 4:48:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 3:37:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 3:37:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:21Z. Reason: GVLK.
Information	8/6/2018 3:32:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/6/2018 3:32:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 3:32:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 3:32:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/6/2018 3:30:39 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/6/2018 3:28:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 3:28:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:10Z. Reason: GVLK.
Information	8/6/2018 3:27:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c710f0b-98fa-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Error	8/6/2018 3:23:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/6/2018 3:23:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/6/2018 3:23:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/6/2018 3:13:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/6/2018 2:20:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/6/2018 2:19:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/6/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/6/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42695)(?)])(1 )(2 )]

"
Information	8/6/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/6/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42695)(?)])(1 )(2 )]

"
Information	8/6/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42695)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/6/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/6/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/6/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/6/2018 1:41:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/6/2018 12:05:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/6/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/5/2018 10:27:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b2e038c7-98d0-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/5/2018 10:25:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 10:20:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 10:19:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 10:19:53 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/5/2018 10:19:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 9:56:11 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	8/5/2018 8:52:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/5/2018 7:15:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 6:19:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 6:19:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 5:27:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c91bed7f-98a6-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/5/2018 5:27:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/5/2018 3:29:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 3:19:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/5/2018 3:19:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:28Z. Reason: GVLK.
Information	8/5/2018 3:14:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/5/2018 3:14:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/5/2018 3:14:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/5/2018 3:14:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/5/2018 2:19:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 2:19:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/5/2018 1:49:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 12:27:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df5379c6-987c-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/5/2018 12:19:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8975.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/5/2018 12:05:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 10:19:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 10:19:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/5/2018 10:16:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/5/2018 8:38:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 7:27:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5748d50-9852-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/5/2018 6:54:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 6:19:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 6:19:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 6:04:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/5/2018 6:04:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:51Z. Reason: GVLK.
Information	8/5/2018 5:59:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/5/2018 5:59:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/5/2018 5:59:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/5/2018 5:59:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/5/2018 5:07:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 4:39:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/5/2018 4:39:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:25Z. Reason: GVLK.
Information	8/5/2018 4:34:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/5/2018 4:34:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/5/2018 4:34:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/5/2018 4:34:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/5/2018 4:32:40 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/5/2018 4:29:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/5/2018 4:29:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:38Z. Reason: GVLK.
Error	8/5/2018 4:24:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/5/2018 4:24:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/5/2018 4:24:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/5/2018 4:24:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/5/2018 4:24:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/5/2018 3:11:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 2:27:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bb8fe9f-9829-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/5/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/5/2018 2:19:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/5/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44135)(?)])(1 )(2 )]

"
Information	8/5/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/5/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44135)(?)])(1 )(2 )]

"
Information	8/5/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44135)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/5/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/5/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/5/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/5/2018 2:19:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 2:19:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/5/2018 2:18:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/5/2018 1:21:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/5/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/4/2018 11:25:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 10:19:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 10:18:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 9:56:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2018 9:56:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:34Z. Reason: GVLK.
Information	8/4/2018 9:51:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2018 9:51:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2018 9:51:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2018 9:51:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/4/2018 9:27:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21ed563c-97ff-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/4/2018 9:25:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/4/2018 7:42:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 6:19:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 6:18:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/4/2018 6:06:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/4/2018 4:28:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 4:27:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3812baa5-97d5-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/4/2018 3:11:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2018 3:11:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:20Z. Reason: GVLK.
Information	8/4/2018 3:06:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2018 3:06:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2018 3:06:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2018 3:06:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/4/2018 2:37:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 2:19:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 2:18:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 12:43:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8974.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	8/4/2018 12:40:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 11:27:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e27b675-97ab-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/4/2018 11:17:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2018 11:17:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:28Z. Reason: GVLK.
Information	8/4/2018 11:12:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2018 11:12:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2018 11:12:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2018 11:12:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/4/2018 10:58:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 10:35:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/4/2018 10:18:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 10:18:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/4/2018 9:05:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 8:58:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/4/2018 8:57:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/4/2018 7:33:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 6:27:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6464faa6-9781-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/4/2018 6:18:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 6:18:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 6:14:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2018 6:14:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:00Z. Reason: GVLK.
Information	8/4/2018 6:09:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2018 6:09:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2018 6:09:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2018 6:08:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/4/2018 6:01:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/4/2018 4:13:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/4/2018 2:26:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/4/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/4/2018 2:19:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45575)(?)])(1 )(2 )]

"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45575)(?)])(1 )(2 )]

"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45575)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/4/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/4/2018 2:18:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2018 1:27:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7abb6d9e-9757-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/4/2018 12:49:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/3/2018 11:08:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 10:18:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/3/2018 9:10:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 8:27:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 91067e36-972d-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Warning	8/3/2018 7:17:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 6:18:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/3/2018 5:24:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/3/2018 3:51:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 3:27:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a746ceaf-9703-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/3/2018 2:18:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2018 2:17:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2018 2:17:50 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/3/2018 2:09:57 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/3/2018 1:56:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 1:07:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/3/2018 1:06:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/3/2018 12:16:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8973.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/3/2018 11:59:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2018 11:59:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:15Z. Reason: GVLK.
Warning	8/3/2018 11:57:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 11:54:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2018 11:54:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2018 11:54:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2018 11:54:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/3/2018 11:46:20 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/3/2018 11:46:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/3/2018 11:45:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/3/2018 11:45:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 17, Compared: 25792, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	8/3/2018 11:43:28 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/3/2018 11:43:28 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/3/2018 10:37:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2018 10:37:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:38Z. Reason: GVLK.
Information	8/3/2018 10:33:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/3/2018 10:30:49 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/3/2018 10:28:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2018 10:28:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2018 10:28:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2018 10:28:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/3/2018 10:28:06 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/3/2018 10:28:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46526)(?)])(1 )(2 )]

"
Information	8/3/2018 10:28:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/3/2018 10:28:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46526)(?)])(1 )(2 )]

"
Information	8/3/2018 10:28:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46526)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2018 10:28:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2018 10:28:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2018 10:28:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2018 10:27:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bd7e83b8-96d9-11e8-9dcc-a12e9f4d6287
Report Status: 0"
Information	8/3/2018 10:25:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2018 10:25:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:38Z. Reason: GVLK.
Error	8/3/2018 10:21:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/3/2018 10:20:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2018 10:20:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2018 10:20:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2018 10:20:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/3/2018 10:19:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/3/2018 10:18:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2018 10:18:04 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/3/2018 10:18:02 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/3/2018 10:17:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/3/2018 10:17:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/3/2018 10:17:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/2/2018 7:09:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/2/2018 5:23:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 5:20:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4440c475-964a-11e8-9dcc-204747d02364
Report Status: 0"
Information	8/2/2018 4:22:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/2/2018 3:43:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/2/2018 1:57:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 1:07:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/2/2018 1:07:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/2/2018 1:04:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/2/2018 1:04:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/2/2018 12:50:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8972.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/2/2018 12:46:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/2/2018 12:45:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/2/2018 12:39:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/2/2018 12:39:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/2/2018 12:27:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 12:25:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/2/2018 12:25:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/2/2018 12:22:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	8/2/2018 12:22:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2018 12:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47853)(?)])(1 )(2 )]

"
Information	8/2/2018 12:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/2/2018 12:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47853)(?)])(1 )(2 )]

"
Information	8/2/2018 12:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47853)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 12:21:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2018 12:21:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 12:21:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2018 12:20:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a87400a-9620-11e8-9dcc-204747d02364
Report Status: 0"
Warning	8/2/2018 12:04:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 10:18:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/2/2018 10:17:40 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/2/2018 10:17:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	8/2/2018 10:07:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 9:02:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 9:02:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:17Z. Reason: GVLK.
Information	8/2/2018 8:57:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2018 8:57:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 8:57:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 8:57:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	8/2/2018 8:15:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 7:20:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 70d6a82c-95f6-11e8-9dcc-204747d02364
Report Status: 0"
Information	8/2/2018 7:19:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/2/2018 6:42:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/2/2018 4:46:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 4:27:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 4:27:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:38Z. Reason: GVLK.
Information	8/2/2018 4:22:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2018 4:22:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 4:22:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 4:22:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2018 4:21:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 4:21:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:16Z. Reason: GVLK.
Error	8/2/2018 4:20:53 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	8/2/2018 4:16:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/2/2018 4:16:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2018 4:16:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 4:16:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 4:16:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2018 3:19:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/2/2018 3:04:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 2:20:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8720281d-95cc-11e8-9dcc-204747d02364
Report Status: 0"
Error	8/2/2018 2:19:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48455)(?)])(1 )(2 )]

"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48455)(?)])(1 )(2 )]

"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48455)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2018 2:02:44 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/2/2018 2:00:45 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	8/2/2018 1:22:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/2/2018 12:32:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2018 12:32:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:01Z. Reason: GVLK.
Information	8/2/2018 12:27:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2018 12:27:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2018 12:27:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2018 12:27:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/1/2018 11:25:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 11:19:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/1/2018 9:28:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 9:20:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d63e3b1-95a2-11e8-9dcc-204747d02364
Report Status: 0"
Information	8/1/2018 7:40:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2018 7:40:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:05Z. Reason: GVLK.
Warning	8/1/2018 7:35:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 7:35:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2018 7:35:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 7:35:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 7:35:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2018 7:19:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/1/2018 5:41:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 4:20:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3e32175-9578-11e8-9dcc-204747d02364
Report Status: 0"
Warning	8/1/2018 3:45:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 3:41:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2018 3:41:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:16Z. Reason: GVLK.
Information	8/1/2018 3:36:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2018 3:36:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 3:36:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 3:36:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/1/2018 3:29:57 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/1/2018 3:21:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2018 3:21:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:41Z. Reason: GVLK.
Information	8/1/2018 3:19:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	8/1/2018 3:14:28 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/1/2018 3:12:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2018 3:12:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 3:12:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 3:12:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2018 2:49:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 2:49:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/1/2018 2:08:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 1:00:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 1:00:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 12:42:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 12:42:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 12:38:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 12:37:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	8/1/2018 12:28:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 12:28:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 12:27:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 12:25:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 12:25:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 12:16:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 12:15:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8971.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/1/2018 12:15:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 12:00:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 11:59:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 11:55:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2018 11:55:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2018 11:27:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/1/2018 11:26:51 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/1/2018 11:20:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ca1dabb4-954e-11e8-9dcc-204747d02364
Report Status: 0"
Information	8/1/2018 11:19:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/1/2018 10:42:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	8/1/2018 10:35:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	8/1/2018 8:54:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 7:19:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	8/1/2018 7:11:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 6:20:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e04c46ed-9524-11e8-9dcc-204747d02364
Report Status: 0"
Warning	8/1/2018 5:27:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 4:21:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2018 4:21:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:48Z. Reason: GVLK.
Information	8/1/2018 4:16:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2018 4:16:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 4:16:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 4:16:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/1/2018 4:14:22 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/1/2018 4:10:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/1/2018 4:05:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2018 4:05:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:52:02Z. Reason: GVLK.
Information	8/1/2018 4:01:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Error	8/1/2018 4:00:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/1/2018 4:00:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2018 4:00:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 4:00:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 3:59:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2018 3:48:47 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	8/1/2018 3:43:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 3:18:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/1/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	8/1/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49895)(?)])(1 )(2 )]

"
Information	8/1/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/1/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49895)(?)])(1 )(2 )]

"
Information	8/1/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49895)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	8/1/2018 1:52:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	8/1/2018 1:20:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f68d5325-94fa-11e8-9dcc-204747d02364
Report Status: 0"
Warning	8/1/2018 12:20:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 11:22:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 11:22:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:42Z. Reason: GVLK.
Information	7/31/2018 11:18:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 11:17:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 11:17:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 11:17:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 11:17:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/31/2018 10:36:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/31/2018 8:53:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 8:20:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0cb9d521-94d1-11e8-9dcc-204747d02364
Report Status: 0"
Information	7/31/2018 7:23:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 7:18:51 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 234

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 172

Information	7/31/2018 7:18:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 7:18:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50316)(?)])(1 )(2 )]

"
Information	7/31/2018 7:18:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 7:18:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50316)(?)])(1 )(2 )]

"
Information	7/31/2018 7:18:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50316)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 7:17:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2018 7:17:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 7:17:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/31/2018 7:11:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 6:22:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 6:20:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/31/2018 5:38:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/31/2018 3:40:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 3:20:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2305e132-94a7-11e8-9dcc-204747d02364
Report Status: 0"
Information	7/31/2018 2:22:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 2:19:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/31/2018 1:58:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 1:49:41 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/31/2018 12:42:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/31/2018 12:11:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/31/2018 12:02:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/31/2018 11:50:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/31/2018 11:50:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/31/2018 11:49:42 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 25712, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/31/2018 11:48:29 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/31/2018 11:48:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/31/2018 11:48:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/31/2018 11:37:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 11:35:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/31/2018 11:35:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/31/2018 11:34:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 11:34:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:46Z. Reason: GVLK.
Information	7/31/2018 11:32:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50782)(?)])(1 )(2 )]

"
Information	7/31/2018 11:32:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 11:32:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50782)(?)])(1 )(2 )]

"
Information	7/31/2018 11:32:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50782)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 11:32:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2018 11:32:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 11:32:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 11:29:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 11:29:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 11:29:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 11:29:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 11:07:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 11:04:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 11:04:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:46Z. Reason: GVLK.
Information	7/31/2018 11:02:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50812)(?)])(1 )(2 )]

"
Information	7/31/2018 11:02:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 11:02:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50812)(?)])(1 )(2 )]

"
Information	7/31/2018 11:02:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50812)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 11:02:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2018 11:02:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 11:02:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 10:59:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 10:59:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:59:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 10:59:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 10:58:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 10:58:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:34Z. Reason: GVLK.
Information	7/31/2018 10:56:07 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8970.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/31/2018 10:53:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 10:53:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:53:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 10:53:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 10:48:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 10:48:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:22Z. Reason: GVLK.
Information	7/31/2018 10:43:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 10:43:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:43:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 10:43:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/31/2018 10:41:06 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/31/2018 10:36:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2018 10:36:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-08-07T04:51:38Z. Reason: GVLK.
Information	7/31/2018 10:29:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/31/2018 10:24:01 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/31/2018 10:24:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50850)(?)])(1 )(2 )]

"
Information	7/31/2018 10:24:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 10:24:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50850)(?)])(1 )(2 )]

"
Information	7/31/2018 10:24:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50850)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:22:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:22:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:22:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/07/31 04:52"
Information	7/31/2018 10:22:16 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/31 04:52, 0, 1, 247740, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/31/2018 10:21:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 10:21:50 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/31/2018 10:20:28 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 218

Information	7/31/2018 10:20:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38d78583-947d-11e8-9dcc-204747d02364
Report Status: 0"
Information	7/31/2018 10:19:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2018 10:19:12 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/31/2018 10:18:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50855)(?)])(1 )(2 )]

"
Information	7/31/2018 10:18:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 10:18:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50855)(?)])(1 )(2 )]

"
Information	7/31/2018 10:18:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50855)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	7/31/2018 10:18:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/31/2018 10:17:46 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2018 10:17:44 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2018 10:17:42 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2018 10:17:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	7/31/2018 10:17:29 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/31/2018 10:17:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50857)(?)])(1 )(2 )]

"
Information	7/31/2018 10:17:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2018 10:17:17 AM	ESENT	302	Logging/Recovery	Windows (8760) Windows: The database engine has successfully completed recovery steps.
Information	7/31/2018 10:17:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50857)(?)])(1 )(2 )]

"
Information	7/31/2018 10:17:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50857)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:17:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2018 10:17:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 247740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2018 10:17:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2018 10:17:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 10:17:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2018 10:17:09 AM	ESENT	301	Logging/Recovery	Windows (8760) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/31/2018 10:17:09 AM	ESENT	300	Logging/Recovery	Windows (8760) Windows: The database engine is initiating recovery steps.
Information	7/31/2018 10:17:09 AM	ESENT	102	General	Windows (8760) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/31/2018 10:17:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2018 10:17:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/31/2018 10:16:57 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	7/31/2018 10:16:57 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8966.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/31/2018 10:15:18 AM	Service1	0	None	Service started successfully.
Error	7/31/2018 10:15:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/31/2018 10:15:02 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/31/2018 10:14:45 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/31/2018 10:14:43 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/31/2018 10:14:41 AM	PostgreSQL	0	None	"2018-07-31 10:14:41 IST LOG:  redirecting log output to logging collector process
2018-07-31 10:14:41 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/31/2018 10:14:41 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/31/2018 10:14:40 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/31/2018 10:14:38 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/31/2018 10:14:18 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/31/2018 10:14:18 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:18 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/31/2018 10:14:18 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/31/2018 10:14:18 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/31/2018 10:14:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/31/2018 10:14:17 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/31/2018 10:14:16 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/31/2018 10:14:15 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4644 at 7/27/2018 3:50:55 PM (local) 7/27/2018 10:20:55 AM (UTC). This is an informational message only; no user action is required.
Information	7/31/2018 10:14:06 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/31/2018 10:13:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/31/2018 10:13:57 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/31/2018 10:13:57 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/31/2018 10:13:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/31/2018 10:13:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/31/2018 10:13:57 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/31/2018 10:13:57 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/31/2018 10:13:57 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/31/2018 10:13:57 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/31/2018 10:13:57 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4716.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/31/2018 10:13:46 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/31/2018 10:13:17 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/31/2018 10:13:09 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2018 10:12:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/31/2018 10:12:55 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/31/2018 10:12:56 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/27/2018 3:51:04 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	7/27/2018 3:50:55 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	7/27/2018 3:50:36 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 596 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2196 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	7/27/2018 3:50:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	7/27/2018 3:50:35 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	7/27/2018 3:50:35 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	7/27/2018 3:50:28 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	7/27/2018 3:25:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2018 3:18:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 39c9622f-9182-11e8-8384-204747d02364
Report Status: 0"
Warning	7/27/2018 3:08:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/27/2018 1:20:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/27/2018 12:56:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/27/2018 12:56:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/27/2018 11:57:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/27/2018 11:57:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/27/2018 11:48:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/27/2018 11:34:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 11:34:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:07Z. Reason: GVLK.
Information	7/27/2018 11:30:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 11:29:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2018 11:29:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 11:29:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 11:29:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 11:25:49 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 515

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 670

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 172

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	7/27/2018 11:25:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2018 11:25:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56549)(?)])(1 )(2 )]

"
Information	7/27/2018 11:25:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/27/2018 11:25:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56549)(?)])(1 )(2 )]

"
Information	7/27/2018 11:25:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56549)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 11:25:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2018 11:25:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 11:25:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 11:04:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 11:04:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:06Z. Reason: GVLK.
Information	7/27/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 10:59:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 10:51:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 10:51:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:53Z. Reason: GVLK.
Information	7/27/2018 10:50:47 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8966.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/27/2018 10:45:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2018 10:45:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 10:45:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 10:45:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/27/2018 10:43:08 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/27/2018 10:34:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 10:34:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:04Z. Reason: GVLK.
Information	7/27/2018 10:27:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/27/2018 10:22:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/27/2018 10:22:37 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/27/2018 10:22:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56612)(?)])(1 )(2 )]

"
Information	7/27/2018 10:22:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/27/2018 10:22:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56612)(?)])(1 )(2 )]

"
Information	7/27/2018 10:22:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56612)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 10:22:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2018 10:22:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 10:22:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 10:21:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2018 10:18:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4f46d807-9158-11e8-8384-204747d02364
Report Status: 0"
Information	7/27/2018 10:17:30 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	7/27/2018 10:16:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {FDA06FFF-AE35-429E-B27A-9DEF4786DF81}
Error	7/27/2018 10:16:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {FDA06FFF-AE35-429E-B27A-9DEF4786DF81}
Information	7/27/2018 10:16:14 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2018 10:16:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56618)(?)])(1 )(2 )]

"
Information	7/27/2018 10:16:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/27/2018 10:16:06 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2018 10:16:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56618)(?)])(1 )(2 )]

"
Information	7/27/2018 10:16:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56618)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 10:16:04 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2018 10:16:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2018 10:16:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 10:16:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 10:16:00 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	7/27/2018 10:15:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/27/2018 10:15:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2018 10:15:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2018 10:15:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2018 10:15:38 AM	ESENT	302	Logging/Recovery	Windows (8272) Windows: The database engine has successfully completed recovery steps.
Information	7/27/2018 10:15:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/27/2018 10:15:31 AM	ESENT	301	Logging/Recovery	Windows (8272) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/27/2018 10:15:31 AM	ESENT	300	Logging/Recovery	Windows (8272) Windows: The database engine is initiating recovery steps.
Information	7/27/2018 10:15:31 AM	ESENT	102	General	Windows (8272) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/27/2018 10:15:26 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8965.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/27/2018 10:14:31 AM	Service1	0	None	Service started successfully.
Information	7/27/2018 10:14:31 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/27/2018 10:14:26 AM	PostgreSQL	0	None	"2018-07-27 10:14:26 IST LOG:  redirecting log output to logging collector process
2018-07-27 10:14:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Error	7/27/2018 10:14:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/27/2018 10:14:11 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/27/2018 10:14:09 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/27/2018 10:14:05 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/27/2018 10:14:05 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/27/2018 10:13:45 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/27/2018 10:13:31 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:31 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/27/2018 10:13:31 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/27/2018 10:13:31 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/27/2018 10:13:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/27/2018 10:13:30 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/27/2018 10:13:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/27/2018 10:13:29 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/27/2018 10:13:28 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/27/2018 10:13:28 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4320 at 7/26/2018 7:54:17 PM (local) 7/26/2018 2:24:17 PM (UTC). This is an informational message only; no user action is required.
Information	7/27/2018 10:13:19 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/27/2018 10:13:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/27/2018 10:13:17 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/27/2018 10:13:17 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/27/2018 10:13:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/27/2018 10:13:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/27/2018 10:13:17 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/27/2018 10:13:16 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/27/2018 10:13:16 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/27/2018 10:13:16 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/27/2018 10:13:16 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4644.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/27/2018 10:13:10 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/27/2018 10:12:18 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/27/2018 10:12:05 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2018 10:11:37 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/27/2018 10:11:37 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/27/2018 10:11:37 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/26/2018 7:54:31 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	7/26/2018 7:54:17 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	7/26/2018 7:54:11 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 532 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 200 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 200 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2424 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 200 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 200 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 200 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2108 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	7/26/2018 7:54:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	7/26/2018 7:54:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	7/26/2018 7:54:10 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	7/26/2018 7:54:03 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	7/26/2018 7:54:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎07‎-‎26T14:24:02.778877100Z.
Information	7/26/2018 7:54:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎07‎-‎26T14:24:02.778877100Z.
Information	7/26/2018 7:54:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2018 7:54:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 7:54:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/26/2018 7:17:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 7:17:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:01Z. Reason: GVLK.
Information	7/26/2018 7:12:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2018 7:12:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 7:12:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 7:12:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/26/2018 7:11:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 6:09:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e4a66cb2-90d0-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/26/2018 5:16:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 4:58:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/26/2018 4:34:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57685)(?)])(1 )(2 )]

"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57685)(?)])(1 )(2 )]

"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57685)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2018 4:29:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 4:29:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/26/2018 3:24:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 1:53:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 1:53:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:53Z. Reason: GVLK.
Information	7/26/2018 1:48:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2018 1:48:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 1:48:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 1:48:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/26/2018 1:37:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 1:37:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/26/2018 1:27:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 1:09:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fadac301-90a6-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/26/2018 1:02:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 1:01:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 12:58:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/26/2018 12:58:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/26/2018 12:57:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/26/2018 12:57:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 12:56:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 12:32:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 12:31:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 12:19:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 12:19:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 12:17:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 12:16:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 12:16:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8965.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/26/2018 12:04:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/26/2018 11:59:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/26/2018 11:59:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57955)(?)])(1 )(2 )]

"
Information	7/26/2018 11:59:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2018 11:59:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57955)(?)])(1 )(2 )]

"
Information	7/26/2018 11:59:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57955)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 11:59:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2018 11:59:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 11:59:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	7/26/2018 11:59:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	7/26/2018 11:50:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 11:47:11 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/26/2018 11:45:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 25417, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/26/2018 11:44:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/26/2018 11:44:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/26/2018 11:43:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/26/2018 11:43:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/26/2018 11:30:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/26/2018 11:30:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/26/2018 11:02:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/26/2018 11:02:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/26/2018 10:45:43 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/26/2018 10:32:24 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/26/2018 10:32:23 AM	PostgreSQL	0	None	"2018-07-26 10:32:23 IST LOG:  redirecting log output to logging collector process
2018-07-26 10:32:23 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/26/2018 10:32:23 AM	PostgreSQL	0	None	Waiting for server startup...

Warning	7/26/2018 10:09:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 9:02:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 8:57:59 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 983

Information	7/26/2018 8:57:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/26/2018 8:57:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58137)(?)])(1 )(2 )]

"
Information	7/26/2018 8:57:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2018 8:57:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58137)(?)])(1 )(2 )]

"
Information	7/26/2018 8:57:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58137)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 8:57:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2018 8:57:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 8:57:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/26/2018 8:30:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 8:09:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 110c7ea1-907d-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/26/2018 6:55:06 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎26T01:24:49.539836500Z.
Information	7/26/2018 6:55:06 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎26T01:24:50.553914500Z.
Information	7/26/2018 6:55:06 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎26T01:24:48.712972900Z.
Information	7/26/2018 6:55:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{9112FE01-ED56-4B34-8B9E-C70A5E491899}v4.10.7304.0\CsAgent.msi. Client Process Id: 3216.
Information	7/26/2018 6:55:06 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.10.7304.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/26/2018 6:55:06 AM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	7/26/2018 6:54:50 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	7/26/2018 6:54:50 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎26T01:24:50.553914500Z.
Information	7/26/2018 6:54:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎26T01:24:49.539836500Z.
Information	7/26/2018 6:54:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎26T01:24:48.712972900Z.
Information	7/26/2018 6:54:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{9112FE01-ED56-4B34-8B9E-C70A5E491899}v4.10.7304.0\CsAgent.msi. Client Process Id: 3216.
Warning	7/26/2018 6:49:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/26/2018 4:51:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 4:11:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 4:11:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:32Z. Reason: GVLK.
Information	7/26/2018 4:06:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2018 4:06:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 4:06:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 4:06:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/26/2018 4:03:46 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/26/2018 3:59:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 3:59:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:53Z. Reason: GVLK.
Error	7/26/2018 3:55:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/26/2018 3:54:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2018 3:54:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 3:54:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 3:54:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/26/2018 3:29:49 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/26/2018 3:27:06 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/26/2018 3:17:41 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/26/2018 3:09:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27297401-9053-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/26/2018 3:03:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 2:24:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/26/2018 2:19:34 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/26/2018 2:19:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58535)(?)])(1 )(2 )]

"
Information	7/26/2018 2:19:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2018 2:19:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58535)(?)])(1 )(2 )]

"
Information	7/26/2018 2:19:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 2:19:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2018 2:19:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 2:19:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/26/2018 1:31:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/26/2018 12:36:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2018 12:36:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:17Z. Reason: GVLK.
Information	7/26/2018 12:31:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2018 12:31:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2018 12:31:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2018 12:31:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/25/2018 11:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 10:09:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d4dfb93-9029-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/25/2018 9:34:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/25/2018 7:54:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	7/25/2018 7:25:06 PM	Application Error	1000	(100)	"Faulting application name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x57316441
Faulting module name: MSVCR120.dll, version: 12.0.21005.1, time stamp: 0x524f83ff
Exception code: 0xc0000005
Fault offset: 0x000000000003c3f9
Faulting process id: 0x342c
Faulting application start time: 0x01d423cf29584aff
Faulting application path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Faulting module path: C:\Windows\system32\MSVCR120.dll
Report Id: 555973fa-9012-11e8-a8e6-204747d02364"
Information	7/25/2018 6:34:23 PM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Warning	7/25/2018 6:18:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 6:09:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 6:09:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 5:09:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 536ab330-8fff-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/25/2018 4:23:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/25/2018 2:42:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 2:22:10 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/25/2018 2:21:49 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/25/2018 2:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 1:41:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 1:41:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 1:39:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 1:39:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 1:11:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2018 1:11:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:36Z. Reason: GVLK.
Information	7/25/2018 1:09:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 1:09:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 1:06:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2018 1:06:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2018 1:06:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2018 1:06:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/25/2018 1:06:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 1:05:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/25/2018 12:45:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 12:30:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 12:30:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 12:22:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 12:22:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 12:19:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 12:18:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 12:18:09 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8964.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/25/2018 12:16:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 12:15:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 12:09:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 12:09:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 12:08:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 68a4623a-8fd5-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/25/2018 11:43:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2018 11:42:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2018 10:45:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	7/25/2018 10:45:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 10:09:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 10:09:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/25/2018 8:53:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/25/2018 7:12:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 7:08:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7eeeb835-8fab-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/25/2018 6:09:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 5:24:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2018 5:24:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:06Z. Reason: GVLK.
Information	7/25/2018 5:19:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2018 5:19:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2018 5:19:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2018 5:19:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/25/2018 5:17:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 4:18:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2018 4:18:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:56Z. Reason: GVLK.
Information	7/25/2018 4:13:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2018 4:13:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2018 4:13:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2018 4:13:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/25/2018 4:12:26 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/25/2018 4:09:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2018 4:09:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:41Z. Reason: GVLK.
Error	7/25/2018 4:04:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/25/2018 4:04:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2018 4:04:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2018 4:04:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2018 4:04:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/25/2018 3:22:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 3:21:21 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/25/2018 3:19:32 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/25/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/25/2018 2:19:32 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/25/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59975)(?)])(1 )(2 )]

"
Information	7/25/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/25/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59975)(?)])(1 )(2 )]

"
Information	7/25/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/25/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/25/2018 2:09:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 2:08:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2018 2:08:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95500d57-8f81-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/25/2018 1:24:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/25/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/24/2018 11:34:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 10:09:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 10:09:03 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/24/2018 10:08:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/24/2018 9:41:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 9:08:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ab20b0b0-8f57-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/24/2018 7:43:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 6:08:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/24/2018 5:53:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/24/2018 4:18:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 4:08:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c15f052c-8f2d-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/24/2018 2:17:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 2:08:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 1:30:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:30:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:28:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:27:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:27:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:26:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:23:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:23:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:21:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:20:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:04:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:04:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 1:01:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 1:01:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 12:51:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 12:51:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 12:49:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 12:49:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:00Z. Reason: GVLK.
Information	7/24/2018 12:46:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 12:46:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 12:44:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 12:44:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 12:43:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 12:43:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 12:43:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2018 12:43:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 12:42:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8963.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	7/24/2018 12:32:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 11:54:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 11:53:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 11:38:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 11:38:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 11:24:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/24/2018 11:24:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/24/2018 11:11:17 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/24/2018 11:10:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/24/2018 11:08:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7aead47-8f03-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/24/2018 10:58:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	7/24/2018 10:52:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 10:13:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 10:08:39 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 1076

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 546

Information	7/24/2018 10:08:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60947)(?)])(1 )(2 )]

"
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60947)(?)])(1 )(2 )]

"
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60947)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2018 10:07:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 10:07:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/24/2018 8:57:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/24/2018 7:16:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 6:47:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 6:47:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 6:08:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ede0b7a6-8ed9-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/24/2018 5:25:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 5:00:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 5:00:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:07Z. Reason: GVLK.
Information	7/24/2018 4:55:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 4:55:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 4:55:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 4:55:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/24/2018 3:33:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 3:26:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 3:26:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:04Z. Reason: GVLK.
Information	7/24/2018 3:21:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 3:21:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 3:21:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 3:21:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2018 3:19:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 3:19:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:24Z. Reason: GVLK.
Error	7/24/2018 3:18:54 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/24/2018 3:14:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 3:14:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 3:14:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 3:14:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2018 3:13:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 3:13:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:31Z. Reason: GVLK.
Error	7/24/2018 3:09:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/24/2018 3:08:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 3:08:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 3:08:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 3:08:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2018 2:47:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 2:47:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2018 2:24:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/24/2018 2:19:33 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/24/2018 2:19:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61415)(?)])(1 )(2 )]

"
Information	7/24/2018 2:19:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61415)(?)])(1 )(2 )]

"
Information	7/24/2018 2:19:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61415)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 2:19:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2018 2:19:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 2:19:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2018 2:08:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2018 2:08:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:24:01Z. Reason: GVLK.
Information	7/24/2018 2:03:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2018 2:03:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2018 2:03:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2018 2:03:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/24/2018 1:53:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 1:08:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0429dd73-8eb0-11e8-a8e6-204747d02364
Report Status: 0"
Warning	7/24/2018 12:19:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/24/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/23/2018 10:47:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 10:47:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/23/2018 10:20:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/23/2018 8:42:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 8:08:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a6a6570-8e86-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/23/2018 6:47:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/23/2018 6:46:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 6:46:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 5:13:28 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/23/2018 5:09:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/23/2018 3:12:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 3:08:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30a3ff86-8e5c-11e8-a8e6-204747d02364
Report Status: 0"
Information	7/23/2018 2:47:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 2:46:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 1:48:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/23/2018 1:47:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/23/2018 1:34:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 12:47:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/23/2018 12:47:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/23/2018 12:45:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/23/2018 12:44:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/23/2018 12:29:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/23/2018 12:28:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/23/2018 12:06:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 12:06:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:43Z. Reason: GVLK.
Information	7/23/2018 12:01:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/23/2018 12:01:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 12:01:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 12:01:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/23/2018 11:45:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 11:43:03 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/23/2018 11:42:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/23/2018 11:42:37 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/23/2018 11:41:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 28, Compared: 25308, Queries: 0, Results: 0, Version: 16.0.9126.2227.
Information	7/23/2018 11:40:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/23/2018 11:40:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/23/2018 11:34:51 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/23/2018 11:34:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/23/2018 11:11:07 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8962.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/23/2018 10:59:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:59:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-30T05:23:07Z. Reason: GVLK.
Information	7/23/2018 10:54:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:54:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:54:06 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/07/23 05:24"
Information	7/23/2018 10:54:03 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/23 05:24, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/23/2018 10:52:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:47:29 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 343

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 812

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 172

Information	7/23/2018 10:47:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 10:47:16 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/23/2018 10:46:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/23/2018 10:45:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62348)(?)])(1 )(2 )]

"
Information	7/23/2018 10:45:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/23/2018 10:45:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62348)(?)])(1 )(2 )]

"
Information	7/23/2018 10:45:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62348)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:45:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/23/2018 10:45:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:45:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:35:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/23/2018 10:35:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:35:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:35:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:33:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/23/2018 10:33:12 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/23/2018 10:28:23 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7968.
Information	7/23/2018 10:28:23 AM	MsiInstaller	1029	None	Product: Office 16 Click-to-Run Licensing Component. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	7/23/2018 10:28:23 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	7/23/2018 10:28:23 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:28:23 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	7/23/2018 10:28:22 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/23/2018 10:28:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62366)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:28:21 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/23/2018 10:28:21 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/23/2018 10:28:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:28:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/23/2018 10:28:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:28:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:28:17 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: SearchFilterHost , Id 10332.
Information	7/23/2018 10:28:17 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 4384.
Information	7/23/2018 10:28:17 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: explorer , Id 7368.
Information	7/23/2018 10:28:17 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 2748.
Information	7/23/2018 10:28:16 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: SearchFilterHost , Id 10332.
Information	7/23/2018 10:28:16 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 4384.
Information	7/23/2018 10:28:16 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: explorer , Id 7368.
Information	7/23/2018 10:28:16 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 2748.
Information	7/23/2018 10:28:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:27:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:27:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:51Z. Reason: GVLK.
Information	7/23/2018 10:27:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:38 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:38 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.9126.2259. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:27:38 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	7/23/2018 10:27:35 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:35 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:35 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:27:35 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	7/23/2018 10:27:32 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:32 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:27:32 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	7/23/2018 10:27:26 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:26 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/23/2018 10:27:26 AM	ESENT	102	General	Windows (9212) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/23/2018 10:27:26 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:26 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:27:26 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	7/23/2018 10:27:09 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:06 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/23/2018 10:27:06 AM	ESENT	103	General	Windows (10552) Windows: The database engine stopped the instance (0).
Information	7/23/2018 10:27:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7968.
Information	7/23/2018 10:27:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.9126.2259. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/23/2018 10:27:06 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	7/23/2018 10:26:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7968.
Warning	7/23/2018 10:25:12 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	7/23/2018 10:25:12 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/23/2018 10:25:12 AM	ESENT	102	General	Windows (10552) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/23/2018 10:25:10 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/23/2018 10:25:10 AM	ESENT	103	General	Windows (7688) Windows: The database engine stopped the instance (0).
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:01 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/23/2018 10:25:00 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:25:00 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:24:58 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:24:58 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=583b478c-7e1a-4840-9b5e-d5e19ce0ab3c"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=966723c9-5b17-4ced-b987-c3ee917781b2"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=71fea0ea-41ba-4ec0-aa3e-a3fa376a2cd0"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2ac442f8-fac5-4e36-854e-237ddbcc6e11"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3310dd32-79c4-4d0f-ad25-4dc943af9284"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=88245e23-b222-4105-8efe-713210e4b3df"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9b94d623-40d9-4e9b-a29e-db274abba5ab"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=027f1584-8b7c-42c0-b55e-9c60729bb2f2"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e044947d-2221-4786-accf-d6d1f254b9f0"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=927f1be5-0947-4517-9823-87af4cc9abe5"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=01bfc0b6-07c5-4f73-8ec6-57dcf0ff1225"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1401b628-7c2b-480c-a6ff-174bdf0f7357"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb285c5-aadb-44f7-84bd-8bc5a2003224"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=237b8eea-0d16-4d4c-9ca7-7786492ed334"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d3e4d451-be8c-4934-baf3-15aefe029ce2"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=44ec0a4d-5df4-4f05-a4da-e6ed3a2343f5"
Information	7/23/2018 10:23:11 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a6bbd738-fb43-43ea-b573-345b73203659"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=9a4c764f-be20-4874-a92e-4687fdff75b1"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=249cc98a-426c-4f30-8b09-dbc991321652"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c8357166-d27b-48e5-86ea-8955d6464d72"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=19fc6dc0-f32a-47a6-a95f-b9b9cb21a97b"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6dec14c8-c21b-4787-9a7c-8960bf580380"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b6d04406-9548-4952-930e-94af630b0313"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1a7462e0-ffbb-4318-9416-dc909424a1bf"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=78094778-3c24-4192-bc3d-e65cbbf1143a"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=29624b21-77b6-45cb-83b2-e86adf08613a"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff7a35a9-0a0e-40c2-8b2a-34e28786f634"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=89ae1f57-3f80-499a-9a4c-09aa59e0600f"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1578b234-6877-4cdb-acf2-d96f0769b3ed"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7a23289f-b442-4610-97fa-d685e68c1348"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=225d37d9-56c6-423a-9d3e-83fa03172120"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4f141d9-a23e-45d4-9f53-ad49623ae716"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=86d954b2-48b9-4e6c-9cc7-9e6ea5ecdb75"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=985329e4-631a-4bb5-b23f-ccc19126d217"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4142355a-a9ac-41c2-bd1f-bdbc3eeb9b79"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe1ddfa5-ea9d-48a2-bb79-2e8853e7a851"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bee90c7-f538-4252-b50f-316883b4becf"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=e38571b6-af68-434f-a14a-2b1d6658babb"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=34aca3f6-86fa-48bc-a5d4-b8a920f7c135"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1be3b35d-6001-46a7-9026-fb31a85d2dc8"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=adb8a6cd-dea8-49c7-ae0d-a197bbd2642e"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=25ee5a44-7ca5-4f82-9d26-4338856a73bc"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6d493bda-faac-4703-a3cb-a49248648a18"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f37c1296-cddb-4132-95b7-a9626599499a"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=f44fe831-4d47-491b-8fbd-3d56cb507a90"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5e74c7d2-9e0f-42b7-917b-b6c6fef6a1e7"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d24c2a89-fd3d-4344-b905-e1836fbc0ddb"
Information	7/23/2018 10:23:10 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=433cb6d2-07c6-4670-a335-173236850344"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=2cc57cbd-3438-4dec-afce-5b24b58bf1f8"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd110ae3-4b40-4e96-a2d1-5afc2bf7522c"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=3914f258-15f4-46ce-a70e-3844db8add2e"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7291e2c3-4471-4c62-a3e8-d49b4308c769"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b1e9c297-1a7f-477f-a676-24189c596b01"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=dba899fc-2a13-46d1-bc95-1f6098de78e9"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9cb3c722-4152-411d-a396-f5c933013210"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=51077ee1-c9a2-4f48-8511-c1f302203e46"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=02e5b1fc-02e7-421c-aec0-c07b3635c539"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bc9ad4c6-ce6f-4c49-bb35-77436b48ca75"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=914e214e-ffb6-4531-8ac4-be64f6a71712"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7e3568d2-a8b8-422f-87e5-e0ff150d2eb5"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	7/23/2018 10:23:09 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Error	7/23/2018 10:22:33 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -1073422333
"
Information	7/23/2018 10:22:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62372)(?)])(1 )(2 )]

"
Information	7/23/2018 10:22:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/23/2018 10:22:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62372)(?)])(1 )(2 )]

"
Information	7/23/2018 10:22:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62372)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:22:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/23/2018 10:22:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:22:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/23/2018 10:22:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:22:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:22:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:22:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:21:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:21:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:43Z. Reason: GVLK.
Information	7/23/2018 10:21:40 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎23T04:51:40.285329700Z.
Information	7/23/2018 10:16:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/23/2018 10:16:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:16:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:16:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:13:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/23/2018 10:13:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:30Z. Reason: GVLK.
Warning	7/23/2018 10:13:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/23/2018 10:10:26 AM	McLogEvent	257	None	The scan of D:\4sightv2\SetUpFile_2018_05_11_Fr_19_50_58_9382\DISK1\ISSetupPrerequisites\{7E4BD306-FC5C-4706-91E0-21DEB7567637}\postgresql-9.5.3-1-windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8959.0000.
Error	7/23/2018 10:09:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/23/2018 10:07:29 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/23/2018 10:07:19 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/23/2018 10:07:18 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/23/2018 10:07:17 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/23/2018 10:06:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/23/2018 10:06:46 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/23/2018 10:06:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/23/2018 10:06:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/23/2018 10:05:53 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/23/2018 10:05:40 AM	ESENT	302	Logging/Recovery	Windows (7688) Windows: The database engine has successfully completed recovery steps.
Information	7/23/2018 10:05:35 AM	ESENT	301	Logging/Recovery	Windows (7688) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/23/2018 10:05:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/23/2018 10:05:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/23/2018 10:05:35 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	7/23/2018 10:05:35 AM	ESENT	300	Logging/Recovery	Windows (7688) Windows: The database engine is initiating recovery steps.
Information	7/23/2018 10:05:35 AM	ESENT	102	General	Windows (7688) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/23/2018 10:05:35 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	7/23/2018 10:05:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/23/2018 10:05:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/23/2018 10:05:15 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8959.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/23/2018 10:04:01 AM	Service1	0	None	Service started successfully.
Error	7/23/2018 10:03:51 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/23/2018 10:03:47 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/23/2018 10:03:46 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/23/2018 10:03:40 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/23/2018 10:03:39 AM	PostgreSQL	0	None	"2018-07-23 10:03:39 IST LOG:  redirecting log output to logging collector process
2018-07-23 10:03:39 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/23/2018 10:03:36 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/23/2018 10:03:01 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/23/2018 10:03:00 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database msdb (database ID 4) in 1 second(s) (analysis 129 ms, redo 0 ms, undo 1155 ms.) This is an informational message only. No user action is required.
Information	7/23/2018 10:03:00 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:59 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/23/2018 10:02:59 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/23/2018 10:02:59 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/23/2018 10:02:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/23/2018 10:02:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:58 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/23/2018 10:02:57 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/23/2018 10:02:56 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	7/23/2018 10:02:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/23/2018 10:02:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/23/2018 10:02:55 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/23/2018 10:02:55 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/23/2018 10:02:54 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/23/2018 10:02:54 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/23/2018 10:02:54 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/23/2018 10:02:53 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/23/2018 10:02:46 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:46 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:46 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/23/2018 10:02:45 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/23/2018 10:02:44 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	7/23/2018 10:02:44 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/23/2018 10:02:44 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/23/2018 10:02:44 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4032 at 7/20/2018 10:25:55 PM (local) 7/20/2018 4:55:55 PM (UTC). This is an informational message only; no user action is required.
Information	7/23/2018 10:02:44 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/23/2018 10:02:38 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/23/2018 10:02:38 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/23/2018 10:02:38 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/23/2018 10:02:38 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/23/2018 10:02:38 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4320.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/23/2018 10:02:25 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/23/2018 10:01:25 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/23/2018 10:00:55 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/23/2018 9:59:33 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/23/2018 9:59:23 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/23/2018 9:59:07 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/20/2018 10:25:55 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	7/20/2018 10:25:25 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4060 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1008 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4060 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1516 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	7/20/2018 10:25:26 PM	MTAService.OnSessionChange	0	None	10:25:26 PM - Logoff
Information	7/20/2018 10:25:25 PM	MTAService.OnSessionChange	0	None	10:25:25 PM - Session change notice received: SessionLogoff Session ID: 1
Information	7/20/2018 10:25:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	7/20/2018 10:25:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	7/20/2018 10:25:24 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	7/20/2018 10:25:21 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	7/20/2018 10:25:13 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	7/20/2018 9:03:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 452c6780-8c32-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/20/2018 8:50:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 8:25:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 8:25:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 8:24:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 7:50:54 PM	MTAService.OnSessionChange	0	None	7:50:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 7:21:13 PM	MTAService.OnSessionChange	0	None	7:21:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/20/2018 7:00:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 5:49:13 PM	MTAService.OnSessionChange	0	None	5:49:13 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/20/2018 5:24:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 4:53:14 PM	MTAService.OnSessionChange	0	None	4:53:14 PM - Session change notice received: SessionLock Session ID: 1
Information	7/20/2018 4:25:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 4:25:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 4:24:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 4:16:15 PM	MTAService.OnSessionChange	0	None	4:16:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 4:04:46 PM	MTAService.OnSessionChange	0	None	4:04:46 PM - Session change notice received: SessionLock Session ID: 1
Information	7/20/2018 4:03:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5b5f07e3-8c08-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/20/2018 3:45:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 3:33:53 PM	MTAService.OnSessionChange	0	None	3:33:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 2:14:31 PM	MTAService.OnSessionChange	0	None	2:14:31 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/20/2018 2:13:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 2:00:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/20/2018 2:00:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66473)(?)])(1 )(2 )]

"
Information	7/20/2018 2:00:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66473)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 2:00:54 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66473)(?)])(1 )(2 )]

"
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109673  Grace type=8.
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=c4d38200-a451-4a9b-927a-8f022ea54a89"
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=2ad47a6c-9622-4a67-9002-d93402397c2f"
Information	7/20/2018 2:00:52 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/20/2018 2:00:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/20/2018 2:00:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20394)(?)])(1 )(2 )]

"
Information	7/20/2018 2:00:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20394)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 2:00:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/20/2018 2:00:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 2:00:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 2:00:13 PM	MTAService.OnSessionChange	0	None	2:00:13 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 1:33:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 1:33:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:52Z. Reason: GVLK.
Information	7/20/2018 1:28:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 1:28:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 1:28:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 1:28:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 1:14:44 PM	MTAService.OnSessionChange	0	None	1:14:44 PM - Session change notice received: SessionLock Session ID: 1
Information	7/20/2018 12:44:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/20/2018 12:44:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/20/2018 12:41:24 PM	MTAService.OnSessionChange	0	None	12:41:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 12:40:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8959.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	7/20/2018 12:38:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 12:28:15 PM	MTAService.OnSessionChange	0	None	12:28:15 PM - Session change notice received: SessionLock Session ID: 1
Information	7/20/2018 12:25:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 12:24:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 12:24:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 12:20:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 12:14:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/20/2018 12:14:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 12:14:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 12:11:48 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/20/2018 12:10:04 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/20/2018 12:09:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/20/2018 11:58:22 AM	MTAService.OnSessionChange	0	None	11:58:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/20/2018 11:29:57 AM	MTAService.OnSessionChange	0	None	11:29:57 AM - Session change notice received: SessionLock Session ID: 1
Information	7/20/2018 11:03:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71ac2ca6-8bde-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/20/2018 10:44:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 10:07:14 AM	MTAService.OnSessionChange	0	None	10:07:14 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/20/2018 9:14:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 8:25:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 8:24:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 8:24:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/20/2018 7:15:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 6:59:47 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13352) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 11168) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 11476) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 11088) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 5064) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 5652) cannot be restarted - Application SID does not match Conductor SID..
Information	7/20/2018 6:59:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎20T01:29:46.584269000Z.
Information	7/20/2018 6:59:43 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎07‎-‎20T01:29:43.076918300Z.
Information	7/20/2018 6:53:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 6:53:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:55Z. Reason: GVLK.
Information	7/20/2018 6:48:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 6:48:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 6:48:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 6:48:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 6:03:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 878bc8e9-8bb4-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/20/2018 5:35:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 5:03:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 5:03:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:08Z. Reason: GVLK.
Information	7/20/2018 4:58:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 4:58:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 4:58:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 4:58:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/20/2018 4:56:06 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/20/2018 4:49:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 4:49:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:20Z. Reason: GVLK.
Error	7/20/2018 4:44:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/20/2018 4:44:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 4:44:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 4:44:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 4:44:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 4:24:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 4:24:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 3:52:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 3:52:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:41Z. Reason: GVLK.
Warning	7/20/2018 3:52:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 3:47:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 3:47:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 3:47:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 3:47:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 3:47:15 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/20/2018 3:39:27 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎19T22:05:57.168214700Z.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 11360.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/20/2018 3:39:27 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4338420. Installation success or error status: 0.
Information	7/20/2018 3:39:27 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4338420' installed successfully.
Information	7/20/2018 3:37:44 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:44 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:43 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:43 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:43 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:42 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:42 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:41 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:41 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:41 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:33 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/20/2018 3:37:33 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00001.log
Information	7/20/2018 3:37:28 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/20/2018 3:37:27 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:26 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	7/20/2018 3:37:25 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/20/2018 3:37:25 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00000.log
Information	7/20/2018 3:37:21 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/20/2018 3:37:21 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/20/2018 3:37:13 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/20/2018 3:37:11 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	7/20/2018 3:37:03 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:37:03 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	7/20/2018 3:36:51 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:49 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: WmiPrvSE , Id 24564.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4888.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: WmiPrvSE , Id 24564.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4888.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4888.
Information	7/20/2018 3:36:45 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:44 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5984.
Information	7/20/2018 3:36:44 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 4916.
Information	7/20/2018 3:36:44 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4888.
Information	7/20/2018 3:36:44 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 4060.
Information	7/20/2018 3:36:44 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Aspnet_perf.dll is being used by the following process: Name: WmiPrvSE , Id 24564.
Information	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13352) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 20768) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE' (pid 11168) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 11476) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 5984) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/20/2018 3:36:11 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4888) cannot be restarted - Application SID does not match Conductor SID..
Information	7/20/2018 3:35:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎19T22:05:57.168214700Z.
Information	7/20/2018 3:35:56 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 11360.
Information	7/20/2018 3:32:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 3:32:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:36Z. Reason: GVLK.
Information	7/20/2018 3:27:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 3:27:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 3:27:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 3:27:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 2:21:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2018 2:21:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:45Z. Reason: GVLK.
Information	7/20/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/20/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21095)(?)])(1 )(2 )]

"
Information	7/20/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21095)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/20/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/20/2018 2:19:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 2:16:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2018 2:16:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2018 2:16:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2018 2:16:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2018 1:03:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9de17964-8b8a-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/20/2018 12:33:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/20/2018 12:24:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 12:24:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/19/2018 10:58:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/19/2018 9:21:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 8:24:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 8:24:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 8:24:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 8:03:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b413cba5-8b60-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/19/2018 7:55:15 PM	MTAService.OnSessionChange	0	None	7:55:15 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/19/2018 7:29:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 6:46:22 PM	MTAService.OnSessionChange	0	None	6:46:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/19/2018 6:43:59 PM	MTAService.OnSessionChange	0	None	6:43:59 PM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 6:00:42 PM	MTAService.OnSessionChange	0	None	6:00:42 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/19/2018 5:52:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 5:13:35 PM	MTAService.OnSessionChange	0	None	5:13:35 PM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 4:57:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 4:52:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/19/2018 4:52:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21662)(?)])(1 )(2 )]

"
Information	7/19/2018 4:52:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21662)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 4:52:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2018 4:52:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 4:52:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/19/2018 4:49:09 PM	MTAService.OnSessionChange	0	None	4:49:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/19/2018 4:24:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 4:24:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 4:23:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/19/2018 3:52:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 3:48:20 PM	MTAService.OnSessionChange	0	None	3:48:20 PM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 3:03:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ca587095-8b36-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/19/2018 2:10:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 2:05:26 PM	MTAService.OnSessionChange	0	None	2:05:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/19/2018 1:54:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 1:54:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 1:06:31 PM	MTAService.OnSessionChange	0	None	1:06:31 PM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 12:53:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8958.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/19/2018 12:48:56 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/19/2018 12:48:35 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/19/2018 12:43:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 12:43:56 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/19/2018 12:43:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 12:24:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 12:23:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/19/2018 12:19:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 11:49:16 AM	MTAService.OnSessionChange	0	None	11:49:16 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/19/2018 11:46:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 11:46:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 11:39:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 11:39:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 11:36:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 11:36:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 11:34:06 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/19/2018 11:33:56 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/19/2018 11:32:03 AM	MTAService.OnSessionChange	0	None	11:32:03 AM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 11:23:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 11:23:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:24Z. Reason: GVLK.
Information	7/19/2018 11:18:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2018 11:18:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 11:18:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 11:18:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2018 10:51:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 10:46:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/19/2018 10:46:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22028)(?)])(1 )(2 )]

"
Information	7/19/2018 10:46:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22028)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 10:46:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2018 10:46:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 10:46:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/19/2018 10:23:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 10:03:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e0817355-8b0c-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/19/2018 9:59:03 AM	MTAService.OnSessionChange	0	None	9:59:03 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/19/2018 9:29:50 AM	MTAService.OnSessionChange	0	None	9:29:50 AM - Session change notice received: SessionLock Session ID: 1
Information	7/19/2018 8:44:02 AM	MTAService.OnSessionChange	0	None	8:44:02 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/19/2018 8:26:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 8:24:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 8:23:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/19/2018 6:49:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/19/2018 5:18:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 5:03:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6da2a34-8ae2-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/19/2018 4:23:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 4:23:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 4:15:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 4:15:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:41Z. Reason: GVLK.
Information	7/19/2018 4:10:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2018 4:10:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 4:10:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 4:10:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2018 4:02:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 4:02:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:09Z. Reason: GVLK.
Information	7/19/2018 3:57:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2018 3:57:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 3:57:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 3:57:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/19/2018 3:55:34 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/19/2018 3:54:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 3:54:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:51Z. Reason: GVLK.
Error	7/19/2018 3:50:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/19/2018 3:49:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2018 3:49:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 3:49:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 3:49:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/19/2018 3:42:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 2:24:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/19/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22535)(?)])(1 )(2 )]

"
Information	7/19/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/19/2018 2:11:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 1:29:17 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/19/2018 1:26:43 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/19/2018 12:23:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 12:23:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2018 12:23:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/19/2018 12:17:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/19/2018 12:03:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d0fb0da-8ab9-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/19/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/18/2018 10:23:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 9:06:43 PM	MTAService.OnSessionChange	0	None	9:06:43 PM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 9:06:37 PM	MTAService.OnSessionChange	0	None	9:06:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 8:56:30 PM	MTAService.OnSessionChange	0	None	8:56:30 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/18/2018 8:52:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 8:23:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 8:23:47 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/18/2018 8:23:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 8:23:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 7:06:14 PM	MTAService.OnSessionChange	0	None	7:06:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 7:03:41 PM	MTAService.OnSessionChange	0	None	7:03:41 PM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 7:03:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2350c78d-8a8f-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/18/2018 7:01:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 5:56:37 PM	MTAService.OnSessionChange	0	None	5:56:37 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/18/2018 5:23:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 4:23:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 4:23:22 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/18/2018 4:23:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 3:49:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 3:49:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:28Z. Reason: GVLK.
Information	7/18/2018 3:44:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 3:44:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 3:44:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 3:44:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 3:35:39 PM	MTAService.OnSessionChange	0	None	3:35:39 PM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 3:34:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 3:34:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:44Z. Reason: GVLK.
Warning	7/18/2018 3:32:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 3:29:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 3:29:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 3:29:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 3:29:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/18/2018 3:25:27 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/18/2018 3:20:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 3:20:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:21Z. Reason: GVLK.
Error	7/18/2018 3:13:25 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/18/2018 3:12:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 3:12:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 3:12:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 3:12:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 2:49:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 2:48:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 2:25:32 PM	MTAService.OnSessionChange	0	None	2:25:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 2:12:03 PM	MTAService.OnSessionChange	0	None	2:12:03 PM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 2:03:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 398abb20-8a65-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/18/2018 2:01:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 1:50:49 PM	MTAService.OnSessionChange	0	None	1:50:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 1:28:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 1:28:17 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/18/2018 1:28:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/18/2018 1:28:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 1:27:45 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/18/2018 1:27:43 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 25108, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/18/2018 1:26:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 1:26:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 1:24:46 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/18/2018 1:24:39 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/18/2018 1:15:07 PM	MTAService.OnSessionChange	0	None	1:15:07 PM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 1:08:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 1:07:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 1:04:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 1:04:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 12:53:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8957.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/18/2018 12:39:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 12:38:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 12:28:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/18/2018 12:28:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 12:27:22 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 12:26:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 12:23:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2018 12:23:35 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/18/2018 12:23:27 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/18/2018 12:23:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/18/2018 12:23:25 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 250

Information	7/18/2018 12:23:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2018 12:23:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/18/2018 12:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/18/2018 12:22:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23372)(?)])(1 )(2 )]

"
Information	7/18/2018 12:22:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23372)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 12:22:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/18/2018 12:22:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 12:22:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 11:55:52 AM	MTAService.OnSessionChange	0	None	11:55:52 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 11:34:23 AM	MTAService.OnSessionChange	0	None	11:34:23 AM - Session change notice received: SessionLock Session ID: 1
Warning	7/18/2018 10:34:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 10:07:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 10:07:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 9:56:34 AM	MTAService.OnSessionChange	0	None	9:56:34 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/18/2018 9:34:28 AM	MTAService.OnSessionChange	0	None	9:34:28 AM - Session change notice received: SessionLock Session ID: 1
Information	7/18/2018 9:03:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4fdb5819-8a3b-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/18/2018 9:01:33 AM	MTAService.OnSessionChange	0	None	9:01:33 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/18/2018 8:39:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/18/2018 7:07:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 6:07:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 6:06:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/18/2018 5:21:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 4:48:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 4:48:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:02Z. Reason: GVLK.
Information	7/18/2018 4:43:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 4:43:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 4:43:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 4:43:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/18/2018 4:40:50 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/18/2018 4:38:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 4:38:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:03Z. Reason: GVLK.
Error	7/18/2018 4:33:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/18/2018 4:33:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 4:33:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 4:33:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 4:33:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 4:03:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 66173d23-8a11-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/18/2018 3:47:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 3:40:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 3:40:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:21Z. Reason: GVLK.
Information	7/18/2018 3:35:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 3:35:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 3:35:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 3:35:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 2:24:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/18/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23975)(?)])(1 )(2 )]

"
Information	7/18/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/18/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/18/2018 2:13:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 2:07:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2018 2:06:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/18/2018 12:33:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/18/2018 12:09:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2018 12:09:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:08Z. Reason: GVLK.
Information	7/18/2018 12:04:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2018 12:04:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2018 12:04:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2018 12:04:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/17/2018 11:03:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c107c8e-89e7-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/17/2018 10:34:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 10:07:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 10:06:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/17/2018 8:52:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 7:51:54 PM	MTAService.OnSessionChange	0	None	7:51:54 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/17/2018 6:54:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 6:15:08 PM	MTAService.OnSessionChange	0	None	6:15:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/17/2018 6:06:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 6:06:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 6:03:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 924b05c9-89bd-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/17/2018 5:21:51 PM	MTAService.OnSessionChange	0	None	5:21:51 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/17/2018 5:03:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/17/2018 3:22:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 2:14:32 PM	MTAService.OnSessionChange	0	None	2:14:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/17/2018 2:06:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 2:06:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/17/2018 1:51:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 1:34:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 1:34:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 1:28:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 1:27:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 1:07:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 1:06:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 1:04:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 1:03:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 1:03:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a893be56-8993-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/17/2018 12:50:09 PM	MTAService.OnSessionChange	0	None	12:50:09 PM - Session change notice received: SessionLock Session ID: 1
Information	7/17/2018 12:25:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 12:24:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 12:23:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 12:22:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 12:15:57 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/17/2018 12:15:46 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/17/2018 12:15:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	7/17/2018 12:09:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 12:09:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8956.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/17/2018 11:47:49 AM	MTAService.OnSessionChange	0	None	11:47:49 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/17/2018 11:34:20 AM	MTAService.OnSessionChange	0	None	11:34:20 AM - Session change notice received: SessionLock Session ID: 1
Information	7/17/2018 11:29:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 11:29:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2018 11:29:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2018 11:01:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 11:01:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:18Z. Reason: GVLK.
Information	7/17/2018 10:56:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2018 10:56:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 10:56:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 10:56:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/17/2018 10:35:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 10:06:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 10:06:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 9:58:41 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/17/2018 9:58:41 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/17/2018 9:48:25 AM	MTAService.OnSessionChange	0	None	9:48:25 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/17/2018 9:20:42 AM	MTAService.OnSessionChange	0	None	9:20:42 AM - Session change notice received: SessionLock Session ID: 1
Information	7/17/2018 9:13:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/17/2018 9:12:58 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/17/2018 9:12:45 AM	MTAService.OnSessionChange	0	None	9:12:45 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/17/2018 8:45:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 8:03:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bebd8e2b-8969-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/17/2018 7:56:37 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	7/17/2018 7:56:33 AM	GE Software	0	(1)	++No Reboot requested by Intel_WiFi_PROSet_Win7_20.50.0_x64_V01
Information	7/17/2018 7:56:31 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	7/17/2018 7:56:31 AM	GE Software	0	(1)	Updating Pactrack registry keys with intel_wifi_proset_win7_20.50.0_x64_v01
Information	7/17/2018 7:56:31 AM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	7/17/2018 7:56:31 AM	GE Software	0	(1)	++Installation complete with an exit code of: 512
Information	7/17/2018 7:56:17 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	7/17/2018 7:56:17 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/17/2018 7:56:16 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/17/2018 7:56:16 AM	GE Software	0	(1)	++ Uninstall_Silent variable : C:\Windows\Options\Packages\Intel_WiFi_PROSet_Win7_20.50.0_x64_V01\uninstall.bat
Information	7/17/2018 7:56:12 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Intel_WiFi_PROSet_Win7_20.50.0_x64_V01\intel_wifi_proset_win7_20.50.0_x64_v01.exe with the following commandline: /Q /NOCHECK
Information	7/17/2018 7:56:10 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Intel_WiFi_PROSet_Win7_20.50.0_x64_V01
Information	7/17/2018 7:56:10 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ Intel_WiFi_PROSet_Win7_20.50.0_x64_V01 was launched using the following Command line: /Q
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ Uninstall_Silent variable : C:\PROGRA~2\Tanium\TANIUM~1\DOWNLO~1\ACTION~3\uninstall.bat
Information	7/17/2018 7:56:09 AM	GE Software	0	(1)	++ The installation of intel_wifi_proset_win7_20.50.0_x64_v01.exe was launched with the following Command Line Switches: /Q
Warning	7/17/2018 7:07:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 6:48:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 6:48:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:20Z. Reason: GVLK.
Information	7/17/2018 6:43:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2018 6:43:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 6:43:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 6:43:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2018 6:06:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 6:06:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 6:06:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/17/2018 5:09:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 3:30:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 3:30:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:22Z. Reason: GVLK.
Information	7/17/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 3:25:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/17/2018 3:23:43 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/17/2018 3:20:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 3:20:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:28Z. Reason: GVLK.
Warning	7/17/2018 3:15:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	7/17/2018 3:15:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/17/2018 3:15:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2018 3:15:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 3:15:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 3:15:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2018 3:03:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d51afe11-893f-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/17/2018 2:42:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 2:42:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:22Z. Reason: GVLK.
Information	7/17/2018 2:37:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2018 2:37:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 2:37:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 2:37:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/17/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/17/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25415)(?)])(1 )(2 )]

"
Information	7/17/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25415)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/17/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/17/2018 2:06:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2018 2:06:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/17/2018 1:22:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/17/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/16/2018 11:52:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/16/2018 10:12:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 10:06:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 10:06:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 10:03:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb531cd8-8915-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/16/2018 8:24:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 7:47:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 7:47:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:20Z. Reason: GVLK.
Information	7/16/2018 7:42:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 7:42:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 7:42:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 7:42:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/16/2018 6:52:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 6:35:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 6:35:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:26Z. Reason: GVLK.
Information	7/16/2018 6:30:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 6:30:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 6:30:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 6:30:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/16/2018 6:06:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 6:06:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/16/2018 5:19:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 5:03:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 01a3015a-88ec-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/16/2018 3:27:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 2:06:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 2:05:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	7/16/2018 1:43:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 12:29:59 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/16/2018 12:24:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8955.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/16/2018 12:03:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17de0664-88c2-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/16/2018 11:54:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 10:59:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 10:59:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-23T05:23:01Z. Reason: GVLK.
Information	7/16/2018 10:54:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 10:54:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 10:54:01 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/07/16 05:23"
Information	7/16/2018 10:54:00 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/16 05:23, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/16/2018 10:48:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 10:48:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 10:48:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 10:48:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/16/2018 10:11:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 10:06:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 10:05:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/16/2018 8:25:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 7:03:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e213752-8898-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/16/2018 6:38:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 6:06:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 6:05:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/16/2018 4:40:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 3:56:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 3:56:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:56Z. Reason: GVLK.
Information	7/16/2018 3:51:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 3:51:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 3:51:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 3:51:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/16/2018 3:49:09 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/16/2018 3:46:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 3:46:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:00Z. Reason: GVLK.
Error	7/16/2018 3:41:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/16/2018 3:41:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 3:41:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 3:41:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 3:41:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/16/2018 2:48:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 2:24:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/16/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26855)(?)])(1 )(2 )]

"
Information	7/16/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26855)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/16/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/16/2018 2:06:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 2:05:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 2:05:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/16/2018 2:03:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 444afd62-886e-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/16/2018 1:24:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/16/2018 1:24:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:29Z. Reason: GVLK.
Information	7/16/2018 1:19:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/16/2018 1:19:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/16/2018 1:19:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/16/2018 1:19:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/16/2018 1:05:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/16/2018 12:13:58 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/15/2018 11:13:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 10:06:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 10:05:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 10:05:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/15/2018 10:05:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 9:58:29 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	7/15/2018 9:39:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 9:03:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5aa2b7ce-8844-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/15/2018 7:49:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 7:28:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 7:28:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:39Z. Reason: GVLK.
Information	7/15/2018 7:23:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 7:23:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 7:23:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 7:23:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/15/2018 6:05:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 6:05:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 6:05:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/15/2018 6:04:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/15/2018 4:29:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 4:02:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 70de9e10-881a-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/15/2018 2:48:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 2:05:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 2:05:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/15/2018 2:05:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 12:52:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8954.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	7/15/2018 12:51:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 11:02:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86f72618-87f0-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/15/2018 10:51:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 10:31:55 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/15/2018 10:31:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/15/2018 10:31:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/15/2018 10:31:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/15/2018 10:31:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/15/2018 10:31:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 23, Compared: 25028, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/15/2018 10:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/15/2018 10:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/15/2018 10:05:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 10:05:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/15/2018 9:00:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/15/2018 7:20:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 6:05:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 6:05:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 6:02:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d15f1e1-87c6-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/15/2018 5:40:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 5:15:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 5:15:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:34Z. Reason: GVLK.
Information	7/15/2018 5:10:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 5:10:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 5:10:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 5:10:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/15/2018 4:45:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 4:45:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:53Z. Reason: GVLK.
Information	7/15/2018 4:40:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 4:40:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 4:40:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 4:40:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/15/2018 3:54:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 3:44:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 3:44:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:46Z. Reason: GVLK.
Information	7/15/2018 3:39:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 3:39:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 3:39:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 3:39:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/15/2018 3:37:58 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/15/2018 3:34:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 3:34:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:42Z. Reason: GVLK.
Error	7/15/2018 3:29:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/15/2018 3:29:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 3:29:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 3:29:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 3:29:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/15/2018 3:13:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 3:13:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:09Z. Reason: GVLK.
Information	7/15/2018 3:08:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/15/2018 3:08:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 3:08:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 3:08:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/15/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/15/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/15/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28295)(?)])(1 )(2 )]

"
Information	7/15/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28295)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/15/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/15/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/15/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/15/2018 2:05:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/15/2018 2:05:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/15/2018 2:03:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 1:02:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3625b21-879c-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/15/2018 12:18:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/15/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/14/2018 10:22:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 10:05:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/14/2018 8:38:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 8:02:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c9b5fa75-8772-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/14/2018 6:56:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 6:34:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/14/2018 6:05:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2018 6:05:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2018 5:31:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2018 5:31:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:15Z. Reason: GVLK.
Information	7/14/2018 5:26:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2018 5:26:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2018 5:26:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2018 5:26:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/14/2018 5:12:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 4:09:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2018 4:09:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:00Z. Reason: GVLK.
Information	7/14/2018 4:04:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2018 4:04:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2018 4:04:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2018 4:04:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/14/2018 3:18:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 3:02:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e005e798-8748-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/14/2018 2:05:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/14/2018 1:45:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 12:44:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8953.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	7/14/2018 12:11:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/14/2018 10:32:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 10:04:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2018 10:04:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2018 10:02:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f63cebe9-871e-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/14/2018 8:43:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/14/2018 6:48:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 6:04:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/14/2018 5:16:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 5:02:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c51f16a-86f5-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/14/2018 3:44:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 3:35:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2018 3:35:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:18Z. Reason: GVLK.
Information	7/14/2018 3:30:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2018 3:30:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2018 3:30:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2018 3:30:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/14/2018 3:28:30 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/14/2018 3:25:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2018 3:25:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:24Z. Reason: GVLK.
Error	7/14/2018 3:20:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/14/2018 3:20:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2018 3:20:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2018 3:20:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2018 3:20:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/14/2018 2:24:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29735)(?)])(1 )(2 )]

"
Information	7/14/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29735)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/14/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/14/2018 2:04:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/14/2018 2:03:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/14/2018 12:25:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/14/2018 12:02:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2292486f-86cb-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/13/2018 11:15:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 11:15:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:15Z. Reason: GVLK.
Information	7/13/2018 11:10:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 11:10:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 11:10:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 11:10:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/13/2018 10:49:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 10:04:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2018 10:04:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/13/2018 9:03:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/13/2018 7:13:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 7:02:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38bab165-86a1-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/13/2018 6:04:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/13/2018 5:24:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 4:24:07 PM	MTAService.OnSessionChange	0	None	4:24:07 PM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 4:24:04 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	7/13/2018 4:18:07 PM	MTAService.OnSessionChange	0	None	4:18:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 4:15:41 PM	MTAService.OnSessionChange	0	None	4:15:41 PM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 3:52:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 3:52:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/13/2018 3:32:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 2:41:46 PM	MTAService.OnSessionChange	0	None	2:41:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 2:29:04 PM	MTAService.OnSessionChange	0	None	2:29:04 PM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 2:05:27 PM	MTAService.OnSessionChange	0	None	2:05:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 2:04:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2018 2:02:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4f4d4141-8677-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/13/2018 2:01:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 1:09:06 PM	MTAService.OnSessionChange	0	None	1:09:06 PM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 1:08:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 1:03:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/13/2018 1:03:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30531)(?)])(1 )(2 )]

"
Information	7/13/2018 1:03:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30531)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 1:03:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/13/2018 1:03:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 1:03:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/13/2018 12:52:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8952.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/13/2018 12:39:36 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/13/2018 12:37:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 12:36:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/13/2018 12:34:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 12:33:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/13/2018 12:29:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 12:28:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 12:28:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:28Z. Reason: GVLK.
Information	7/13/2018 12:23:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 12:23:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 12:23:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 12:23:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2018 12:19:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 12:18:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/13/2018 12:11:53 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/13/2018 12:09:01 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/13/2018 12:04:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 12:03:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/13/2018 11:50:30 AM	MTAService.OnSessionChange	0	None	11:50:30 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 11:33:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2018 11:33:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/13/2018 11:09:38 AM	MTAService.OnSessionChange	0	None	11:09:38 AM - Session change notice received: SessionLock Session ID: 1
Warning	7/13/2018 10:42:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 10:20:09 AM	MTAService.OnSessionChange	0	None	10:20:09 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 10:04:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2018 10:03:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2018 9:54:37 AM	MTAService.OnSessionChange	0	None	9:54:37 AM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 9:50:20 AM	MTAService.OnSessionChange	0	None	9:50:20 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 9:24:25 AM	MTAService.OnSessionChange	0	None	9:24:25 AM - Session change notice received: SessionLock Session ID: 1
Information	7/13/2018 9:07:40 AM	MTAService.OnSessionChange	0	None	9:07:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/13/2018 9:02:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6571c1cf-864d-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/13/2018 9:02:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/13/2018 7:06:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 6:14:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 6:14:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:43Z. Reason: GVLK.
Information	7/13/2018 6:09:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 6:09:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 6:09:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 6:09:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2018 6:03:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/13/2018 5:35:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 5:08:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 5:08:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:41Z. Reason: GVLK.
Information	7/13/2018 5:03:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 5:03:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 5:03:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 5:03:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/13/2018 5:01:45 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/13/2018 4:57:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 4:57:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:34Z. Reason: GVLK.
Error	7/13/2018 4:52:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/13/2018 4:52:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 4:52:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 4:52:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 4:52:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2018 4:02:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7bb8bba1-8623-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/13/2018 3:48:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 3:11:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 3:11:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:43Z. Reason: GVLK.
Information	7/13/2018 3:06:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2018 3:06:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 3:06:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 3:06:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/13/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/13/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31175)(?)])(1 )(2 )]

"
Information	7/13/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31175)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/13/2018 2:19:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/13/2018 2:06:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 2:03:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2018 2:03:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/13/2018 12:22:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/12/2018 11:02:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9205c169-85f9-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/12/2018 10:31:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 10:03:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 10:03:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/12/2018 10:03:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/12/2018 8:53:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/12/2018 7:17:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 7:01:35 PM	MTAService.OnSessionChange	0	None	7:01:35 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 6:52:45 PM	MTAService.OnSessionChange	0	None	6:52:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 6:14:57 PM	MTAService.OnSessionChange	0	None	6:14:57 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 6:14:03 PM	MTAService.OnSessionChange	0	None	6:14:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 6:10:07 PM	MTAService.OnSessionChange	0	None	6:10:07 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 6:09:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 6:04:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31671)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 6:04:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31671)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 6:04:12 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/12/2018 6:04:12 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/12/2018 6:04:11 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	7/12/2018 6:03:32 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Information	7/12/2018 6:03:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 6:03:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/12/2018 6:03:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31672)(?)])(1 )(2 )]

"
Information	7/12/2018 6:03:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31672)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 6:03:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/12/2018 6:03:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 6:03:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/12/2018 6:02:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a83656a8-85cf-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/12/2018 5:54:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 5:54:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:18Z. Reason: GVLK.
Information	7/12/2018 5:49:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2018 5:49:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 5:49:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 5:49:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/12/2018 5:40:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 5:37:50 PM	MTAService.OnSessionChange	0	None	5:37:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/12/2018 4:00:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 3:42:56 PM	MTAService.OnSessionChange	0	None	3:42:56 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 3:38:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 3:33:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 63

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 63

Information	7/12/2018 3:33:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 3:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/12/2018 3:33:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31822)(?)])(1 )(2 )]

"
Information	7/12/2018 3:33:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31822)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 3:33:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/12/2018 3:33:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 3:33:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/12/2018 3:32:19 PM	MTAService.OnSessionChange	0	None	3:32:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 3:16:10 PM	MTAService.OnSessionChange	0	None	3:16:10 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 3:09:59 PM	MTAService.OnSessionChange	0	None	3:09:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 2:53:19 PM	MTAService.OnSessionChange	0	None	2:53:19 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 2:14:57 PM	MTAService.OnSessionChange	0	None	2:14:57 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/12/2018 2:01:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 1:05:34 PM	MTAService.OnSessionChange	0	None	1:05:34 PM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 1:02:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: be7320d6-85a5-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/12/2018 12:54:36 PM	MTAService.OnSessionChange	0	None	12:54:36 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/12/2018 12:28:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 12:20:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8951.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/12/2018 12:08:46 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/12/2018 12:08:45 PM	ESENT	102	General	Windows (7132) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/12/2018 11:58:01 AM	MTAService.OnSessionChange	0	None	11:58:01 AM - Session change notice received: SessionLock Session ID: 1
Error	7/12/2018 11:57:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/12/2018 11:57:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15852.
Information	7/12/2018 11:57:18 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20055. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	7/12/2018 11:57:18 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	7/12/2018 11:57:18 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20055. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20055). Installation success or error status: 0.
Information	7/12/2018 11:57:18 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20055)' installed successfully.
Information	7/12/2018 11:57:16 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/12/2018 11:56:49 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/12/2018 11:56:49 AM	ESENT	103	General	Windows (8844) Windows: The database engine stopped the instance (0).
Information	7/12/2018 11:56:41 AM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE\MCSHIELD.EXE was blocked by rule Common Standard Protection:Prevent termination of McAfee processes.
Information	7/12/2018 11:56:40 AM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\WINDOWS\SYSTEM32\MFEVTPS.EXE was blocked by rule Common Standard Protection:Prevent termination of McAfee processes.
Information	7/12/2018 11:56:40 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15852.
Information	7/12/2018 11:56:19 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15852.
Information	7/12/2018 11:56:19 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20055. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	7/12/2018 11:56:19 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	7/12/2018 11:56:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15852.
Information	7/12/2018 11:44:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824272646_3849898931176308257222535870693957989.msi. Client Process Id: 9508.
Information	7/12/2018 11:44:11 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	7/12/2018 11:44:11 AM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	7/12/2018 11:44:11 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/12/2018 11:43:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824272646_3849898931176308257222535870693957989.msi. Client Process Id: 9508.
Information	7/12/2018 11:43:18 AM	MTAService.OnSessionChange	0	None	11:43:18 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 11:29:46 AM	MTAService.OnSessionChange	0	None	11:29:46 AM - Session change notice received: SessionLock Session ID: 1
Information	7/12/2018 11:16:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/12/2018 11:16:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/12/2018 11:15:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/12/2018 11:15:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/12/2018 10:46:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 10:46:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 10:46:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/12/2018 10:46:13 AM	MTAService.OnSessionChange	0	None	10:46:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/12/2018 10:45:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/12/2018 10:38:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 10:32:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/12/2018 10:32:45 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/12/2018 10:32:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/12/2018 10:32:20 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/12/2018 10:32:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/12/2018 10:32:02 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 24895, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/12/2018 10:30:25 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/12/2018 10:30:25 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/12/2018 10:04:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	7/12/2018 9:07:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 8:02:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d49a92f8-857b-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/12/2018 7:24:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 6:47:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 6:47:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:20Z. Reason: GVLK.
Information	7/12/2018 6:46:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 6:45:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 6:42:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2018 6:42:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 6:42:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 6:42:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/12/2018 5:31:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/12/2018 3:55:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 3:28:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 3:28:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:58Z. Reason: GVLK.
Information	7/12/2018 3:23:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2018 3:23:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 3:23:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 3:23:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/12/2018 3:22:03 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/12/2018 3:17:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 3:17:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:54Z. Reason: GVLK.
Error	7/12/2018 3:13:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/12/2018 3:12:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2018 3:12:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 3:12:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 3:12:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/12/2018 3:02:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eadce996-8551-11e8-b937-8dd7520ee28e
Report Status: 0"
Information	7/12/2018 2:51:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 2:51:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:19Z. Reason: GVLK.
Information	7/12/2018 2:46:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 2:46:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2018 2:46:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 2:46:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 2:46:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/12/2018 2:45:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/12/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/12/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32615)(?)])(1 )(2 )]

"
Information	7/12/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32615)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/12/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/12/2018 2:08:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 2:07:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/12/2018 2:05:23 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	7/12/2018 12:31:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/12/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/11/2018 10:46:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 10:46:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 10:45:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/11/2018 10:34:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 10:02:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0122e6d1-8528-11e8-b937-8dd7520ee28e
Report Status: 0"
Warning	7/11/2018 8:50:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/11/2018 7:16:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 7:00:16 PM	MTAService.OnSessionChange	0	None	7:00:16 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 6:46:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 6:45:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 6:45:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 6:21:19 PM	MTAService.OnSessionChange	0	None	6:21:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 6:18:28 PM	MTAService.OnSessionChange	0	None	6:18:28 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 5:30:56 PM	MTAService.OnSessionChange	0	None	5:30:56 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/11/2018 5:28:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 5:02:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1749502f-84fe-11e8-b937-204747d02364
Report Status: 0"
Information	7/11/2018 4:56:25 PM	MTAService.OnSessionChange	0	None	4:56:25 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 4:52:25 PM	MTAService.OnSessionChange	0	None	4:52:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 4:41:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 4:41:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:08Z. Reason: GVLK.
Information	7/11/2018 4:36:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2018 4:36:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 4:36:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 4:36:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/11/2018 4:32:57 PM	MTAService.OnSessionChange	0	None	4:32:57 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/11/2018 3:56:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 3:40:24 PM	MTAService.OnSessionChange	0	None	3:40:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 3:35:58 PM	MTAService.OnSessionChange	0	None	3:35:58 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 3:02:08 PM	MTAService.OnSessionChange	0	None	3:02:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 2:47:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 2:46:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 2:45:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 2:45:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/11/2018 2:44:20 PM	MTAService.OnSessionChange	0	None	2:44:20 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 2:42:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/11/2018 2:42:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33313)(?)])(1 )(2 )]

"
Information	7/11/2018 2:42:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33313)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 2:42:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2018 2:42:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 2:42:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/11/2018 2:14:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 2:14:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/11/2018 2:04:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 2:03:54 PM	MTAService.OnSessionChange	0	None	2:03:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 1:59:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:59:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:53:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:53:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:29:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:29:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:24:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:24:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:22:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:21:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:15:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 1:15:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 1:11:48 PM	MTAService.OnSessionChange	0	None	1:11:48 PM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 1:00:29 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 12:59:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 12:45:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 12:44:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 12:43:31 PM	MTAService.OnSessionChange	0	None	12:43:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 12:29:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 12:29:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 12:28:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8950.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/11/2018 12:15:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 12:14:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 12:12:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 12:11:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/11/2018 12:09:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 12:02:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2d81727f-84d4-11e8-b937-204747d02364
Report Status: 0"
Information	7/11/2018 11:59:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 11:59:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 11:57:11 AM	MTAService.OnSessionChange	0	None	11:57:11 AM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 11:47:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 11:47:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 11:45:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 11:44:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 11:44:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2018 11:44:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2018 11:12:17 AM	MTAService.OnSessionChange	0	None	11:12:17 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/11/2018 10:57:41 AM	MTAService.OnSessionChange	0	None	10:57:41 AM - Session change notice received: SessionLock Session ID: 1
Information	7/11/2018 10:45:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 10:45:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/11/2018 10:37:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 10:29:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎11T04:59:53.542520300Z.
Information	7/11/2018 10:29:57 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎11T04:59:51.891355200Z.
Information	7/11/2018 10:29:57 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{0117821A-6540-41D5-81F9-302DA5CF3E29}v4.8.7152.0\CsDeviceControl.msi. Client Process Id: 15684.
Information	7/11/2018 10:29:57 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Device Control. Product Version: 4.8.7152.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/11/2018 10:29:57 AM	MsiInstaller	11707	None	Product: CrowdStrike Device Control -- Installation completed successfully.
Information	7/11/2018 10:29:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎11T04:59:53.542520300Z.
Information	7/11/2018 10:29:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎11T04:59:51.891355200Z.
Information	7/11/2018 10:29:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎11T04:59:36.651831400Z.
Information	7/11/2018 10:29:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎11T04:59:38.500016200Z.
Information	7/11/2018 10:29:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎11T04:59:35.171683400Z.
Information	7/11/2018 10:29:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{0117821A-6540-41D5-81F9-302DA5CF3E29}v4.8.7152.0\CsDeviceControl.msi. Client Process Id: 15684.
Information	7/11/2018 10:29:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{412FB444-DDFA-4AB1-8B37-6ED21C84FAB7}v4.9.7202.0\CsAgent.msi. Client Process Id: 15684.
Information	7/11/2018 10:29:51 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.9.7202.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/11/2018 10:29:51 AM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	7/11/2018 10:29:39 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\System32\taskeng.exe' (pid 6508) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\System32\wbem\WmiPrvSE.exe' (pid 14500) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\wbem\WmiPrvSE.exe' (pid 10352) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15932) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\PostgreSQL\9.5\bin\postgres.exe' (pid 7720) cannot be restarted - Application SID does not match Conductor SID..
Warning	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	7/11/2018 10:29:38 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎11T04:59:38.500016200Z.
Information	7/11/2018 10:29:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎11T04:59:36.651831400Z.
Information	7/11/2018 10:29:35 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎11T04:59:35.171683400Z.
Information	7/11/2018 10:29:34 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{412FB444-DDFA-4AB1-8B37-6ED21C84FAB7}v4.9.7202.0\CsAgent.msi. Client Process Id: 15684.
Information	7/11/2018 9:59:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/11/2018 9:59:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/11/2018 9:59:35 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/11/2018 9:56:07 AM	MTAService.OnSessionChange	0	None	9:56:07 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/11/2018 8:58:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/11/2018 7:14:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 7:02:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43d154d7-84aa-11e8-b937-204747d02364
Report Status: 0"
Information	7/11/2018 6:45:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 6:45:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/11/2018 5:35:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 5:18:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 5:18:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:45Z. Reason: GVLK.
Information	7/11/2018 5:13:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2018 5:13:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 5:13:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 5:13:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/11/2018 5:02:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 5:02:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:37Z. Reason: GVLK.
Information	7/11/2018 4:57:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2018 4:57:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 4:57:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 4:57:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/11/2018 4:55:54 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/11/2018 4:51:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 4:51:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:18Z. Reason: GVLK.
Error	7/11/2018 4:46:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/11/2018 4:46:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2018 4:46:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 4:46:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 4:46:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/11/2018 3:47:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 2:45:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 2:45:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2018 2:41:57 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/11/2018 2:39:48 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/11/2018 2:24:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/11/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34055)(?)])(1 )(2 )]

"
Information	7/11/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34055)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2018 2:19:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/11/2018 2:15:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 2:02:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a0ad842-8480-11e8-b937-204747d02364
Report Status: 0"
Warning	7/11/2018 12:38:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/11/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/10/2018 11:00:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 10:45:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 10:45:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/10/2018 9:02:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 9:02:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 709fc430-8456-11e8-b937-204747d02364
Report Status: 0"
Warning	7/10/2018 7:29:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 6:59:30 PM	MTAService.OnSessionChange	0	None	6:59:30 PM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 6:45:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 6:45:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 6:35:07 PM	MTAService.OnSessionChange	0	None	6:35:07 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/10/2018 5:57:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 5:43:37 PM	MTAService.OnSessionChange	0	None	5:43:37 PM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 4:30:15 PM	MTAService.OnSessionChange	0	None	4:30:15 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/10/2018 4:18:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 4:02:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86eefdd4-842c-11e8-b937-204747d02364
Report Status: 0"
Information	7/10/2018 3:49:36 PM	MTAService.OnSessionChange	0	None	3:49:36 PM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 3:08:51 PM	MTAService.OnSessionChange	0	None	3:08:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/10/2018 2:45:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 2:44:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/10/2018 2:29:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 2:21:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 2:21:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 1:17:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 1:16:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 1:02:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 1:02:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:03Z. Reason: GVLK.
Information	7/10/2018 12:57:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 12:57:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 12:57:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 12:57:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 12:57:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 12:57:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/10/2018 12:51:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8949.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/10/2018 12:42:02 PM	MTAService.OnSessionChange	0	None	12:42:02 PM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 12:40:11 PM	MTAService.OnSessionChange	0	None	12:40:11 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/10/2018 12:39:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 12:38:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 12:38:44 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 12:36:49 PM	MTAService.OnSessionChange	0	None	12:36:49 PM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 12:12:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 12:12:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 12:08:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 12:08:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 12:04:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 12:04:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:46:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:45:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:43:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:41:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:38:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:38:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:36:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:36:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:32:09 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:32:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:29:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:29:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:14:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/10/2018 11:14:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2018 11:02:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d2701dd-8402-11e8-b937-204747d02364
Report Status: 0"
Information	7/10/2018 10:59:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/10/2018 10:58:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/10/2018 10:58:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/10/2018 10:55:36 AM	MTAService.OnSessionChange	0	None	10:55:36 AM - Session change notice received: SessionUnlock Session ID: 1
Error	7/10/2018 10:48:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	7/10/2018 10:47:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 10:45:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 10:44:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 10:29:20 AM	MTAService.OnSessionChange	0	None	10:29:20 AM - Session change notice received: SessionLock Session ID: 1
Information	7/10/2018 10:29:13 AM	MTAService.OnSessionChange	0	None	10:29:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/10/2018 10:16:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 10:16:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:54Z. Reason: GVLK.
Information	7/10/2018 10:11:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 10:11:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 10:11:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 10:11:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/10/2018 9:12:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/10/2018 7:14:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 6:48:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 6:48:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:41Z. Reason: GVLK.
Information	7/10/2018 6:45:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 6:44:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 6:43:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 6:43:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 6:43:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 6:43:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/10/2018 6:02:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b37a7e9b-83d8-11e8-b937-204747d02364
Report Status: 0"
Warning	7/10/2018 5:28:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 4:46:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 4:46:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:03Z. Reason: GVLK.
Information	7/10/2018 4:41:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 4:41:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 4:41:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 4:41:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/10/2018 4:18:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 4:18:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:20Z. Reason: GVLK.
Information	7/10/2018 4:13:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 4:13:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 4:13:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 4:13:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/10/2018 4:11:38 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/10/2018 4:09:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 4:09:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:01Z. Reason: GVLK.
Error	7/10/2018 4:04:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/10/2018 4:04:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/10/2018 4:04:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 4:04:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 4:04:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/10/2018 3:29:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 2:45:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 2:44:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/10/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/10/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/10/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35495)(?)])(1 )(2 )]

"
Information	7/10/2018 2:19:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35495)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/10/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/10/2018 1:56:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/10/2018 1:02:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c9d515b7-83ae-11e8-b937-204747d02364
Report Status: 0"
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++Installation complete
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++ Current User shortcut created for profile: Default
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++ Current User shortcut created for profile: MSSQL$SQLEXPRESS
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++ Current User shortcut created for profile: DefaultAppPool
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++ Current User shortcut created for profile: Administrator
Information	7/10/2018 12:34:36 AM	GE Software	0	(1)	++ Current User shortcut created for profile: admin
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++ Current User shortcut created for profile: 212558710
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++ Current User shortcut created for profile: 212553210
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++ Moving shortcut from All Users desktop to all current users desktops
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++I-Rev running : I01
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Warning	7/10/2018 12:34:35 AM	GE Software	0	(1)	++ Passed permissions check
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++Started the installation of GE SOLV Web Chat Shortcut 1.0 V01 with the following commandline: /Q
Information	7/10/2018 12:34:35 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/10/2018 12:34:34 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/10/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	7/9/2018 11:59:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 10:44:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/9/2018 10:44:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/9/2018 10:04:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/9/2018 8:15:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 8:02:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e043a3be-8384-11e8-b937-204747d02364
Report Status: 0"
Information	7/9/2018 6:44:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/9/2018 6:44:53 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/9/2018 6:44:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/9/2018 6:41:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 4:53:03 PM	MTAService.OnSessionChange	0	None	4:53:03 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/9/2018 4:51:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 4:47:34 PM	MTAService.OnSessionChange	0	None	4:47:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/9/2018 4:38:37 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/9/2018 4:36:13 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	7/9/2018 4:34:31 PM	GE Software	0	(1)	++Application Already Installed, exiting Installation Code 51638
Information	7/9/2018 4:34:31 PM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Warning	7/9/2018 4:34:31 PM	GE Software	0	(1)	++Installation Check - TAG file exists
Information	7/9/2018 4:34:31 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	7/9/2018 4:34:31 PM	GE Software	0	(1)	++ Crowdstrike_Falcon_4.1.6308_V01 was launched using the following Command line: /Q 
Information	7/9/2018 4:34:31 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/9/2018 4:34:30 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/9/2018 4:34:30 PM	GE Software	0	(1)	++ProgramData path is C:\ProgramData
Information	7/9/2018 4:34:30 PM	GE Software	0	(1)	"++Uninstall path is ""C:\ProgramData\Package Cache\{de328129-d501-4587-b850-156c9e41df31}\WindowsSensor.exe"" /uninstall /quiet"
Information	7/9/2018 4:34:30 PM	GE Software	0	(1)	++ The installation of crowdstrike_falcon_4.1.6308_v01.exe was launched with the following Command Line Switches: /Q 
Information	7/9/2018 4:34:28 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\UPDATE\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 4:27:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/9/2018 3:42:32 PM	MTAService.OnSessionChange	0	None	3:42:32 PM - Session change notice received: SessionLock Session ID: 1
Information	7/9/2018 3:32:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 3:26:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/9/2018 3:26:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36148)(?)])(1 )(2 )]

"
Information	7/9/2018 3:26:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36148)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 3:26:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/9/2018 3:26:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 3:26:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 3:24:39 PM	MTAService.OnSessionChange	0	None	3:24:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/9/2018 3:07:09 PM	MTAService.OnSessionChange	0	None	3:07:09 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/9/2018 3:04:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 3:02:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f695fdb2-835a-11e8-b937-204747d02364
Report Status: 0"
Information	7/9/2018 2:44:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/9/2018 2:21:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 2:20:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/9/2018 2:06:57 PM	MTAService.OnSessionChange	0	None	2:06:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/9/2018 1:30:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T08:00:35.222795300Z.
Information	7/9/2018 1:30:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T08:00:33.817795300Z.
Information	7/9/2018 1:30:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{0AFBA8D3-5BF5-4FBC-BB5C-1CA61C140CF0}v4.8.7151.0\CsDeviceControl.msi. Client Process Id: 13076.
Information	7/9/2018 1:30:37 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Device Control. Product Version: 4.8.7151.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/9/2018 1:30:37 PM	MsiInstaller	11707	None	Product: CrowdStrike Device Control -- Installation completed successfully.
Information	7/9/2018 1:30:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T08:00:35.222795300Z.
Information	7/9/2018 1:30:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T08:00:33.817795300Z.
Information	7/9/2018 1:30:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T07:55:55.198055800Z.
Information	7/9/2018 1:30:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T07:55:56.084144400Z.
Information	7/9/2018 1:30:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T07:55:52.753811400Z.
Information	7/9/2018 1:30:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{0AFBA8D3-5BF5-4FBC-BB5C-1CA61C140CF0}v4.8.7151.0\CsDeviceControl.msi. Client Process Id: 13076.
Information	7/9/2018 1:30:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{3B608969-7881-4F67-8ED5-2AD3230AED04}v4.8.7101.0\CsAgent.msi. Client Process Id: 13076.
Information	7/9/2018 1:30:33 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.8.7101.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/9/2018 1:30:33 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	7/9/2018 1:28:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 1:28:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/9/2018 1:25:56 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	7/9/2018 1:25:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T07:55:56.084144400Z.
Information	7/9/2018 1:25:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T07:55:55.198055800Z.
Information	7/9/2018 1:25:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T07:55:52.753811400Z.
Information	7/9/2018 1:25:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{3B608969-7881-4F67-8ED5-2AD3230AED04}v4.8.7101.0\CsAgent.msi. Client Process Id: 13076.
Warning	7/9/2018 1:25:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 1:15:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 1:14:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/9/2018 1:05:18 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 1:04:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/9/2018 1:02:52 PM	MTAService.OnSessionChange	0	None	1:02:52 PM - Session change notice received: SessionLock Session ID: 1
Information	7/9/2018 1:02:44 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\CURRENT\S_SUPDAT2500\SUPERDAT\0000\SUPERDAT64.LOG was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 1:02:44 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\CURRENT\S_SUPDAT2500\SUPERDAT\0000\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 1:02:43 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\CURRENT\S_SUPDAT2500\SUPERDAT\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 1:02:43 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\CURRENT\S_SUPDAT2500\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 1:02:43 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\CURRENT\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 12:37:59 PM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	7/9/2018 12:37:55 PM	GE Software	0	(1)	++No Reboot requested by Crowdstrike_Falcon_4.1.6308_V01
Information	7/9/2018 12:37:52 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T07:07:48.572190700Z.
Information	7/9/2018 12:37:53 PM	GE Software	0	(1)	Package Tracker MIF file created.
Information	7/9/2018 12:37:53 PM	GE Software	0	(1)	Updating Pactrack registry keys with crowdstrike_falcon_4.1.6308_v01
Information	7/9/2018 12:37:53 PM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	7/9/2018 12:37:53 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	7/9/2018 12:37:52 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{9AC58122-81EE-4E26-810C-206F94A3C68F}v4.0.6292.0\CsDeviceControl.msi. Client Process Id: 13544.
Information	7/9/2018 12:37:52 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Device Control. Product Version: 4.0.6292.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/9/2018 12:37:52 PM	MsiInstaller	11707	None	Product: CrowdStrike Device Control -- Installation completed successfully.
Information	7/9/2018 12:37:48 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T07:07:48.572190700Z.
Information	7/9/2018 12:37:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎07‎-‎09T07:07:40.533386900Z.
Information	7/9/2018 12:37:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{9AC58122-81EE-4E26-810C-206F94A3C68F}v4.0.6292.0\CsDeviceControl.msi. Client Process Id: 13544.
Information	7/9/2018 12:37:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\ProgramData\Package Cache\{7D89319C-A5F9-4506-B868-99203E672FD7}v4.1.6308.0\CsAgent.msi. Client Process Id: 13544.
Information	7/9/2018 12:37:48 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: CrowdStrike Sensor Platform. Product Version: 4.1.6308.0. Product Language: 1033. Manufacturer: CrowdStrike, Inc.. Installation success or error status: 0.
Information	7/9/2018 12:37:48 PM	MsiInstaller	11707	None	Product: CrowdStrike Sensor Platform -- Installation completed successfully.
Information	7/9/2018 12:37:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎07‎-‎09T07:07:40.533386900Z.
Information	7/9/2018 12:37:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\ProgramData\Package Cache\{7D89319C-A5F9-4506-B868-99203E672FD7}v4.1.6308.0\CsAgent.msi. Client Process Id: 13544.
Information	7/9/2018 12:37:38 PM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	7/9/2018 12:37:38 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/9/2018 12:37:37 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/9/2018 12:37:37 PM	GE Software	0	(1)	++ProgramData path is C:\ProgramData
Information	7/9/2018 12:37:37 PM	GE Software	0	(1)	"++Uninstall path is ""C:\ProgramData\Package Cache\{de328129-d501-4587-b850-156c9e41df31}\WindowsSensor.exe"" /uninstall /quiet"
Information	7/9/2018 12:37:35 PM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Crowdstrike_Falcon_4.1.6308_V01\crowdstrike_falcon_4.1.6308_v01.exe with the following commandline: /Q  /NOCHECK
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Crowdstrike_Falcon_4.1.6308_V01
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ Crowdstrike_Falcon_4.1.6308_V01 was launched using the following Command line: /Q 
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ProgramData path is C:\ProgramData
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	"++Uninstall path is ""C:\ProgramData\Package Cache\{de328129-d501-4587-b850-156c9e41df31}\WindowsSensor.exe"" /uninstall /quiet"
Information	7/9/2018 12:37:33 PM	GE Software	0	(1)	++ The installation of crowdstrike_falcon_4.1.6308_v01.exe was launched with the following Command Line Switches: /Q 
Information	7/9/2018 12:37:31 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAMDATA\MCAFEE\COMMON FRAMEWORK\UPDATE\ was blocked by rule Common Standard Protection:Prevent modification of McAfee Common Management Agent files and settings.
Information	7/9/2018 12:33:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 12:33:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:45Z. Reason: GVLK.
Information	7/9/2018 12:28:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/9/2018 12:28:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 12:28:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 12:28:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 12:14:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 12:14:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/9/2018 11:53:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/9/2018 11:53:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/9/2018 11:30:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/9/2018 11:19:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 11:19:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:19:03Z. Reason: GVLK.
Information	7/9/2018 11:14:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/9/2018 11:14:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 11:14:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 11:14:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 10:54:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 10:54:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T05:18:06Z. Reason: GVLK.
Information	7/9/2018 10:50:25 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8948.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/9/2018 10:49:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 10:49:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:49:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:49:05 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/07/09 05:19"
Information	7/9/2018 10:49:04 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/09 05:19, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/9/2018 10:45:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 161, Deleted: 0, Modified: 117, Compared: 24538, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/9/2018 10:44:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/9/2018 10:44:20 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/9/2018 10:44:20 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/9/2018 10:44:20 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/9/2018 10:44:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/9/2018 10:44:15 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 390

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	7/9/2018 10:44:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/9/2018 10:44:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/9/2018 10:44:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:44:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 10:44:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 10:43:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/9/2018 10:43:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/9/2018 10:43:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36431)(?)])(1 )(2 )]

"
Information	7/9/2018 10:43:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36431)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:43:43 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/9/2018 10:43:43 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 10:43:42 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 10:36:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	7/9/2018 10:33:05 AM	MTAService.OnSessionChange	0	None	10:33:05 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/9/2018 10:24:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 10:24:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T04:48:31Z. Reason: GVLK.
Information	7/9/2018 10:19:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/9/2018 10:14:31 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/9/2018 10:14:31 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B4897D56-B073-4931-B2D3-CCB264EAF463}
Error	7/9/2018 10:14:31 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B4897D56-B073-4931-B2D3-CCB264EAF463}
Information	7/9/2018 10:14:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/9/2018 10:14:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36460)(?)])(1 )(2 )]

"
Information	7/9/2018 10:14:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:14:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/9/2018 10:14:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 10:14:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 10:14:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/9/2018 10:14:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:14:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 10:14:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/9/2018 10:12:17 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/9/2018 10:09:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 10:09:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-16T04:33:33Z. Reason: GVLK.
Information	7/9/2018 10:05:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/9/2018 10:04:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 10:04:33 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	7/9/2018 10:04:33 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/09 04:34, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/9/2018 10:01:22 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	7/9/2018 10:00:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/9/2018 10:00:07 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E30887A6-A8D5-4855-8C89-38AD85D37DA9}
Error	7/9/2018 10:00:07 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E30887A6-A8D5-4855-8C89-38AD85D37DA9}
Information	7/9/2018 10:00:04 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/9/2018 10:00:02 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/9/2018 10:00:01 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/9/2018 9:59:50 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/9/2018 9:59:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	7/9/2018 9:59:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/9/2018 9:59:34 AM	ESENT	302	Logging/Recovery	Windows (8844) Windows: The database engine has successfully completed recovery steps.
Information	7/9/2018 9:59:33 AM	ESENT	301	Logging/Recovery	Windows (8844) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/9/2018 9:59:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36475)(?)])(1 )(2 )]

"
Information	7/9/2018 9:59:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36475)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 9:59:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/9/2018 9:59:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/9/2018 9:59:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 9:59:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/9/2018 9:59:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/9/2018 9:59:25 AM	ESENT	301	Logging/Recovery	Windows (8844) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00920.log.
Information	7/9/2018 9:59:25 AM	ESENT	300	Logging/Recovery	Windows (8844) Windows: The database engine is initiating recovery steps.
Information	7/9/2018 9:59:25 AM	ESENT	102	General	Windows (8844) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/9/2018 9:59:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 9:59:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/9/2018 9:59:18 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8946.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/9/2018 9:59:07 AM	MTAService.OnSessionChange	0	None	9:59:07 AM - Session change notice received: SessionLock Session ID: 1
Error	7/9/2018 9:58:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/9/2018 9:58:39 AM	Service1	0	None	Service started successfully.
Information	7/9/2018 9:58:36 AM	MTAService	0	None	Service started successfully.
Error	7/9/2018 9:58:33 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/9/2018 9:58:33 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/9/2018 9:58:15 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/9/2018 9:58:02 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/9/2018 9:58:01 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/9/2018 9:58:01 AM	PostgreSQL	0	None	"2018-07-09 09:58:01 IST LOG:  redirecting log output to logging collector process
2018-07-09 09:58:01 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/9/2018 9:57:59 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/9/2018 9:57:59 AM	MTAService.OnStart	0	None	9:57:59 AM - User is already logged in : 212558710
Information	7/9/2018 9:57:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/9/2018 9:57:56 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/9/2018 9:57:56 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/9/2018 9:57:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/9/2018 9:57:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/9/2018 9:57:55 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/9/2018 9:57:46 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:46 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/9/2018 9:57:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/9/2018 9:57:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/9/2018 9:57:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/9/2018 9:57:45 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/9/2018 9:57:45 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:44 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/9/2018 9:57:43 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/9/2018 9:57:43 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/9/2018 9:57:43 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:40 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/9/2018 9:57:39 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/9/2018 9:57:39 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/9/2018 9:57:39 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3984 at 7/2/2018 9:09:10 AM (local) 7/2/2018 3:39:10 AM (UTC). This is an informational message only; no user action is required.
Information	7/9/2018 9:57:38 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/9/2018 9:57:37 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/9/2018 9:57:37 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/9/2018 9:57:37 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/9/2018 9:57:37 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4032.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/9/2018 9:57:36 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/9/2018 9:57:12 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/9/2018 9:57:08 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/9/2018 9:56:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/9/2018 9:56:56 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/9/2018 9:56:56 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/7/2018 4:02:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8946.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	7/7/2018 3:21:19 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/7/2018 3:21:19 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {71F4F1C9-5D10-4244-AC28-2355DEB55C87}
Error	7/7/2018 3:21:19 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {71F4F1C9-5D10-4244-AC28-2355DEB55C87}
Information	7/7/2018 3:21:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/7/2018 3:21:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39034)(?)])(1 )(2 )]

"
Information	7/7/2018 3:21:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39034)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/7/2018 3:10:38 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/7/2018 3:10:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/7/2018 3:10:27 PM	MTAService.OnSessionChange	0	None	3:10:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/7/2018 3:10:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/6/2018 4:55:07 PM	MTAService.OnSessionChange	0	None	4:55:07 PM - Session change notice received: SessionLock Session ID: 1
Information	7/6/2018 4:12:02 PM	MTAService.OnSessionChange	0	None	4:12:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/6/2018 3:50:57 PM	MTAService.OnSessionChange	0	None	3:50:57 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/6/2018 3:15:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 2:31:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 2:30:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 2:12:06 PM	MTAService.OnSessionChange	0	None	2:12:06 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/6/2018 1:37:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 1:17:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2018 1:17:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:36Z. Reason: GVLK.
Information	7/6/2018 1:16:18 PM	MTAService.OnSessionChange	0	None	1:16:18 PM - Session change notice received: SessionLock Session ID: 1
Information	7/6/2018 1:07:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2018 1:07:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 1:07:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2018 1:07:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2018 12:35:40 PM	MTAService.OnSessionChange	0	None	12:35:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/6/2018 12:27:42 PM	MTAService.OnSessionChange	0	None	12:27:42 PM - Session change notice received: SessionLock Session ID: 1
Information	7/6/2018 12:19:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b2420848-80e8-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/6/2018 12:07:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 12:01:11 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8945.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	7/6/2018 11:34:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/6/2018 11:34:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/6/2018 11:23:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/6/2018 11:23:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/6/2018 11:10:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2018 11:10:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40725)(?)])(1 )(2 )]

"
Information	7/6/2018 11:10:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40725)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 10:31:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 10:30:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 10:21:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2018 10:21:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40773)(?)])(1 )(2 )]

"
Information	7/6/2018 10:21:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40773)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 10:09:39 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/6/2018 10:09:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/6/2018 10:09:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	7/6/2018 10:07:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 10:04:09 AM	MTAService.OnSessionChange	0	None	10:04:09 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/6/2018 8:33:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 7:19:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c85d1158-80be-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/6/2018 6:34:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 6:31:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 6:30:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 5:33:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2018 5:33:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:51Z. Reason: GVLK.
Information	7/6/2018 5:28:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2018 5:28:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 5:28:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2018 5:28:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/6/2018 4:49:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 3:50:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2018 3:50:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:56Z. Reason: GVLK.
Information	7/6/2018 3:45:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2018 3:45:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 3:45:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2018 3:45:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/6/2018 3:43:16 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/6/2018 3:39:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2018 3:39:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:14Z. Reason: GVLK.
Error	7/6/2018 3:34:31 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/6/2018 3:34:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2018 3:34:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 3:34:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2018 3:34:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/6/2018 3:01:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 2:31:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 2:30:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41255)(?)])(1 )(2 )]

"
Information	7/6/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41256)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 2:19:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de5e3b42-8094-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/6/2018 1:16:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/6/2018 12:50:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2018 12:50:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:39Z. Reason: GVLK.
Information	7/6/2018 12:45:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2018 12:45:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2018 12:45:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2018 12:45:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/5/2018 11:55:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/5/2018 11:55:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:16Z. Reason: GVLK.
Information	7/5/2018 11:50:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/5/2018 11:50:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2018 11:50:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2018 11:50:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/5/2018 11:24:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 10:31:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 10:30:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/5/2018 9:39:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 9:19:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f469c60e-806a-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/5/2018 7:42:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 6:31:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 6:30:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 6:19:39 PM	MTAService.OnSessionChange	0	None	6:19:39 PM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 6:09:47 PM	MTAService.OnSessionChange	0	None	6:09:47 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/5/2018 5:55:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 5:28:50 PM	MTAService.OnSessionChange	0	None	5:28:50 PM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 5:04:33 PM	MTAService.OnSessionChange	0	None	5:04:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/5/2018 4:35:44 PM	MTAService.OnSessionChange	0	None	4:35:44 PM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 4:35:09 PM	MTAService.OnSessionChange	0	None	4:35:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/5/2018 4:20:36 PM	MTAService.OnSessionChange	0	None	4:20:36 PM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 4:19:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0a582b89-8041-11e8-86bb-204747d02364
Report Status: 0"
Information	7/5/2018 4:13:53 PM	MTAService.OnSessionChange	0	None	4:13:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/5/2018 4:00:44 PM	MTAService.OnSessionChange	0	None	4:00:44 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/5/2018 3:56:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 2:30:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 2:30:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 2:15:14 PM	MTAService.OnSessionChange	0	None	2:15:14 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	7/5/2018 2:14:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 1:34:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/5/2018 1:34:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/5/2018 1:09:18 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/5/2018 1:08:40 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 13, Compared: 24706, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/5/2018 1:07:13 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/5/2018 1:07:13 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/5/2018 12:59:00 PM	MTAService.OnSessionChange	0	None	12:59:00 PM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 12:55:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8944.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/5/2018 12:49:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/5/2018 12:49:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/5/2018 12:34:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 12:19:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/5/2018 12:18:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/5/2018 12:15:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/5/2018 12:15:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/5/2018 11:36:42 AM	MTAService.OnSessionChange	0	None	11:36:42 AM - Session change notice received: SessionUnlock Session ID: 1
Error	7/5/2018 11:34:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/5/2018 11:32:54 AM	MTAService.OnSessionChange	0	None	11:32:54 AM - Session change notice received: SessionLock Session ID: 1
Information	7/5/2018 11:19:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 20527832-8017-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/5/2018 10:41:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 10:40:07 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/5/2018 10:39:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/5/2018 10:30:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 10:30:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/5/2018 10:30:29 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/5/2018 10:29:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 10:09:16 AM	MTAService.OnSessionChange	0	None	10:09:16 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/5/2018 9:30:25 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/5/2018 9:30:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/5/2018 9:06:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/5/2018 9:06:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:42Z. Reason: GVLK.
Warning	7/5/2018 9:05:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 9:01:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/5/2018 9:01:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2018 9:01:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2018 9:01:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/5/2018 7:20:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 6:29:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 6:19:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 364c2b82-7fed-11e8-86bb-204747d02364
Report Status: 0"
Information	7/5/2018 6:12:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/5/2018 6:12:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:49Z. Reason: GVLK.
Information	7/5/2018 6:07:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/5/2018 6:07:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2018 6:07:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2018 6:07:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/5/2018 5:48:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/5/2018 3:49:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 2:29:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42695)(?)])(1 )(2 )]

"
Information	7/5/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42695)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	7/5/2018 1:54:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/5/2018 1:19:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c6091df-7fc3-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/5/2018 12:15:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 10:29:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/4/2018 10:18:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/4/2018 8:43:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 8:19:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6249e186-7f99-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/4/2018 6:45:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 6:29:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2018 5:49:58 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/4/2018 5:47:51 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/4/2018 5:40:18 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/4/2018 5:07:45 PM	MTAService.OnSessionChange	0	None	5:07:45 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/4/2018 4:59:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 3:27:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/4/2018 3:27:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:20Z. Reason: GVLK.
Warning	7/4/2018 3:23:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 3:19:23 PM	McLogEvent	257	None	The scan of D:\4sightv2\SetUpFile_2018_05_11_Fr_19_50_58_9382\DISK1\ISSetupPrerequisites\{7E4BD306-FC5C-4706-91E0-21DEB7567637}\postgresql-9.5.3-1-windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8943.0000.
Information	7/4/2018 3:18:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 779a5af5-7f6f-11e8-86bb-204747d02364
Report Status: 0"
Information	7/4/2018 3:15:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/4/2018 3:15:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2018 3:15:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/4/2018 3:14:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/4/2018 2:29:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2018 2:07:40 PM	MTAService.OnSessionChange	0	None	2:07:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/4/2018 2:01:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 2:01:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 1:56:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 1:55:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 1:53:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 1:52:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/4/2018 1:27:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 1:04:59 PM	MTAService.OnSessionChange	0	None	1:04:59 PM - Session change notice received: SessionLock Session ID: 1
Information	7/4/2018 1:02:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 1:02:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:59:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:59:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 12:59:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:30:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 12:29:50 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:25:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 12:25:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:22:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8943.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/4/2018 12:02:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 12:02:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 12:00:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 11:59:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/4/2018 11:43:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 11:28:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 11:28:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 10:45:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/4/2018 10:45:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/4/2018 10:29:26 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 359

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1029

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 32

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 483

Information	7/4/2018 10:29:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2018 10:28:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/4/2018 10:28:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43646)(?)])(1 )(2 )]

"
Information	7/4/2018 10:28:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43646)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2018 10:26:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/4/2018 10:26:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:54Z. Reason: GVLK.
Information	7/4/2018 10:21:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/4/2018 10:21:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2018 10:21:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/4/2018 10:21:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	7/4/2018 10:20:03 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/4/2018 10:19:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/4/2018 10:19:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43656)(?)])(1 )(2 )]

"
Information	7/4/2018 10:19:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43656)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2018 10:18:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8d5ab73f-7f45-11e8-86bb-204747d02364
Report Status: 0"
Information	7/4/2018 10:18:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/4/2018 10:18:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:43Z. Reason: GVLK.
Error	7/4/2018 10:12:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/4/2018 10:11:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/4/2018 10:11:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2018 10:11:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/4/2018 10:11:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/4/2018 10:11:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/4/2018 10:09:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2018 10:09:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/4/2018 10:09:00 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/4/2018 10:09:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2018 10:08:57 AM	MTAService.OnSessionChange	0	None	10:08:57 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/4/2018 10:08:52 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/4/2018 10:08:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/3/2018 6:09:27 PM	MTAService.OnSessionChange	0	None	6:09:27 PM - Session change notice received: SessionLock Session ID: 1
Information	7/3/2018 6:01:37 PM	MTAService.OnSessionChange	0	None	6:01:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/3/2018 5:13:19 PM	MTAService.OnSessionChange	0	None	5:13:19 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/3/2018 4:39:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 4:18:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2018 3:27:07 PM	MTAService.OnSessionChange	0	None	3:27:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/3/2018 3:14:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2e286b3-7ea5-11e8-86bb-204747d02364
Report Status: 0"
Information	7/3/2018 3:11:08 PM	MTAService.OnSessionChange	0	None	3:11:08 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/3/2018 3:05:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 2:13:07 PM	MTAService.OnSessionChange	0	None	2:13:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/3/2018 1:49:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 1:49:34 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 1:27:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 1:26:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/3/2018 1:25:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 1:10:38 PM	MTAService.OnSessionChange	0	None	1:10:38 PM - Session change notice received: SessionLock Session ID: 1
Information	7/3/2018 12:22:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 12:22:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 12:20:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8942.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/3/2018 12:19:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 12:18:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/3/2018 12:18:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 12:14:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 12:14:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 12:10:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 12:10:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 12:07:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 12:07:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 12:07:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/3/2018 11:49:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/3/2018 11:49:21 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/3/2018 11:43:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 11:21:58 AM	MTAService.OnSessionChange	0	None	11:21:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/3/2018 10:44:53 AM	MTAService.OnSessionChange	0	None	10:44:53 AM - Session change notice received: SessionLock Session ID: 1
Information	7/3/2018 10:33:42 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/3/2018 10:32:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/3/2018 10:31:26 AM	MTAService.OnSessionChange	0	None	10:31:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/3/2018 10:14:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b8d4a581-7e7b-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/3/2018 10:08:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 9:52:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/3/2018 9:18:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/3/2018 9:18:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:31Z. Reason: GVLK.
Information	7/3/2018 9:13:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/3/2018 9:13:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2018 9:13:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2018 9:13:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/3/2018 8:35:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 8:18:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/3/2018 6:45:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 5:14:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ced189be-7e51-11e8-86bb-204747d02364
Report Status: 0"
Warning	7/3/2018 4:46:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 4:18:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2018 3:33:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/3/2018 3:33:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:06Z. Reason: GVLK.
Error	7/3/2018 3:26:35 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/3/2018 3:24:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/3/2018 3:24:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2018 3:24:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2018 3:24:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/3/2018 3:23:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/3/2018 3:23:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:06Z. Reason: GVLK.
Error	7/3/2018 3:18:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/3/2018 3:16:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/3/2018 3:16:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2018 3:16:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2018 3:16:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/3/2018 2:46:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/3/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45575)(?)])(1 )(2 )]

"
Information	7/3/2018 2:19:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45576)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	7/3/2018 12:51:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/3/2018 12:18:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2018 12:14:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e4e57960-7e27-11e8-86bb-204747d02364
Report Status: 0"
Information	7/3/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/2/2018 11:19:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 11:19:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:38Z. Reason: GVLK.
Information	7/2/2018 11:14:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/2/2018 11:14:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 11:14:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 11:14:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	7/2/2018 11:13:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	7/2/2018 9:38:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 8:18:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/2/2018 7:52:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 7:14:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fad1bb60-7dfd-11e8-86bb-204747d02364
Report Status: 0"
Information	7/2/2018 6:49:20 PM	MTAService.OnSessionChange	0	None	6:49:20 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/2/2018 6:14:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 6:06:58 PM	MTAService.OnSessionChange	0	None	6:06:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/2/2018 5:05:23 PM	MTAService.OnSessionChange	0	None	5:05:23 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/2/2018 4:40:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 4:18:29 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 437

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 405

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Information	7/2/2018 4:18:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/2/2018 4:17:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/2/2018 4:17:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46177)(?)])(1 )(2 )]

"
Information	7/2/2018 4:17:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46177)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 4:02:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/2/2018 4:02:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 4:02:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 3:43:02 PM	MTAService.OnSessionChange	0	None	3:43:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/2/2018 3:06:16 PM	MTAService.OnSessionChange	0	None	3:06:16 PM - Session change notice received: SessionLock Session ID: 1
Warning	7/2/2018 2:50:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 2:16:45 PM	MTAService.OnSessionChange	0	None	2:16:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	7/2/2018 2:14:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 10965abd-7dd4-11e8-86bb-204747d02364
Report Status: 0"
Information	7/2/2018 1:58:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/2/2018 1:57:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/2/2018 1:33:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 1:33:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 1:32:37 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 1:03:36 PM	MTAService.OnSessionChange	0	None	1:03:36 PM - Session change notice received: SessionLock Session ID: 1
Information	7/2/2018 1:03:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 1:02:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	7/2/2018 12:57:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 12:48:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 12:48:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 12:37:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 12:36:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 12:06:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 12:01:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/2/2018 12:01:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46434)(?)])(1 )(2 )]

"
Information	7/2/2018 12:01:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46434)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 12:01:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/2/2018 12:01:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 12:01:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 11:56:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 11:56:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 11:36:17 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 11:35:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 11:33:52 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 24569, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/2/2018 11:33:16 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/2/2018 11:32:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/2/2018 11:32:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/2/2018 11:26:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/2/2018 11:26:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	7/2/2018 11:00:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	7/2/2018 10:49:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 10:49:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:25Z. Reason: GVLK.
Information	7/2/2018 10:44:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/2/2018 10:44:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 10:44:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 10:44:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 10:41:01 AM	MTAService.OnSessionChange	0	None	10:41:01 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/2/2018 10:30:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 10:30:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:26:03Z. Reason: GVLK.
Information	7/2/2018 10:28:32 AM	MTAService.OnSessionChange	0	None	10:28:32 AM - Session change notice received: SessionLock Session ID: 1
Information	7/2/2018 10:28:28 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Tuesday, June 19, 2018 10:52:54 PM.
Information	7/2/2018 10:28:28 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=NetLock Arany (Class Gold) Főtanúsítvány, OU=Tanúsítványkiadók (Certification Services), O=NetLock Kft., L=Budapest, C=HU> Sha1 thumbprint: <06083F593F15A104A069A46BA903D006B7970991>.
Information	7/2/2018 10:28:28 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=Starfield Services Root Certificate Authority, OU=http://certificates.starfieldtech.com/repository/, O=""Starfield Technologies, Inc."", L=Scottsdale, S=Arizona, C=US> Sha1 thumbprint: <5D003860F002ED829DEAA41868F788186D62127F>."
Information	7/2/2018 10:28:28 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Autoridad de Certificacion de la Abogacia, O=Consejo General de la Abogacia NIF:Q-2863006I, C=ES> Sha1 thumbprint: <7F8A77836BDC6D068F8B0737FCC5725413068CA4>.
Information	7/2/2018 10:28:28 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE> Sha1 thumbprint: <D4DE20D05E66FC53FE1A50882C78DB2852CAE474>.
Information	7/2/2018 10:25:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/2/2018 10:25:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 10:25:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 10:25:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 10:20:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8941.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/2/2018 10:02:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 10:01:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 10:01:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-09T04:25:43Z. Reason: GVLK.
Information	7/2/2018 9:58:23 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	7/2/2018 9:58:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/2/2018 9:58:02 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/2/2018 9:58:01 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	7/2/2018 9:57:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/2/2018 9:57:00 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/2/2018 9:57:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/2/2018 9:57:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46558)(?)])(1 )(2 )]

"
Information	7/2/2018 9:57:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46558)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:56:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/2/2018 9:56:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 9:56:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 9:56:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:56:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:56:42 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/07/02 04:26"
Information	7/2/2018 9:56:41 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/07/02 04:26, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/2/2018 9:56:07 AM	MTAService.OnSessionChange	0	None	9:56:07 AM - Session change notice received: SessionUnlock Session ID: 1
Information	7/2/2018 9:51:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/2/2018 9:51:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:51:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 9:51:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 9:35:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 9:35:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:37Z. Reason: GVLK.
Warning	7/2/2018 9:30:27 AM	McLogEvent	258	None	The file C:\Program Files\MTA\Tools\ProxySet.exe contains Artemis!299B60DBC3FA Trojan.  The file was successfully deleted.
Error	7/2/2018 9:28:58 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	7/2/2018 9:24:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 9:19:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/2/2018 9:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46595)(?)])(1 )(2 )]

"
Information	7/2/2018 9:19:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46595)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:19:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/2/2018 9:19:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 9:19:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	7/2/2018 9:17:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/2/2018 9:17:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/2/2018 9:16:05 AM	MTAService.OnSessionChange	0	None	9:16:05 AM - Session change notice received: SessionLock Session ID: 1
Information	7/2/2018 9:15:16 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/2/2018 9:15:15 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/2/2018 9:13:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 26707d8e-7daa-11e8-86bb-204747d02364
Report Status: 0"
Information	7/2/2018 9:13:02 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	7/2/2018 9:12:07 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {4F29C994-A89A-46F8-8534-37CD8ABBE729}
Error	7/2/2018 9:12:07 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {4F29C994-A89A-46F8-8534-37CD8ABBE729}
Information	7/2/2018 9:11:52 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/2/2018 9:11:51 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/2/2018 9:11:48 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/2/2018 9:11:33 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/2/2018 9:11:15 AM	ESENT	302	Logging/Recovery	Windows (8704) Windows: The database engine has successfully completed recovery steps.
Information	7/2/2018 9:11:14 AM	ESENT	301	Logging/Recovery	Windows (8704) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/2/2018 9:11:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/2/2018 9:11:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46604)(?)])(1 )(2 )]

"
Information	7/2/2018 9:11:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46604)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:11:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/2/2018 9:11:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 9:11:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/2/2018 9:11:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/2/2018 9:11:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/2/2018 9:11:06 AM	ESENT	301	Logging/Recovery	Windows (8704) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00909.log.
Information	7/2/2018 9:11:06 AM	ESENT	300	Logging/Recovery	Windows (8704) Windows: The database engine is initiating recovery steps.
Information	7/2/2018 9:11:05 AM	ESENT	102	General	Windows (8704) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/2/2018 9:11:04 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 9:11:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/2/2018 9:10:59 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8938.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	7/2/2018 9:10:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/2/2018 9:10:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/2/2018 9:09:55 AM	Service1	0	None	Service started successfully.
Error	7/2/2018 9:09:48 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/2/2018 9:09:48 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/2/2018 9:09:48 AM	MTAService	0	None	Service started successfully.
Information	7/2/2018 9:09:33 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/2/2018 9:09:32 AM	PostgreSQL	0	None	"2018-07-02 09:09:32 IST LOG:  redirecting log output to logging collector process
2018-07-02 09:09:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/2/2018 9:09:31 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/2/2018 9:09:29 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/2/2018 9:09:29 AM	MTAService.OnStart	0	None	9:09:28 AM - User is already logged in : 212558710
Information	7/2/2018 9:09:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/2/2018 9:09:27 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/2/2018 9:09:27 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/2/2018 9:09:26 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/2/2018 9:09:26 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/2/2018 9:09:25 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/2/2018 9:09:17 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/2/2018 9:09:16 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:16 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/2/2018 9:09:16 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/2/2018 9:09:16 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/2/2018 9:09:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/2/2018 9:09:15 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/2/2018 9:09:14 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/2/2018 9:09:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/2/2018 9:09:10 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3948 at 6/29/2018 4:12:43 PM (local) 6/29/2018 10:42:43 AM (UTC). This is an informational message only; no user action is required.
Information	7/2/2018 9:09:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/2/2018 9:09:08 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/2/2018 9:09:08 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/2/2018 9:09:08 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/2/2018 9:09:08 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3984.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/2/2018 9:09:05 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/2/2018 9:08:30 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/2/2018 9:08:22 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/2/2018 9:08:09 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/2/2018 9:08:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/2/2018 9:08:09 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/29/2018 4:12:58 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	6/29/2018 4:12:44 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	6/29/2018 4:12:43 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	6/29/2018 4:12:42 PM	McLogEvent	257	None	The scan of C:\Program Files\MTA\GUI\msvcp140.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8938.0000.
Warning	6/29/2018 4:12:39 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 176 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1244 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1240 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1244 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
"
Information	6/29/2018 4:12:38 PM	MTAService.OnSessionChange	0	None	4:12:38 PM - Logoff
Information	6/29/2018 4:12:38 PM	MTAService.OnSessionChange	0	None	4:12:38 PM - Session change notice received: SessionLogoff Session ID: 1
Information	6/29/2018 4:12:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	6/29/2018 4:12:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	6/29/2018 4:12:36 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	6/29/2018 4:11:47 PM	MTAService.OnSessionChange	0	None	4:11:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/29/2018 3:45:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 3:44:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 3:44:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/29/2018 3:09:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 2:04:50 PM	MTAService.OnSessionChange	0	None	2:04:50 PM - Session change notice received: SessionLock Session ID: 1
Information	6/29/2018 1:59:17 PM	MTAService.OnSessionChange	0	None	1:59:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/29/2018 1:56:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 1:56:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/29/2018 1:22:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53bb2a45-7b71-11e8-8759-204747d02364
Report Status: 0"
Warning	6/29/2018 1:11:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 12:40:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8938.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	6/29/2018 12:34:15 PM	MTAService.OnSessionChange	0	None	12:34:15 PM - Session change notice received: SessionLock Session ID: 1
Information	6/29/2018 12:07:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 12:07:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/29/2018 12:04:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 12:04:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/29/2018 11:48:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 11:48:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/29/2018 11:45:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 11:44:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 11:44:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/29/2018 11:23:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 11:23:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/29/2018 11:15:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 11:14:16 AM	MTAService.OnSessionChange	0	None	11:14:16 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/29/2018 11:03:08 AM	MTAService.OnSessionChange	0	None	11:03:08 AM - Session change notice received: SessionLock Session ID: 1
Information	6/29/2018 11:01:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/29/2018 11:01:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/29/2018 10:22:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/29/2018 10:22:20 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/29/2018 10:20:21 AM	MTAService.OnSessionChange	0	None	10:20:21 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/29/2018 9:42:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 9:31:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/29/2018 8:59:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2018 8:59:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:18Z. Reason: GVLK.
Information	6/29/2018 8:54:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2018 8:54:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2018 8:54:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2018 8:54:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2018 8:22:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69b2f25a-7b47-11e8-8759-204747d02364
Report Status: 0"
Warning	6/29/2018 7:45:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 7:45:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 7:44:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 7:44:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/29/2018 5:51:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 5:04:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2018 5:04:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:10Z. Reason: GVLK.
Information	6/29/2018 4:59:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2018 4:59:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2018 4:59:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2018 4:59:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/29/2018 4:02:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 3:45:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 3:44:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 3:44:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2018 3:34:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2018 3:34:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:15Z. Reason: GVLK.
Information	6/29/2018 3:29:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2018 3:29:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2018 3:29:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2018 3:29:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/29/2018 3:27:31 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/29/2018 3:24:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2018 3:24:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:14Z. Reason: GVLK.
Information	6/29/2018 3:22:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f9f34e7-7b1d-11e8-8759-204747d02364
Report Status: 0"
Error	6/29/2018 3:19:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/29/2018 3:19:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2018 3:19:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2018 3:19:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2018 3:19:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/29/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51335)(?)])(1 )(2 )]

"
Information	6/29/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51336)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	6/29/2018 2:05:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/29/2018 12:21:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/29/2018 12:15:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2018 12:15:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:59Z. Reason: GVLK.
Information	6/29/2018 12:10:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2018 12:10:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2018 12:10:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2018 12:10:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/28/2018 11:44:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 11:44:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 11:44:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/28/2018 10:35:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 10:22:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95b2b469-7af3-11e8-8759-204747d02364
Report Status: 0"
Warning	6/28/2018 8:36:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 7:44:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 7:44:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 7:43:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/28/2018 6:58:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 6:52:21 PM	MTAService.OnSessionChange	0	None	6:52:21 PM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 6:44:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2018 6:44:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51790)(?)])(1 )(2 )]

"
Information	6/28/2018 6:44:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51790)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 6:38:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2018 6:38:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 6:38:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2018 6:01:46 PM	MTAService.OnSessionChange	0	None	6:01:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/28/2018 5:22:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aafe888b-7ac9-11e8-8759-204747d02364
Report Status: 0"
Warning	6/28/2018 5:18:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 5:13:12 PM	MTAService.OnSessionChange	0	None	5:13:12 PM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 4:38:02 PM	MTAService.OnSessionChange	0	None	4:38:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/28/2018 3:44:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 3:43:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 3:43:48 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/28/2018 3:43:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 3:38:11 PM	MTAService.OnSessionChange	0	None	3:38:11 PM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 3:23:23 PM	MTAService.OnSessionChange	0	None	3:23:23 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/28/2018 3:20:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 2:58:54 PM	MTAService.OnSessionChange	0	None	2:58:54 PM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 2:13:25 PM	MTAService.OnSessionChange	0	None	2:13:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/28/2018 1:55:21 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 1:55:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/28/2018 1:21:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 1:04:03 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 1:03:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 1:00:57 PM	MTAService.OnSessionChange	0	None	1:00:57 PM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 12:44:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 12:44:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 12:44:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 12:44:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 12:39:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 12:39:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 12:25:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8937.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	6/28/2018 12:22:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0f6a927-7a9f-11e8-8759-204747d02364
Report Status: 0"
Information	6/28/2018 12:20:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 12:19:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 12:06:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 12:05:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 11:59:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 11:58:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 11:44:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 11:44:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/28/2018 11:43:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/28/2018 11:43:29 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 11:37:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2018 11:37:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:23Z. Reason: GVLK.
Information	6/28/2018 11:32:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2018 11:32:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 11:32:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 11:32:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2018 11:31:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2018 11:31:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:33Z. Reason: GVLK.
Information	6/28/2018 11:29:10 AM	MTAService.OnSessionChange	0	None	11:29:10 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/28/2018 11:28:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 11:26:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2018 11:26:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 11:26:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 11:26:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2018 11:19:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/28/2018 11:19:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/28/2018 11:00:54 AM	MTAService.OnSessionChange	0	None	11:00:54 AM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 10:00:03 AM	MTAService.OnSessionChange	0	None	10:00:03 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/28/2018 9:34:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 9:34:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/28/2018 9:34:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/28/2018 9:34:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	6/28/2018 9:33:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/28/2018 9:33:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 24, Compared: 24592, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/28/2018 9:31:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/28/2018 9:31:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	6/28/2018 9:31:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	6/28/2018 9:22:11 AM	MTAService.OnSessionChange	0	None	9:22:11 AM - Session change notice received: SessionLock Session ID: 1
Information	6/28/2018 9:19:00 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/28/2018 9:04:16 AM	MTAService.OnSessionChange	0	None	9:04:16 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/28/2018 7:45:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 7:44:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 7:43:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 7:21:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d6caf46d-7a75-11e8-8759-204747d02364
Report Status: 0"
Warning	6/28/2018 5:54:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 4:29:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2018 4:29:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:55Z. Reason: GVLK.
Information	6/28/2018 4:24:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2018 4:24:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 4:24:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 4:24:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/28/2018 4:23:08 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/28/2018 4:20:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2018 4:20:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:09Z. Reason: GVLK.
Warning	6/28/2018 4:17:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	6/28/2018 4:15:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/28/2018 4:15:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2018 4:15:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 4:15:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 4:15:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2018 3:44:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2018 3:43:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/28/2018 2:32:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2018 2:21:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ecd58072-7a4b-11e8-8759-204747d02364
Report Status: 0"
Information	6/28/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52775)(?)])(1 )(2 )]

"
Information	6/28/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52775)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2018 2:19:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2018 1:40:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/28/2018 1:39:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/28/2018 12:57:22 AM	GE Software	0	(1)	++Installation complete
Information	6/28/2018 12:57:22 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++Started the installation of GE Skype for Business DefaultIMProvider Correction 1.0 V01 with the following commandline: /Q
Information	6/28/2018 12:57:20 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	6/28/2018 12:57:19 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Warning	6/28/2018 12:39:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/28/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/27/2018 11:44:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 11:43:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/27/2018 11:01:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 9:21:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02e3c933-7a22-11e8-8759-204747d02364
Report Status: 0"
Warning	6/27/2018 9:08:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 8:38:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 8:38:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:54Z. Reason: GVLK.
Information	6/27/2018 8:33:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/27/2018 8:33:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 8:33:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 8:33:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/27/2018 7:44:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 7:44:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:30Z. Reason: GVLK.
Information	6/27/2018 7:44:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 7:43:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/27/2018 7:43:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 7:42:02 PM	MTAService.OnSessionChange	0	None	7:42:02 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 7:39:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/27/2018 7:39:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 7:39:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 7:39:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/27/2018 7:25:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 7:17:51 PM	MTAService.OnSessionChange	0	None	7:17:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 6:58:21 PM	MTAService.OnSessionChange	0	None	6:58:21 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 6:52:52 PM	MTAService.OnSessionChange	0	None	6:52:52 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 6:49:00 PM	MTAService.OnSessionChange	0	None	6:49:00 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/27/2018 5:48:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 5:20:49 PM	MTAService.OnSessionChange	0	None	5:20:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 4:36:27 PM	MTAService.OnSessionChange	0	None	4:36:27 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 4:21:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18bb2e03-79f8-11e8-8759-204747d02364
Report Status: 0"
Warning	6/27/2018 4:17:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 4:00:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 3:55:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/27/2018 3:55:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53399)(?)])(1 )(2 )]

"
Information	6/27/2018 3:55:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53399)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	6/27/2018 3:55:28 PM	Application Error	1000	(100)	"Faulting application name: WINWORD.EXE, version: 16.0.8431.2270, time stamp: 0x5b19e1b4
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x0000a048
Faulting process id: 0x3ab8
Faulting application start time: 0x01d40e010c34cc4f
Faulting application path: C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 68caea2f-79f4-11e8-8759-204747d02364"
Information	6/27/2018 3:54:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/27/2018 3:54:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53400)(?)])(1 )(2 )]

"
Information	6/27/2018 3:54:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53400)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 3:54:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/27/2018 3:54:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 3:54:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	6/27/2018 3:54:29 PM	Application Error	1000	(100)	"Faulting application name: WINWORD.EXE, version: 16.0.8431.2270, time stamp: 0x5b19e1b4
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x0000a048
Faulting process id: 0x3250
Faulting application start time: 0x01d40d4bc53dfda1
Faulting application path: C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE
Faulting module path: C:\Windows\syswow64\msvcrt.dll
Report Id: 45e46f9f-79f4-11e8-8759-204747d02364"
Information	6/27/2018 3:43:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 3:22:20 PM	MTAService.OnSessionChange	0	None	3:22:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 2:55:29 PM	MTAService.OnSessionChange	0	None	2:55:29 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/27/2018 2:45:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 2:15:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/27/2018 2:15:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 2:02:17 PM	MTAService.OnSessionChange	0	None	2:02:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 1:32:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/27/2018 1:32:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 1:06:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	6/27/2018 1:06:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 1:06:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 1:00:28 PM	MTAService.OnSessionChange	0	None	1:00:28 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 12:58:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8936.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/27/2018 12:29:10 PM	MTAService.OnSessionChange	0	None	12:29:10 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 12:17:41 PM	MTAService.OnSessionChange	0	None	12:17:41 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 12:17:37 PM	MTAService.OnSessionChange	0	None	12:17:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 12:17:25 PM	MTAService.OnSessionChange	0	None	12:17:25 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 12:08:40 PM	MTAService.OnSessionChange	0	None	12:08:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 12:06:43 PM	MTAService.OnSessionChange	0	None	12:06:43 PM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 12:06:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/27/2018 12:06:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 12:01:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/27/2018 12:00:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 11:45:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/27/2018 11:44:50 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/27/2018 11:43:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 11:21:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2ea420e6-79ce-11e8-8759-204747d02364
Report Status: 0"
Warning	6/27/2018 11:13:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 10:59:02 AM	MTAService.OnSessionChange	0	None	10:59:02 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 10:50:57 AM	MTAService.OnSessionChange	0	None	10:50:57 AM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 9:48:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/27/2018 9:48:25 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/27/2018 9:48:16 AM	MTAService.OnSessionChange	0	None	9:48:16 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/27/2018 9:27:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	6/27/2018 9:27:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 9:21:01 AM	MTAService.OnSessionChange	0	None	9:21:01 AM - Session change notice received: SessionLock Session ID: 1
Information	6/27/2018 8:49:48 AM	MTAService.OnSessionChange	0	None	8:49:48 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/27/2018 7:56:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 7:42:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/27/2018 6:25:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 6:21:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 442706b1-79a4-11e8-8759-204747d02364
Report Status: 0"
Warning	6/27/2018 4:47:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 3:42:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/27/2018 3:39:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 3:39:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:55Z. Reason: GVLK.
Information	6/27/2018 3:34:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/27/2018 3:34:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 3:34:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 3:34:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/27/2018 3:32:49 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/27/2018 3:30:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 3:30:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:22Z. Reason: GVLK.
Error	6/27/2018 3:25:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/27/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/27/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 3:25:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 3:25:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/27/2018 3:20:03 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/27/2018 3:18:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	6/27/2018 3:01:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 2:24:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54215)(?)])(1 )(2 )]

"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54215)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/27/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/27/2018 1:25:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/27/2018 1:21:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a2fd2a9-797a-11e8-8759-204747d02364
Report Status: 0"
Information	6/27/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/26/2018 11:42:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/26/2018 11:29:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/26/2018 9:53:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 9:04:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 9:04:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:49Z. Reason: GVLK.
Information	6/26/2018 8:59:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/26/2018 8:59:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 8:59:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 8:59:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 8:37:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8935.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/26/2018 8:21:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7001fd0a-7950-11e8-8759-204747d02364
Report Status: 0"
Warning	6/26/2018 8:06:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 7:42:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/26/2018 7:25:24 PM	MTAService.OnSessionChange	0	None	7:25:24 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/26/2018 6:32:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 6:22:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54698)(?)])(1 )(2 )]

"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54698)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 6:16:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 6:05:28 PM	MTAService.OnSessionChange	0	None	6:05:28 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/26/2018 4:54:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 4:50:51 PM	MTAService.OnSessionChange	0	None	4:50:51 PM - Session change notice received: SessionLock Session ID: 1
Information	6/26/2018 3:42:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/26/2018 3:21:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 85f34955-7926-11e8-8759-204747d02364
Report Status: 0"
Warning	6/26/2018 3:10:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 2:34:42 PM	MTAService.OnSessionChange	0	None	2:34:42 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/26/2018 1:24:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 1:22:22 PM	MTAService.OnSessionChange	0	None	1:22:22 PM - Session change notice received: SessionLock Session ID: 1
Information	6/26/2018 12:58:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/26/2018 12:58:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/26/2018 11:47:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 11:42:31 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 499

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	6/26/2018 11:42:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 4294967295

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/26/2018 11:42:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/26/2018 11:42:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55093)(?)])(1 )(2 )]

"
Information	6/26/2018 11:42:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55093)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 11:42:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/26/2018 11:42:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 11:42:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 11:41:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/26/2018 11:31:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 10:26:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 10:26:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:29Z. Reason: GVLK.
Information	6/26/2018 10:25:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 10:21:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9be5999c-78fc-11e8-8759-204747d02364
Report Status: 0"
Information	6/26/2018 10:21:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/26/2018 10:21:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 10:21:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 10:21:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 10:20:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/26/2018 10:20:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55174)(?)])(1 )(2 )]

"
Information	6/26/2018 10:20:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55174)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 10:15:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/26/2018 10:15:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55179)(?)])(1 )(2 )]

"
Information	6/26/2018 10:15:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55179)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 10:15:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/26/2018 10:15:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 10:15:42 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 10:06:10 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/26/2018 10:05:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/26/2018 9:50:08 AM	MTAService.OnSessionChange	0	None	9:50:08 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/26/2018 9:35:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 9:25:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/26/2018 9:21:05 AM	MTAService.OnSessionChange	0	None	9:21:05 AM - Session change notice received: SessionLock Session ID: 1
Information	6/26/2018 9:20:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/26/2018 9:20:00 AM	MTAService.OnSessionChange	0	None	9:20:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/26/2018 9:07:18 AM	MTAService.OnSessionChange	0	None	9:07:18 AM - Session change notice received: SessionLock Session ID: 1
Information	6/26/2018 8:56:17 AM	MTAService.OnSessionChange	0	None	8:56:17 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/26/2018 7:55:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 6:24:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 6:24:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:23Z. Reason: GVLK.
Information	6/26/2018 6:19:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/26/2018 6:19:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 6:19:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 6:19:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/26/2018 6:14:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 5:24:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/26/2018 5:21:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1e62a93-78d2-11e8-8759-204747d02364
Report Status: 0"
Warning	6/26/2018 4:42:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 4:19:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 4:19:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:28Z. Reason: GVLK.
Information	6/26/2018 4:14:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/26/2018 4:14:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 4:14:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 4:14:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/26/2018 4:12:55 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/26/2018 4:09:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 4:09:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:54Z. Reason: GVLK.
Error	6/26/2018 4:05:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/26/2018 4:04:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/26/2018 4:04:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 4:04:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 4:04:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 3:58:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/26/2018 3:58:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/26/2018 2:58:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 2:24:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/26/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/26/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55655)(?)])(1 )(2 )]

"
Information	6/26/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55655)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/26/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/26/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/26/2018 2:19:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/26/2018 1:24:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/26/2018 1:03:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/26/2018 12:21:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c8063a62-78a8-11e8-8759-204747d02364
Report Status: 0"
Information	6/26/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	6/25/2018 11:31:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/25/2018 9:38:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 9:24:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 8:27:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 8:27:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:32Z. Reason: GVLK.
Information	6/25/2018 8:22:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 8:22:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 8:22:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 8:22:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/25/2018 7:43:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 7:32:46 PM	MTAService.OnSessionChange	0	None	7:32:46 PM - Session change notice received: SessionLock Session ID: 1
Information	6/25/2018 7:21:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ddf72690-787e-11e8-8759-204747d02364
Report Status: 0"
Information	6/25/2018 6:29:25 PM	MTAService.OnSessionChange	0	None	6:29:25 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/25/2018 6:09:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 6:06:23 PM	MTAService.OnSessionChange	0	None	6:06:23 PM - Session change notice received: SessionLock Session ID: 1
Information	6/25/2018 5:24:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 5:22:59 PM	MTAService.OnSessionChange	0	None	5:22:59 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/25/2018 4:26:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/25/2018 2:40:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 2:29:18 PM	MTAService.OnSessionChange	0	None	2:29:18 PM - Session change notice received: SessionLock Session ID: 1
Information	6/25/2018 2:21:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4095f76-7854-11e8-8759-204747d02364
Report Status: 0"
Information	6/25/2018 2:20:26 PM	MTAService.OnSessionChange	0	None	2:20:26 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/25/2018 1:48:57 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/25/2018 1:48:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/25/2018 1:24:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 1:24:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 1:20:19 PM	MTAService.OnSessionChange	0	None	1:20:19 PM - Session change notice received: SessionLock Session ID: 1
Information	6/25/2018 1:15:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/25/2018 1:14:36 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/25/2018 1:07:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 12:53:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/25/2018 12:53:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/25/2018 12:25:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/25/2018 12:24:16 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/25/2018 11:25:28 AM	MTAService.OnSessionChange	0	None	11:25:28 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/25/2018 11:15:58 AM	MTAService.OnSessionChange	0	None	11:15:58 AM - Session change notice received: SessionLock Session ID: 1
Warning	6/25/2018 11:14:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/25/2018 10:48:08 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8932.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/25/2018 10:38:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 10:38:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:14Z. Reason: GVLK.
Information	6/25/2018 10:33:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 10:33:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 10:33:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 10:33:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 10:25:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 10:25:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:29Z. Reason: GVLK.
Information	6/25/2018 10:20:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 10:20:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 10:20:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 10:20:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 10:14:58 AM	MTAService.OnSessionChange	0	None	10:14:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/25/2018 10:08:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 10:08:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:22:13Z. Reason: GVLK.
Information	6/25/2018 10:05:50 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/25/2018 10:03:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 10:03:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 10:03:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 10:03:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 9:57:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 9:57:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-07-02T04:21:36Z. Reason: GVLK.
Information	6/25/2018 9:52:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:52:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:52:35 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/06/25 04:22"
Information	6/25/2018 9:52:35 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/06/25 04:22, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	6/25/2018 9:45:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/25/2018 9:45:22 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/25/2018 9:45:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	6/25/2018 9:44:47 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 24347, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/25/2018 9:43:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	6/25/2018 9:43:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	6/25/2018 9:39:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	6/25/2018 9:38:07 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/25/2018 9:34:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/25/2018 9:34:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56660)(?)])(1 )(2 )]

"
Information	6/25/2018 9:34:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56660)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:34:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/25/2018 9:34:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 9:34:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 9:33:19 AM	MTAService.OnSessionChange	0	None	9:33:19 AM - Session change notice received: SessionLock Session ID: 1
Information	6/25/2018 9:29:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 9:29:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:29:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 9:29:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 9:29:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 9:26:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/25/2018 9:26:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:30Z. Reason: GVLK.
Information	6/25/2018 9:24:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 9:24:17 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/25/2018 9:24:11 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 218

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 390

Information	6/25/2018 9:24:01 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/25/2018 9:24:00 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/25/2018 9:23:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/25/2018 9:23:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/25/2018 9:23:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56672)(?)])(1 )(2 )]

"
Information	6/25/2018 9:23:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/25/2018 9:23:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56672)(?)])(1 )(2 )]

"
Information	6/25/2018 9:23:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56672)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:23:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56672)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:21:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0a00603d-782b-11e8-8759-204747d02364
Report Status: 0"
Error	6/25/2018 9:20:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/25/2018 9:20:06 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/25/2018 9:19:41 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8931.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	6/25/2018 9:19:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/25/2018 9:19:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/25/2018 9:19:18 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/25/2018 9:19:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56676)(?)])(1 )(2 )]

"
Information	6/25/2018 9:19:17 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/25/2018 9:19:17 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/25/2018 9:19:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56676)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:19:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/25/2018 9:19:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 9:19:16 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/25/2018 9:19:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/25/2018 9:18:54 AM	ESENT	302	Logging/Recovery	Windows (8496) Windows: The database engine has successfully completed recovery steps.
Information	6/25/2018 9:18:52 AM	ESENT	301	Logging/Recovery	Windows (8496) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/25/2018 9:18:45 AM	ESENT	301	Logging/Recovery	Windows (8496) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008EF.log.
Information	6/25/2018 9:18:45 AM	ESENT	300	Logging/Recovery	Windows (8496) Windows: The database engine is initiating recovery steps.
Information	6/25/2018 9:18:44 AM	ESENT	102	General	Windows (8496) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/25/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/25/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/25/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/25/2018 9:18:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/25/2018 9:18:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/25/2018 9:18:00 AM	Service1	0	None	Service started successfully.
Information	6/25/2018 9:17:57 AM	MTAService	0	None	Service started successfully.
Error	6/25/2018 9:17:54 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/25/2018 9:17:53 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/25/2018 9:17:53 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/25/2018 9:17:49 AM	PostgreSQL	0	None	Server started and accepting connections

Information	6/25/2018 9:17:48 AM	PostgreSQL	0	None	"2018-06-25 09:17:48 IST LOG:  redirecting log output to logging collector process
2018-06-25 09:17:48 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/25/2018 9:17:46 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/25/2018 9:17:45 AM	MTAService.OnStart	0	None	9:17:44 AM - User is already logged in : 212558710
Information	6/25/2018 9:17:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/25/2018 9:17:42 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/25/2018 9:17:42 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/25/2018 9:17:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/25/2018 9:17:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/25/2018 9:17:41 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/25/2018 9:17:33 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/25/2018 9:17:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/25/2018 9:17:32 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/25/2018 9:17:31 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/25/2018 9:17:28 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3744 at 6/22/2018 4:28:14 PM (local) 6/22/2018 10:58:14 AM (UTC). This is an informational message only; no user action is required.
Information	6/25/2018 9:17:26 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/25/2018 9:17:26 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/25/2018 9:17:26 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/25/2018 9:17:26 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/25/2018 9:17:26 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3948.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/25/2018 9:17:24 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/25/2018 9:17:23 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/25/2018 9:16:50 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/25/2018 9:16:46 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/25/2018 9:16:34 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/25/2018 9:16:34 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/25/2018 9:16:34 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/22/2018 4:28:30 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	6/22/2018 4:28:14 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	6/22/2018 4:28:10 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 496 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 3884 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1752 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	6/22/2018 4:28:11 PM	MTAService.OnSessionChange	0	None	4:28:11 PM - Logoff
Information	6/22/2018 4:28:11 PM	MTAService.OnSessionChange	0	None	4:28:11 PM - Session change notice received: SessionLogoff Session ID: 1
Information	6/22/2018 4:28:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	6/22/2018 4:28:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	6/22/2018 4:28:09 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	6/22/2018 4:17:56 PM	MTAService.OnSessionChange	0	None	4:17:56 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/22/2018 3:48:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/22/2018 3:15:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03b94971-7601-11e8-8a2b-204747d02364
Report Status: 0"
Information	6/22/2018 3:14:50 PM	MTAService.OnSessionChange	0	None	3:14:50 PM - Session change notice received: SessionLock Session ID: 1
Information	6/22/2018 2:15:30 PM	MTAService.OnSessionChange	0	None	2:15:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/22/2018 2:06:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/22/2018 2:06:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/22/2018 2:05:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/22/2018 1:58:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/22/2018 1:32:44 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/22/2018 1:00:53 PM	MTAService.OnSessionChange	0	None	1:00:53 PM - Session change notice received: SessionLock Session ID: 1
Information	6/22/2018 12:33:42 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/22/2018 12:33:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/22/2018 12:05:41 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	6/22/2018 11:58:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/22/2018 10:48:18 AM	MTAService.OnSessionChange	0	None	10:48:18 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/22/2018 10:36:50 AM	MTAService.OnSessionChange	0	None	10:36:50 AM - Session change notice received: SessionLock Session ID: 1
Information	6/22/2018 10:36:22 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8931.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/22/2018 10:28:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/22/2018 10:28:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:43Z. Reason: GVLK.
Information	6/22/2018 10:23:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/22/2018 10:23:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/22/2018 10:23:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/22/2018 10:23:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/22/2018 10:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/22/2018 10:23:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60932)(?)])(1 )(2 )]

"
Information	6/22/2018 10:23:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60932)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/22/2018 10:22:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/22/2018 10:22:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:16Z. Reason: GVLK.
Information	6/22/2018 10:17:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/22/2018 10:17:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/22/2018 10:17:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/22/2018 10:17:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/22/2018 10:15:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 19fb49ec-75d7-11e8-8a2b-204747d02364
Report Status: 0"
Warning	6/22/2018 10:07:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/22/2018 10:06:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/22/2018 10:06:07 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/22/2018 10:05:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/22/2018 10:05:40 AM	MTAService.OnSessionChange	0	None	10:05:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 7:18:52 PM	MTAService.OnSessionChange	0	None	7:18:52 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/21/2018 6:35:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 5:40:09 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/21/2018 5:39:10 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 25, Deleted: 0, Modified: 3, Compared: 24347, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/21/2018 5:37:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/21/2018 5:37:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/21/2018 5:37:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/21/2018 5:37:33 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 124

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 406

Information	6/21/2018 5:37:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/21/2018 5:36:57 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/21/2018 5:36:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 5:36:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61938)(?)])(1 )(2 )]

"
Information	6/21/2018 5:36:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61938)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 5:28:42 PM	MTAService.OnSessionChange	0	None	5:28:42 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/21/2018 4:58:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 4:24:43 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/21/2018 4:24:43 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/21/2018 4:23:56 PM	MTAService.OnSessionChange	0	None	4:23:56 PM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 4:23:39 PM	MTAService.OnSessionChange	0	None	4:23:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 4:10:48 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/21/2018 4:10:48 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/21/2018 3:46:03 PM	MTAService.OnSessionChange	0	None	3:46:03 PM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 3:17:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1e763261-7538-11e8-8a2b-204747d02364
Report Status: 0"
Warning	6/21/2018 3:13:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 3:11:25 PM	MTAService.OnSessionChange	0	None	3:11:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 3:01:54 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/21/2018 3:01:53 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/21/2018 3:00:45 PM	MTAService.OnSessionChange	0	None	3:00:45 PM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 3:00:04 PM	MTAService.OnSessionChange	0	None	3:00:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 1:59:37 PM	MTAService.OnSessionChange	0	None	1:59:37 PM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 1:49:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 1:49:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 1:49:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 1:47:08 PM	MTAService.OnSessionChange	0	None	1:47:08 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/21/2018 1:28:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 1:13:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 1:13:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:35Z. Reason: GVLK.
Information	6/21/2018 1:08:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 1:08:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 1:08:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 1:08:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 12:52:49 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/21/2018 12:50:55 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/21/2018 12:44:43 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/21/2018 12:43:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 12:43:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:34Z. Reason: GVLK.
Information	6/21/2018 12:38:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 12:38:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 12:38:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 12:38:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 12:24:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8930.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/21/2018 12:13:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 12:13:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:35Z. Reason: GVLK.
Information	6/21/2018 12:08:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 12:08:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 12:08:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 12:08:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 12:01:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 12:01:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:34Z. Reason: GVLK.
Information	6/21/2018 12:00:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 11:59:59 AM	MTAService.OnSessionChange	0	None	11:59:59 AM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 11:58:51 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/21/2018 11:58:50 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/21/2018 11:56:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	6/21/2018 11:55:48 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/21/2018 11:55:33 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/21/2018 11:55:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 11:55:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62279)(?)])(1 )(2 )]

"
Information	6/21/2018 11:55:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62279)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 11:54:38 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8929.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/21/2018 11:54:18 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 11:54:17 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	6/21/2018 11:54:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	6/21/2018 11:54:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 11:54:13 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 11:54:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/21/2018 11:53:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 11:53:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 11:53:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62281)(?)])(1 )(2 )]

"
Information	6/21/2018 11:53:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 11:53:50 AM	ESENT	302	Logging/Recovery	Windows (7360) Windows: The database engine has successfully completed recovery steps.
Information	6/21/2018 11:53:49 AM	ESENT	301	Logging/Recovery	Windows (7360) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/21/2018 11:53:48 AM	ESENT	300	Logging/Recovery	Windows (7360) Windows: The database engine is initiating recovery steps.
Information	6/21/2018 11:53:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 11:53:48 AM	ESENT	102	General	Windows (7360) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/21/2018 11:53:48 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 11:53:48 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 11:53:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	6/21/2018 11:53:29 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 11:53:17 AM	MTAService.OnSessionChange	0	None	11:53:17 AM - Logon : 212558710
Information	6/21/2018 11:53:17 AM	MTAService.OnSessionChange	0	None	11:53:17 AM - Session change notice received: SessionLogon Session ID: 1
Error	6/21/2018 11:53:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 11:53:06 AM	Service1	0	None	Service started successfully.
Error	6/21/2018 11:52:58 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/21/2018 11:52:58 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/21/2018 11:52:46 AM	PostgreSQL	0	None	Server started and accepting connections

Information	6/21/2018 11:52:42 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/21/2018 11:52:42 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/21/2018 11:52:40 AM	PostgreSQL	0	None	"2018-06-21 11:52:40 IST LOG:  redirecting log output to logging collector process
2018-06-21 11:52:40 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/21/2018 11:52:39 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/21/2018 11:52:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/21/2018 11:52:38 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/21/2018 11:52:38 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/21/2018 11:52:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/21/2018 11:52:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/21/2018 11:52:36 AM	MTAService	0	None	Service started successfully.
Information	6/21/2018 11:52:36 AM	MTAService.OnStart	0	None	11:52:36 AM - Waiting for user to Logon
Information	6/21/2018 11:52:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/21/2018 11:52:30 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/21/2018 11:52:29 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/21/2018 11:52:29 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3924 at 6/21/2018 10:44:20 AM (local) 6/21/2018 5:14:20 AM (UTC). This is an informational message only; no user action is required.
Information	6/21/2018 11:52:28 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/21/2018 11:52:27 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/21/2018 11:52:27 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/21/2018 11:52:27 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/21/2018 11:52:27 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/21/2018 11:52:27 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3744.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/21/2018 11:52:26 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/21/2018 11:52:15 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/21/2018 11:52:14 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 11:52:10 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/21/2018 11:52:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/21/2018 11:52:10 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/21/2018 10:55:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 10:55:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62340)(?)])(1 )(2 )]

"
Information	6/21/2018 10:55:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62340)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 10:55:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 10:55:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 10:55:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 10:54:55 AM	MTAService.OnSessionChange	0	None	10:54:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 10:54:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 10:54:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:19Z. Reason: GVLK.
Information	6/21/2018 10:52:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 10:51:10 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/21/2018 10:51:10 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/21/2018 10:48:34 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/21/2018 10:47:09 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 10:47:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 10:47:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 10:47:01 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 10:47:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 10:46:59 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 10:46:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 10:46:47 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/21/2018 10:46:38 AM	ESENT	302	Logging/Recovery	Windows (7100) Windows: The database engine has successfully completed recovery steps.
Information	6/21/2018 10:46:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 10:46:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62348)(?)])(1 )(2 )]

"
Information	6/21/2018 10:46:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62348)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 10:46:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 10:46:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 10:46:35 AM	ESENT	301	Logging/Recovery	Windows (7100) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/21/2018 10:46:35 AM	ESENT	300	Logging/Recovery	Windows (7100) Windows: The database engine is initiating recovery steps.
Information	6/21/2018 10:46:35 AM	ESENT	102	General	Windows (7100) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/21/2018 10:46:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 10:46:30 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8929.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/21/2018 10:46:18 AM	MTAService.OnSessionChange	0	None	10:46:18 AM - Session change notice received: SessionLock Session ID: 1
Error	6/21/2018 10:46:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 10:45:40 AM	Service1	0	None	Service started successfully.
Error	6/21/2018 10:45:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 10:45:20 AM	MTAService	0	None	Service started successfully.
Error	6/21/2018 10:45:18 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/21/2018 10:45:16 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/21/2018 10:45:03 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/21/2018 10:45:03 AM	PostgreSQL	0	None	Server started and accepting connections

Information	6/21/2018 10:45:02 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/21/2018 10:44:45 AM	PostgreSQL	0	None	"2018-06-21 10:44:45 IST LOG:  redirecting log output to logging collector process
2018-06-21 10:44:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/21/2018 10:44:45 AM	MTAService.OnStart	0	None	10:44:44 AM - User is already logged in : 212558710
Information	6/21/2018 10:44:43 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/21/2018 10:44:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/21/2018 10:44:39 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/21/2018 10:44:39 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/21/2018 10:44:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/21/2018 10:44:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/21/2018 10:44:38 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/21/2018 10:44:28 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:28 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/21/2018 10:44:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/21/2018 10:44:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/21/2018 10:44:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/21/2018 10:44:27 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/21/2018 10:44:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/21/2018 10:44:27 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:26 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/21/2018 10:44:25 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/21/2018 10:44:25 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/21/2018 10:44:25 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/21/2018 10:44:21 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:21 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:21 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/21/2018 10:44:21 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/21/2018 10:44:20 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:20 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/21/2018 10:44:20 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/21/2018 10:44:20 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3604 at 6/20/2018 6:18:30 PM (local) 6/20/2018 12:48:30 PM (UTC). This is an informational message only; no user action is required.
Information	6/21/2018 10:44:20 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/21/2018 10:44:19 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/21/2018 10:44:18 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/21/2018 10:44:18 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/21/2018 10:44:18 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/21/2018 10:44:18 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3924.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/21/2018 10:44:17 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/21/2018 10:43:29 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/21/2018 10:43:20 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/21/2018 10:43:05 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/21/2018 10:43:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/21/2018 10:43:05 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	6/21/2018 10:18:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 10:17:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 34f8c3d4-750e-11e8-88ee-204747d02364
Report Status: 0"
Information	6/21/2018 9:30:34 AM	MTAService.OnSessionChange	0	None	9:30:34 AM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 9:22:58 AM	MTAService.OnSessionChange	0	None	9:22:58 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/21/2018 8:42:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 8:39:27 AM	MTAService.OnSessionChange	0	None	8:39:27 AM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 8:36:44 AM	MTAService.OnSessionChange	0	None	8:36:44 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/21/2018 8:31:49 AM	MTAService.OnSessionChange	0	None	8:31:49 AM - Session change notice received: SessionLock Session ID: 1
Information	6/21/2018 8:28:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 8:28:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 8:28:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 8:26:01 AM	MTAService.OnSessionChange	0	None	8:26:01 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/21/2018 6:57:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 6:52:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/21/2018 5:25:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 5:17:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b521396-74e4-11e8-88ee-204747d02364
Report Status: 0"
Information	6/21/2018 4:28:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 4:28:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:02Z. Reason: GVLK.
Information	6/21/2018 4:23:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 4:23:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 4:23:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 4:23:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 3:32:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 3:32:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:05Z. Reason: GVLK.
Warning	6/21/2018 3:29:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 3:27:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 3:27:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 3:27:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 3:27:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/21/2018 3:24:26 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/21/2018 3:17:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 3:17:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:17Z. Reason: GVLK.
Error	6/21/2018 3:12:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/21/2018 3:12:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/21/2018 3:12:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 3:12:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 3:12:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/21/2018 2:51:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/21/2018 2:24:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62855)(?)])(1 )(2 )]

"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62855)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/21/2018 2:19:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/21/2018 1:45:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/21/2018 12:17:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61b14059-74ba-11e8-88ee-204747d02364
Report Status: 0"
Information	6/21/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	6/21/2018 12:02:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 10:51:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/20/2018 10:26:45 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/20/2018 10:24:42 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/20/2018 10:12:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	6/20/2018 10:10:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 9:27:34 PM	MTAService.OnSessionChange	0	None	9:27:34 PM - Session change notice received: SessionLock Session ID: 1
Information	6/20/2018 8:43:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 8:38:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 8:38:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63196)(?)])(1 )(2 )]

"
Information	6/20/2018 8:38:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63196)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 8:38:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 8:38:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 8:38:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/20/2018 8:24:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 7:58:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 7:58:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:20Z. Reason: GVLK.
Information	6/20/2018 7:53:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 7:53:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 7:53:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 7:53:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 7:28:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 7:28:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:20Z. Reason: GVLK.
Information	6/20/2018 7:23:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 7:23:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 7:23:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 7:23:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 7:17:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 780caed2-7490-11e8-88ee-204747d02364
Report Status: 0"
Information	6/20/2018 7:07:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 7:02:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 7:02:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63293)(?)])(1 )(2 )]

"
Information	6/20/2018 7:02:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63293)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 7:02:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 7:02:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 7:02:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:58:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 6:58:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:28Z. Reason: GVLK.
Information	6/20/2018 6:56:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 6:54:19 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 35, Deleted: 0, Modified: 0, Compared: 24335, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/20/2018 6:53:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 6:53:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 6:53:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 6:53:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:51:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/20/2018 6:51:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/20/2018 6:51:37 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	6/20/2018 6:51:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/20/2018 6:50:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/20/2018 6:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 6:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63305)(?)])(1 )(2 )]

"
Information	6/20/2018 6:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63305)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 6:50:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 6:50:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 6:50:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:44:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 6:43:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 6:43:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:21Z. Reason: GVLK.
Warning	6/20/2018 6:42:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 6:40:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	6/20/2018 6:39:00 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/20/2018 6:38:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 6:38:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63316)(?)])(1 )(2 )]

"
Information	6/20/2018 6:38:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63316)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 6:38:48 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/20/2018 6:38:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 6:38:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 6:38:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:38:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 6:38:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 6:38:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 6:38:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:38:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/20/2018 6:38:03 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/20/2018 6:38:03 PM	MTAService.OnSessionChange	0	None	6:38:03 PM - Logon : 212558710
Information	6/20/2018 6:38:03 PM	MTAService.OnSessionChange	0	None	6:38:03 PM - Session change notice received: SessionLogon Session ID: 1
Information	6/20/2018 6:38:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/20/2018 6:38:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/20/2018 6:26:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 6:26:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:52Z. Reason: GVLK.
Information	6/20/2018 6:23:16 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	6/20/2018 6:23:15 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	6/20/2018 6:21:06 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/20/2018 6:21:02 PM	MTAService.OnSessionChange	0	None	6:21:02 PM - Session change notice received: ConsoleConnect Session ID: 1
Information	6/20/2018 6:21:02 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	6/20/2018 6:21:02 PM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 103 second(s) to handle the notification event (CreateSession).
Information	6/20/2018 6:21:01 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 6:21:00 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	6/20/2018 6:20:18 PM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	6/20/2018 6:19:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 6:19:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 6:19:18 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	6/20/2018 6:19:17 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	6/20/2018 6:19:17 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	6/20/2018 6:19:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 6:19:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 6:19:13 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/20/2018 6:19:09 PM	ESENT	302	Logging/Recovery	Windows (6168) Windows: The database engine has successfully completed recovery steps.
Information	6/20/2018 6:19:07 PM	ESENT	301	Logging/Recovery	Windows (6168) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/20/2018 6:19:07 PM	ESENT	300	Logging/Recovery	Windows (6168) Windows: The database engine is initiating recovery steps.
Information	6/20/2018 6:19:07 PM	ESENT	102	General	Windows (6168) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/20/2018 6:18:59 PM	Service1	0	None	Service started successfully.
Error	6/20/2018 6:18:52 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/20/2018 6:18:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8929.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/20/2018 6:18:50 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/20/2018 6:18:45 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/20/2018 6:18:44 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/20/2018 6:18:44 PM	PostgreSQL	0	None	"2018-06-20 18:18:44 IST LOG:  redirecting log output to logging collector process
2018-06-20 18:18:44 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/20/2018 6:18:43 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/20/2018 6:18:42 PM	MTAService	0	None	Service started successfully.
Information	6/20/2018 6:18:42 PM	MTAService.OnStart	0	None	6:18:41 PM - Waiting for user to Logon
Information	6/20/2018 6:18:41 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/20/2018 6:18:40 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/20/2018 6:18:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/20/2018 6:18:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/20/2018 6:18:37 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:37 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/20/2018 6:18:37 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/20/2018 6:18:36 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/20/2018 6:18:36 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3960 at 6/20/2018 6:12:56 PM (local) 6/20/2018 12:42:56 PM (UTC). This is an informational message only; no user action is required.
Information	6/20/2018 6:18:30 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/20/2018 6:18:29 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/20/2018 6:18:28 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/20/2018 6:18:28 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/20/2018 6:18:28 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/20/2018 6:18:28 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3604.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/20/2018 6:18:17 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/20/2018 6:18:02 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/20/2018 6:17:45 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 6:17:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: Wlansvc
P2: wlansvc.dll
P3: 6.1.7601.23915
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1679a51d-7488-11e8-88ee-204747d02364
Report Status: 0"
Information	6/20/2018 6:17:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: EacService
P2: jTnccService.exe""
P3: 0.0.0.0
P4: 10
P5: 3
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1679a51c-7488-11e8-88ee-204747d02364
Report Status: 0"
Information	6/20/2018 6:17:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: dot3svc
P2: dot3svc.dll
P3: 6.1.7601.17514
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1679a51b-7488-11e8-88ee-204747d02364
Report Status: 0"
Information	6/20/2018 6:15:57 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/20/2018 6:15:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/20/2018 6:15:58 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/20/2018 6:13:02 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	6/20/2018 6:12:56 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	6/20/2018 6:12:54 PM	Microsoft-Windows-Winlogon	6004	None	The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Information	6/20/2018 6:12:12 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/20/2018 6:12:02 PM	ESENT	302	Logging/Recovery	Windows (7084) Windows: The database engine has successfully completed recovery steps.
Information	6/20/2018 6:11:58 PM	ESENT	301	Logging/Recovery	Windows (7084) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/20/2018 6:11:58 PM	ESENT	300	Logging/Recovery	Windows (7084) Windows: The database engine is initiating recovery steps.
Information	6/20/2018 6:11:58 PM	ESENT	102	General	Windows (7084) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/20/2018 6:11:46 PM	Service1	0	None	Service started successfully.
Error	6/20/2018 6:11:38 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/20/2018 6:11:38 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/20/2018 6:11:36 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8929.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/20/2018 6:11:35 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/20/2018 6:11:22 PM	PostgreSQL	0	None	"2018-06-20 18:11:22 IST LOG:  redirecting log output to logging collector process
2018-06-20 18:11:22 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/20/2018 6:11:22 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/20/2018 6:11:21 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/20/2018 6:11:19 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/20/2018 6:11:18 PM	MTAService	0	None	Service started successfully.
Information	6/20/2018 6:11:18 PM	MTAService.OnStart	0	None	6:11:18 PM - Waiting for user to Logon
Information	6/20/2018 6:11:17 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/20/2018 6:11:15 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/20/2018 6:11:15 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:15 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/20/2018 6:11:15 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/20/2018 6:11:15 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/20/2018 6:11:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/20/2018 6:11:14 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:13 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/20/2018 6:11:12 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/20/2018 6:11:12 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/20/2018 6:11:12 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/20/2018 6:11:07 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3808 at 6/20/2018 1:49:17 PM (local) 6/20/2018 8:19:17 AM (UTC). This is an informational message only; no user action is required.
Information	6/20/2018 6:11:05 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/20/2018 6:11:05 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/20/2018 6:11:05 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/20/2018 6:11:05 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/20/2018 6:11:05 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3960.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/20/2018 6:11:04 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/20/2018 6:10:22 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/20/2018 6:10:14 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 6:09:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/20/2018 6:08:49 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/20/2018 6:08:27 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Warning	6/20/2018 4:15:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 3:51:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 3:51:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:05Z. Reason: GVLK.
Information	6/20/2018 3:46:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 3:46:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 3:46:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 3:46:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 3:34:36 PM	MTAService.OnSessionChange	0	None	3:34:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/20/2018 3:21:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 3:21:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:05Z. Reason: GVLK.
Information	6/20/2018 3:16:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 3:16:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 3:16:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 3:16:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 3:12:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 3:12:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:54Z. Reason: GVLK.
Information	6/20/2018 3:07:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 3:07:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 3:07:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 3:07:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 2:54:24 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/20/2018 2:53:41 PM	MTAService.OnSessionChange	0	None	2:53:41 PM - Session change notice received: SessionLock Session ID: 1
Information	6/20/2018 2:51:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 2:51:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:05Z. Reason: GVLK.
Information	6/20/2018 2:42:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 2:42:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 2:42:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 2:42:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 2:37:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 2:36:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 2:36:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:05Z. Reason: GVLK.
Information	6/20/2018 2:34:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8929.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Warning	6/20/2018 2:33:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 2:32:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 2:32:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63563)(?)])(1 )(2 )]

"
Information	6/20/2018 2:32:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63563)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 2:31:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 2:31:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63564)(?)])(1 )(2 )]

"
Information	6/20/2018 2:31:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63564)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	6/20/2018 2:31:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/20/2018 2:31:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 2:31:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 2:31:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 2:31:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 2:31:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 2:31:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 2:31:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 2:30:48 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/20/2018 2:30:48 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/20/2018 2:30:47 PM	MTAService.OnSessionChange	0	None	2:30:47 PM - Logon : 212558710
Information	6/20/2018 2:30:47 PM	MTAService.OnSessionChange	0	None	2:30:47 PM - Session change notice received: SessionLogon Session ID: 1
Information	6/20/2018 2:30:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/20/2018 2:30:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/20/2018 2:10:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 2:10:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:36Z. Reason: GVLK.
Information	6/20/2018 2:05:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 2:05:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 2:05:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 2:05:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/20/2018 2:04:13 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/20/2018 1:58:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 1:58:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:57Z. Reason: GVLK.
Information	6/20/2018 1:52:11 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/20/2018 1:52:05 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 1:52:04 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 1:52:03 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	6/20/2018 1:51:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/20/2018 1:51:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 1:51:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 1:51:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 1:51:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 1:50:21 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/20/2018 1:50:18 PM	ESENT	302	Logging/Recovery	Windows (6668) Windows: The database engine has successfully completed recovery steps.
Information	6/20/2018 1:50:17 PM	ESENT	301	Logging/Recovery	Windows (6668) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/20/2018 1:50:13 PM	ESENT	301	Logging/Recovery	Windows (6668) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008E5.log.
Information	6/20/2018 1:50:13 PM	ESENT	300	Logging/Recovery	Windows (6668) Windows: The database engine is initiating recovery steps.
Information	6/20/2018 1:50:12 PM	ESENT	102	General	Windows (6668) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/20/2018 1:50:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8928.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/20/2018 1:49:48 PM	Service1	0	None	Service started successfully.
Error	6/20/2018 1:49:45 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/20/2018 1:49:45 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/20/2018 1:49:39 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/20/2018 1:49:35 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/20/2018 1:49:34 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/20/2018 1:49:33 PM	PostgreSQL	0	None	"2018-06-20 13:49:33 IST LOG:  redirecting log output to logging collector process
2018-06-20 13:49:33 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/20/2018 1:49:32 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/20/2018 1:49:30 PM	MTAService	0	None	Service started successfully.
Information	6/20/2018 1:49:30 PM	MTAService.OnStart	0	None	1:49:30 PM - Waiting for user to Logon
Information	6/20/2018 1:49:27 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/20/2018 1:49:22 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:22 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/20/2018 1:49:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/20/2018 1:49:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/20/2018 1:49:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/20/2018 1:49:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/20/2018 1:49:20 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:20 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/20/2018 1:49:20 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/20/2018 1:49:20 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/20/2018 1:49:20 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/20/2018 1:49:18 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:18 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/20/2018 1:49:17 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3820 at 6/19/2018 4:20:38 PM (local) 6/19/2018 10:50:38 AM (UTC). This is an informational message only; no user action is required.
Information	6/20/2018 1:49:14 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/20/2018 1:49:14 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/20/2018 1:49:14 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/20/2018 1:49:14 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/20/2018 1:49:14 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3808.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/20/2018 1:49:13 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/20/2018 1:48:42 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/20/2018 1:48:35 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/20/2018 1:48:23 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/20/2018 1:48:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/20/2018 1:48:23 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/20/2018 11:40:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/20/2018 11:40:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	6/20/2018 10:42:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 9:28:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/20/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:55Z. Reason: GVLK.
Information	6/20/2018 9:23:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/20/2018 9:23:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63872)(?)])(1 )(2 )]

"
Information	6/20/2018 9:23:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63872)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 9:23:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/20/2018 9:23:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 9:22:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 9:18:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/20/2018 9:18:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/20/2018 9:18:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/20/2018 9:18:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/20/2018 9:17:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a6093776-743c-11e8-ac68-204747d02364
Report Status: 0"
Information	6/20/2018 9:09:32 AM	MTAService.OnSessionChange	0	None	9:09:32 AM - Session change notice received: SessionLock Session ID: 1
Warning	6/20/2018 9:09:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/20/2018 9:08:13 AM	MTAService.OnSessionChange	0	None	9:08:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/20/2018 9:07:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/19/2018 7:24:12 PM	MTAService.OnSessionChange	0	None	7:24:12 PM - Session change notice received: SessionLock Session ID: 1
Information	6/19/2018 7:12:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0cfe506-73c6-11e8-ac68-204747d02364
Report Status: 0"
Information	6/19/2018 6:46:57 PM	MTAService.OnSessionChange	0	None	6:46:57 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/19/2018 6:34:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 5:51:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 5:51:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:32Z. Reason: GVLK.
Information	6/19/2018 5:49:01 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/19/2018 5:46:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 5:46:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 5:46:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 5:46:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 5:21:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 5:21:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:31Z. Reason: GVLK.
Information	6/19/2018 5:16:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 5:16:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 5:16:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 5:16:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 5:04:30 PM	MTAService.OnSessionChange	0	None	5:04:30 PM - Session change notice received: SessionLock Session ID: 1
Information	6/19/2018 4:51:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 4:51:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 4:51:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:31Z. Reason: GVLK.
Information	6/19/2018 4:48:32 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 5, Deleted: 0, Modified: 5, Compared: 24294, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/19/2018 4:46:59 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 421

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 15

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	6/19/2018 4:46:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/19/2018 4:46:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 4:46:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64868)(?)])(1 )(2 )]

"
Information	6/19/2018 4:46:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64868)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 4:46:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 4:46:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 4:46:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 4:46:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 4:46:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/19/2018 4:46:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 4:46:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 4:45:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 4:45:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:38Z. Reason: GVLK.
Information	6/19/2018 4:40:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 4:40:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 4:40:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 4:40:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/19/2018 4:38:43 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	6/19/2018 4:37:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 4:37:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 4:36:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 4:36:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:22:30Z. Reason: GVLK.
Error	6/19/2018 4:32:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/19/2018 4:32:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 4:32:04 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/19/2018 4:32:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64883)(?)])(1 )(2 )]

"
Information	6/19/2018 4:32:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64883)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 4:32:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/19/2018 4:32:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 4:32:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 4:31:13 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/19/2018 4:31:13 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/19/2018 4:31:13 PM	MTAService.OnSessionChange	0	None	4:31:13 PM - Logon : 212558710
Information	6/19/2018 4:31:13 PM	MTAService.OnSessionChange	0	None	4:31:13 PM - Session change notice received: SessionLogon Session ID: 1
Information	6/19/2018 4:31:13 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/19/2018 4:31:13 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	6/19/2018 4:27:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/19/2018 4:23:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 4:23:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 4:23:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 4:23:29 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/19/2018 4:23:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 4:23:25 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/19/2018 4:23:24 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/19/2018 4:23:23 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/19/2018 4:21:37 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/19/2018 4:21:33 PM	ESENT	302	Logging/Recovery	Windows (7132) Windows: The database engine has successfully completed recovery steps.
Information	6/19/2018 4:21:33 PM	ESENT	301	Logging/Recovery	Windows (7132) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/19/2018 4:21:33 PM	ESENT	300	Logging/Recovery	Windows (7132) Windows: The database engine is initiating recovery steps.
Information	6/19/2018 4:21:33 PM	ESENT	102	General	Windows (7132) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/19/2018 4:21:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8928.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/19/2018 4:21:08 PM	Service1	0	None	Service started successfully.
Error	6/19/2018 4:21:04 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/19/2018 4:21:04 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/19/2018 4:21:01 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/19/2018 4:20:57 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/19/2018 4:20:56 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/19/2018 4:20:56 PM	PostgreSQL	0	None	"2018-06-19 16:20:56 IST LOG:  redirecting log output to logging collector process
2018-06-19 16:20:56 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/19/2018 4:20:55 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/19/2018 4:20:54 PM	MTAService	0	None	Service started successfully.
Information	6/19/2018 4:20:54 PM	MTAService.OnStart	0	None	4:20:54 PM - Waiting for user to Logon
Information	6/19/2018 4:20:51 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/19/2018 4:20:44 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:44 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/19/2018 4:20:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:42 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/19/2018 4:20:41 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/19/2018 4:20:41 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/19/2018 4:20:41 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/19/2018 4:20:39 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:39 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:39 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/19/2018 4:20:38 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3820 at 6/18/2018 9:17:53 AM (local) 6/18/2018 3:47:53 AM (UTC). This is an informational message only; no user action is required.
Information	6/19/2018 4:20:36 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/19/2018 4:20:36 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/19/2018 4:20:36 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/19/2018 4:20:36 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/19/2018 4:20:36 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3820.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/19/2018 4:20:35 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/19/2018 4:20:06 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/19/2018 4:19:59 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/19/2018 4:19:45 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/19/2018 4:19:45 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/19/2018 4:19:45 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	6/19/2018 4:10:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 4:02:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/19/2018 3:59:11 PM	MTAService.OnSessionChange	0	None	3:59:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/19/2018 3:23:29 PM	MTAService.OnSessionChange	0	None	3:23:29 PM - Session change notice received: SessionLock Session ID: 1
Information	6/19/2018 2:34:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 2:29:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 2:29:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65005)(?)])(1 )(2 )]

"
Information	6/19/2018 2:29:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65005)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 2:29:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/19/2018 2:29:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 2:29:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 2:19:21 PM	MTAService.OnSessionChange	0	None	2:19:21 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/19/2018 2:17:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 2:12:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b735d88d-739c-11e8-a495-cd3fa1c4a6ab
Report Status: 0"
Warning	6/19/2018 12:43:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 12:32:07 PM	MTAService.OnSessionChange	0	None	12:32:07 PM - Session change notice received: SessionLock Session ID: 1
Information	6/19/2018 12:23:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8928.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/19/2018 12:07:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 12:02:39 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 390

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	6/19/2018 12:02:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/19/2018 12:02:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 12:02:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65153)(?)])(1 )(2 )]

"
Information	6/19/2018 12:02:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65153)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	6/19/2018 10:53:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 10:12:49 AM	MTAService.OnSessionChange	0	None	10:12:49 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/19/2018 10:05:11 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/19/2018 9:32:16 AM	MTAService.OnSessionChange	0	None	9:32:16 AM - Session change notice received: SessionLock Session ID: 1
Information	6/19/2018 9:25:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/19/2018 9:24:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/19/2018 9:24:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/19/2018 9:21:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/19/2018 9:21:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:38Z. Reason: GVLK.
Information	6/19/2018 9:16:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 9:16:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65319)(?)])(1 )(2 )]

"
Information	6/19/2018 9:16:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65319)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 9:13:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/19/2018 9:13:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 9:13:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/19/2018 9:13:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/19/2018 9:12:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccf6d4c7-7372-11e8-a495-cd3fa1c4a6ab
Report Status: 0"
Information	6/19/2018 9:09:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/19/2018 9:09:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65326)(?)])(1 )(2 )]

"
Information	6/19/2018 9:09:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65326)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/19/2018 9:05:51 AM	MTAService.OnSessionChange	0	None	9:05:51 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/19/2018 9:04:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/19/2018 9:02:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/19/2018 9:02:53 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/19/2018 9:02:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/18/2018 7:03:18 PM	MTAService.OnSessionChange	0	None	7:03:18 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/18/2018 6:37:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/18/2018 6:24:09 PM	MTAService.OnSessionChange	0	None	6:24:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/18/2018 6:14:54 PM	MTAService.OnSessionChange	0	None	6:14:54 PM - Session change notice received: SessionLock Session ID: 1
Information	6/18/2018 5:56:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/18/2018 5:56:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/18/2018 5:53:52 PM	MTAService.OnSessionChange	0	None	5:53:52 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/18/2018 5:04:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/18/2018 3:24:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/18/2018 3:22:17 PM	MTAService.OnSessionChange	0	None	3:22:17 PM - Session change notice received: SessionLock Session ID: 1
Information	6/18/2018 3:07:35 PM	MTAService.OnSessionChange	0	None	3:07:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/18/2018 2:59:43 PM	MTAService.OnSessionChange	0	None	2:59:43 PM - Session change notice received: SessionLock Session ID: 1
Information	6/18/2018 2:21:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb903c14-72d4-11e8-a495-204747d02364
Report Status: 0"
Information	6/18/2018 2:13:33 PM	MTAService.OnSessionChange	0	None	2:13:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/18/2018 1:56:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/18/2018 1:46:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/18/2018 1:31:31 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/18/2018 12:59:15 PM	MTAService.OnSessionChange	0	None	12:59:15 PM - Session change notice received: SessionLock Session ID: 1
Information	6/18/2018 12:39:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/18/2018 12:39:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66556)(?)])(1 )(2 )]

"
Information	6/18/2018 12:39:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66556)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 11:50:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 11:50:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:33Z. Reason: GVLK.
Warning	6/18/2018 11:49:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/18/2018 11:45:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/18/2018 11:45:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 11:45:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 11:45:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 11:30:33 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/18/2018 11:30:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	6/18/2018 10:16:08 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8927.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/18/2018 9:58:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 9:58:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:21:32Z. Reason: GVLK.
Information	6/18/2018 9:58:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 12830, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/18/2018 9:56:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/18/2018 9:56:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66718)(?)])(1 )(2 )]

"
Information	6/18/2018 9:56:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66718)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:56:35 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	6/18/2018 9:56:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/18/2018 9:56:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2270.
Information	6/18/2018 9:56:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/18/2018 9:56:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66718)(?)])(1 )(2 )]

"
Information	6/18/2018 9:56:30 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/18/2018 9:56:30 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109918  Grace type=8.
Information	6/18/2018 9:56:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=9488b676-2139-4c19-a51c-15db89741ebf"
Information	6/18/2018 9:56:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=32dc25ae-ce8d-4993-9377-735e2f3dd277"
Information	6/18/2018 9:56:29 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/18/2018 9:56:29 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 32

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 405

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 500

Information	6/18/2018 9:56:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/18/2018 9:56:08 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/18/2018 9:56:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/18/2018 9:56:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20639)(?)])(1 )(2 )]

"
Information	6/18/2018 9:56:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20639)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	6/18/2018 9:53:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/18/2018 9:53:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/18/2018 9:53:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20642)(?)])(1 )(2 )]

"
Information	6/18/2018 9:53:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20642)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:53:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/18/2018 9:53:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:53:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 9:52:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:52:32 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/06/18 04:22"
Information	6/18/2018 9:52:31 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/06/18 04:22, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	6/18/2018 9:52:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/18/2018 9:52:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:52:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:52:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 9:52:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 9:52:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T04:16:15Z. Reason: GVLK.
Information	6/18/2018 9:50:08 AM	MTAService.OnSessionChange	0	None	9:50:08 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/18/2018 9:47:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:47:15 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	6/18/2018 9:47:15 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/06/18 04:17, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	6/18/2018 9:42:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/18/2018 9:42:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:42:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:42:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/18/2018 9:40:50 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/18/2018 9:37:38 AM	MTAService.OnSessionChange	0	None	9:37:38 AM - Session change notice received: SessionLock Session ID: 1
Information	6/18/2018 9:30:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 9:30:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-25T03:54:27Z. Reason: GVLK.
Information	6/18/2018 9:30:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 9:25:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:25:27 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	6/18/2018 9:25:27 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/06/18 03:55, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	6/18/2018 9:25:03 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9788.
Information	6/18/2018 9:25:03 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8431.2270. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/18/2018 9:25:03 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	6/18/2018 9:25:02 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/18/2018 9:25:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20670)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:25:00 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	6/18/2018 9:25:00 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/18/2018 9:24:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:24:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/18/2018 9:24:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:24:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 9:24:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/18/2018 9:24:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2270. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/18/2018 9:24:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	6/18/2018 9:24:42 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:42 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2270. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/18/2018 9:24:42 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	6/18/2018 9:24:39 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/18/2018 9:24:39 AM	ESENT	102	General	Windows (5972) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/18/2018 9:24:39 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:39 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2270. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/18/2018 9:24:39 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	6/18/2018 9:24:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:22 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	6/18/2018 9:24:22 AM	ESENT	103	General	Windows (7988) Windows: The database engine stopped the instance (0).
Information	6/18/2018 9:24:22 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:24:22 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2270. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/18/2018 9:24:22 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	6/18/2018 9:23:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9788.
Information	6/18/2018 9:23:19 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/18/2018 9:23:19 AM	ESENT	102	General	Windows (7988) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	6/18/2018 9:23:15 AM	ESENT	103	General	Windows (7048) Windows: The database engine stopped the instance (0).
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:14 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:14 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/18/2018 9:23:14 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:14 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/18/2018 9:23:14 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	6/18/2018 9:22:30 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {8DF8BC42-25DF-4F78-906F-2CC535819A4D}
Error	6/18/2018 9:22:30 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {8DF8BC42-25DF-4F78-906F-2CC535819A4D}
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	6/18/2018 9:22:22 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	6/18/2018 9:22:21 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Error	6/18/2018 9:22:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/18/2018 9:22:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/18/2018 9:22:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/18/2018 9:22:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20673)(?)])(1 )(2 )]

"
Information	6/18/2018 9:22:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20673)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:22:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/18/2018 9:22:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:22:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 9:21:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎06‎-‎18T03:51:34.417705100Z.
Error	6/18/2018 9:21:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/18/2018 9:20:36 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/18/2018 9:20:29 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/18/2018 9:20:26 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/18/2018 9:20:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/18/2018 9:20:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/18/2018 9:20:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/18/2018 9:20:24 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/18/2018 9:20:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/18/2018 9:19:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/18/2018 9:19:52 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/18/2018 9:19:52 AM	MTAService.OnSessionChange	0	None	9:19:52 AM - Logon : 212558710
Information	6/18/2018 9:19:52 AM	MTAService.OnSessionChange	0	None	9:19:52 AM - Session change notice received: SessionLogon Session ID: 1
Information	6/18/2018 9:19:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/18/2018 9:19:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/18/2018 9:19:21 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8923.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/18/2018 9:18:44 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/18/2018 9:18:34 AM	ESENT	302	Logging/Recovery	Windows (7048) Windows: The database engine has successfully completed recovery steps.
Information	6/18/2018 9:18:33 AM	ESENT	301	Logging/Recovery	Windows (7048) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/18/2018 9:18:26 AM	ESENT	301	Logging/Recovery	Windows (7048) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008D3.log.
Information	6/18/2018 9:18:26 AM	ESENT	300	Logging/Recovery	Windows (7048) Windows: The database engine is initiating recovery steps.
Information	6/18/2018 9:18:26 AM	ESENT	102	General	Windows (7048) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/18/2018 9:18:14 AM	Service1	0	None	Service started successfully.
Error	6/18/2018 9:18:09 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/18/2018 9:18:09 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/18/2018 9:18:08 AM	PostgreSQL	0	None	Server started and accepting connections

Information	6/18/2018 9:18:03 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/18/2018 9:18:02 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/18/2018 9:18:02 AM	PostgreSQL	0	None	"2018-06-18 09:18:02 IST LOG:  redirecting log output to logging collector process
2018-06-18 09:18:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/18/2018 9:18:00 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/18/2018 9:17:59 AM	MTAService	0	None	Service started successfully.
Information	6/18/2018 9:17:59 AM	MTAService.OnStart	0	None	9:17:58 AM - Waiting for user to Logon
Information	6/18/2018 9:17:57 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:56 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/18/2018 9:17:55 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4104 at 6/17/2018 2:36:05 PM (local) 6/17/2018 9:06:05 AM (UTC). This is an informational message only; no user action is required.
Information	6/18/2018 9:17:53 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/18/2018 9:17:52 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/18/2018 9:17:52 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/18/2018 9:17:52 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/18/2018 9:17:52 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/18/2018 9:17:52 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3820.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/18/2018 9:17:51 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/18/2018 9:17:32 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/18/2018 9:17:28 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/18/2018 9:17:20 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/18/2018 9:17:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/18/2018 9:17:20 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/17/2018 5:32:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎06‎-‎17T12:02:10.248714700Z.
Information	6/17/2018 5:29:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 5:29:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:49Z. Reason: GVLK.
Information	6/17/2018 5:27:47 PM	MTAService.OnSessionChange	0	None	5:27:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/17/2018 5:17:06 PM	MTAService.OnSessionChange	0	None	5:17:06 PM - Session change notice received: SessionLock Session ID: 1
Information	6/17/2018 5:14:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/17/2018 5:14:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 5:14:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 5:14:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 4:46:32 PM	MTAService.OnSessionChange	0	None	4:46:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/17/2018 4:05:44 PM	MTAService.OnSessionChange	0	None	4:05:44 PM - Session change notice received: SessionLock Session ID: 1
Information	6/17/2018 3:57:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 3:57:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:53Z. Reason: GVLK.
Information	6/17/2018 3:52:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/17/2018 3:52:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 3:52:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 3:52:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 3:52:49 PM	MTAService.OnSessionChange	0	None	3:52:49 PM - Session change notice received: SessionUnlock Session ID: 1
Error	6/17/2018 3:52:37 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x268c
Faulting application start time: 0x01d4061b8324c79f
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: 5b16d77c-7218-11e8-8876-204747d02364"
Error	6/17/2018 3:15:41 PM	RasClient	20227	None	CoId={67998425-88C6-48EA-B6C7-956E9A64545D}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	6/17/2018 3:15:41 PM	RasClient	20221	None	CoId={67998425-88C6-48EA-B6C7-956E9A64545D}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	6/17/2018 3:15:41 PM	RasClient	20227	None	CoId={22DB90E8-F567-4831-B3E3-E7B2D3AE6C4E}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	6/17/2018 3:15:41 PM	RasClient	20221	None	CoId={22DB90E8-F567-4831-B3E3-E7B2D3AE6C4E}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	6/17/2018 3:15:39 PM	MTAService.OnSessionChange	0	None	3:15:39 PM - Session change notice received: SessionLock Session ID: 1
Information	6/17/2018 3:15:34 PM	RasClient	20226	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	6/17/2018 2:57:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 2:57:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:05Z. Reason: GVLK.
Information	6/17/2018 2:54:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 2:52:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/17/2018 2:52:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:52:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 2:52:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 2:51:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 2:51:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:23Z. Reason: GVLK.
Information	6/17/2018 2:48:51 PM	RasClient	20225	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.249.91
TunnelIpv6Address = None
Dial-in User = .
Error	6/17/2018 2:48:49 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {43DBF125-28F2-42EA-9086-BC19354A46AB}
Information	6/17/2018 2:48:48 PM	RasClient	20224	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	6/17/2018 2:48:48 PM	RasClient	20223	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	6/17/2018 2:48:48 PM	RasClient	20222	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	6/17/2018 2:48:48 PM	RasClient	20221	None	CoId={2DDDF602-3131-4EFA-B61D-60A425B1CBFE}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	6/17/2018 2:48:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/17/2018 2:48:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21787)(?)])(1 )(2 )]

"
Information	6/17/2018 2:48:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21787)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:47:48 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 437

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 437

Information	6/17/2018 2:47:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/17/2018 2:46:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/17/2018 2:46:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:46:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 2:46:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 2:45:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 08a17608-720f-11e8-8876-204747d02364
Report Status: 0"
Information	6/17/2018 2:45:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/17/2018 2:45:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:35Z. Reason: GVLK.
Information	6/17/2018 2:40:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/17/2018 2:40:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21794)(?)])(1 )(2 )]

"
Information	6/17/2018 2:40:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21794)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:39:49 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/17/2018 2:38:32 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	6/17/2018 2:38:32 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {32643D28-5868-494B-8C99-EBEBE39C3B86}
Error	6/17/2018 2:38:32 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {32643D28-5868-494B-8C99-EBEBE39C3B86}
Information	6/17/2018 2:38:25 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/17/2018 2:38:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/17/2018 2:38:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:38:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 2:38:23 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/17/2018 2:38:21 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/17/2018 2:38:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 2:38:05 PM	ESENT	302	Logging/Recovery	Windows (8588) Windows: The database engine has successfully completed recovery steps.
Information	6/17/2018 2:38:02 PM	ESENT	301	Logging/Recovery	Windows (8588) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/17/2018 2:37:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/17/2018 2:37:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21797)(?)])(1 )(2 )]

"
Information	6/17/2018 2:37:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21797)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/17/2018 2:37:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/17/2018 2:37:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/17/2018 2:37:51 PM	ESENT	301	Logging/Recovery	Windows (8588) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008C0.log.
Information	6/17/2018 2:37:51 PM	ESENT	300	Logging/Recovery	Windows (8588) Windows: The database engine is initiating recovery steps.
Information	6/17/2018 2:37:51 PM	ESENT	102	General	Windows (8588) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/17/2018 2:37:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/17/2018 2:37:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8923.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	6/17/2018 2:37:25 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	6/17/2018 2:37:00 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/17/2018 2:36:47 PM	Service1	0	None	Service started successfully.
Error	6/17/2018 2:36:43 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/17/2018 2:36:43 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/17/2018 2:36:40 PM	MTAService	0	None	Service started successfully.
Information	6/17/2018 2:36:31 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/17/2018 2:36:27 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/17/2018 2:36:26 PM	PostgreSQL	0	None	"2018-06-17 14:36:26 IST LOG:  redirecting log output to logging collector process
2018-06-17 14:36:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/17/2018 2:36:23 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/17/2018 2:36:21 PM	MTAService.OnStart	0	None	2:36:20 PM - User is already logged in : 212558710
Information	6/17/2018 2:36:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/17/2018 2:36:19 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/17/2018 2:36:19 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/17/2018 2:36:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/17/2018 2:36:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/17/2018 2:36:17 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/17/2018 2:36:10 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:10 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/17/2018 2:36:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/17/2018 2:36:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/17/2018 2:36:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/17/2018 2:36:09 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/17/2018 2:36:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/17/2018 2:36:09 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:08 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/17/2018 2:36:07 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/17/2018 2:36:07 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/17/2018 2:36:07 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3968 at 6/14/2018 4:16:35 PM (local) 6/14/2018 10:46:35 AM (UTC). This is an informational message only; no user action is required.
Information	6/17/2018 2:36:05 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/17/2018 2:36:02 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/17/2018 2:36:02 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/17/2018 2:36:02 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/17/2018 2:36:02 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/17/2018 2:36:02 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4104.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/17/2018 2:36:01 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/17/2018 2:35:29 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/17/2018 2:35:21 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/17/2018 2:35:09 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/17/2018 2:35:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/17/2018 2:35:09 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/14/2018 4:16:52 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	6/14/2018 4:16:36 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	6/14/2018 4:16:35 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	6/14/2018 4:16:32 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1004 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2728 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2728 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1500 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	6/14/2018 4:16:33 PM	MTAService.OnSessionChange	0	None	4:16:33 PM - Logoff
Information	6/14/2018 4:16:33 PM	MTAService.OnSessionChange	0	None	4:16:32 PM - Session change notice received: SessionLogoff Session ID: 1
Information	6/14/2018 4:16:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	6/14/2018 4:16:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	6/14/2018 4:16:31 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	6/14/2018 4:16:22 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	6/14/2018 4:07:59 PM	MTAService.OnSessionChange	0	None	4:07:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/14/2018 3:25:47 PM	MTAService.OnSessionChange	0	None	3:25:47 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/14/2018 2:32:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 2:29:28 PM	MTAService.OnSessionChange	0	None	2:29:28 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/14/2018 2:08:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 2:07:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 1:44:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 1:44:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:56Z. Reason: GVLK.
Information	6/14/2018 1:39:56 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	6/14/2018 1:39:56 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	6/14/2018 1:39:56 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	6/14/2018 1:39:56 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	6/14/2018 1:39:56 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	6/14/2018 1:39:56 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	6/14/2018 1:39:53 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	6/14/2018 1:39:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 1:39:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 1:39:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 1:39:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/14/2018 1:39:51 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	6/14/2018 1:03:12 PM	MTAService.OnSessionChange	0	None	1:03:12 PM - Session change notice received: SessionLock Session ID: 1
Information	6/14/2018 12:57:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8923.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Warning	6/14/2018 12:46:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 12:11:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 12:11:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:31Z. Reason: GVLK.
Information	6/14/2018 12:06:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 12:06:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 12:06:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 12:06:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/14/2018 11:33:21 AM	MTAService.OnSessionChange	0	None	11:33:21 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/14/2018 11:24:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ec30b1c-6f97-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/14/2018 11:14:44 AM	MTAService.OnSessionChange	0	None	11:14:44 AM - Session change notice received: SessionLock Session ID: 1
Information	6/14/2018 10:57:53 AM	MTAService.OnSessionChange	0	None	10:57:53 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/14/2018 10:55:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 10:46:44 AM	MTAService.OnSessionChange	0	None	10:46:44 AM - Session change notice received: SessionLock Session ID: 1
Information	6/14/2018 10:12:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 10:12:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:43Z. Reason: GVLK.
Information	6/14/2018 10:08:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 10:07:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 10:07:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/14/2018 10:07:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 10:07:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 10:07:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 10:07:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/14/2018 10:07:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 10:06:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 10:01:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/14/2018 10:01:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26394)(?)])(1 )(2 )]

"
Information	6/14/2018 10:01:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26394)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 10:01:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/14/2018 10:01:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 10:01:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/14/2018 10:00:51 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/14/2018 9:58:58 AM	MTAService.OnSessionChange	0	None	9:58:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/14/2018 9:34:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/14/2018 9:32:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/14/2018 9:32:07 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/14/2018 9:32:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	6/14/2018 9:26:31 AM	MTAService.OnSessionChange	0	None	9:26:31 AM - Session change notice received: SessionLock Session ID: 1
Information	6/14/2018 9:23:48 AM	MTAService.OnSessionChange	0	None	9:23:48 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/14/2018 8:55:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/14/2018 7:21:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 6:24:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 75181a06-6f6d-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/14/2018 6:08:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 6:07:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/14/2018 5:39:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 4:14:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 4:11:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 4:11:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:04Z. Reason: GVLK.
Information	6/14/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/14/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26745)(?)])(1 )(2 )]

"
Information	6/14/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26745)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/14/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 4:09:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/14/2018 4:06:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 4:06:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 4:06:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 4:06:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/14/2018 4:05:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 3:22:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 3:22:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:00Z. Reason: GVLK.
Information	6/14/2018 3:17:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 3:17:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 3:17:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 3:16:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/14/2018 3:15:15 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/14/2018 3:12:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/14/2018 3:12:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:39Z. Reason: GVLK.
Error	6/14/2018 3:07:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/14/2018 3:07:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/14/2018 3:07:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/14/2018 3:07:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/14/2018 3:07:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/14/2018 2:08:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 2:07:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 2:07:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/14/2018 1:53:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/14/2018 1:51:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/14/2018 1:24:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b7a39c2-6f43-11e8-bc3a-204747d02364
Report Status: 0"
Warning	6/14/2018 12:13:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	6/13/2018 10:30:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 10:07:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 10:06:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/13/2018 8:48:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 8:24:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a19db9fb-6f19-11e8-bc3a-204747d02364
Report Status: 0"
Warning	6/13/2018 7:10:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 6:13:24 PM	MTAService.OnSessionChange	0	None	6:13:24 PM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 6:07:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 6:06:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 6:01:52 PM	MTAService.OnSessionChange	0	None	6:01:52 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/13/2018 5:36:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 4:50:51 PM	MTAService.OnSessionChange	0	None	4:50:51 PM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 4:03:47 PM	MTAService.OnSessionChange	0	None	4:03:47 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/13/2018 3:41:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 3:24:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5edceb5-6eef-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/13/2018 2:40:02 PM	MTAService.OnSessionChange	0	None	2:40:02 PM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 2:19:29 PM	MTAService.OnSessionChange	0	None	2:19:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/13/2018 2:07:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 2:06:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 2:04:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/13/2018 2:04:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:35Z. Reason: GVLK.
Warning	6/13/2018 2:01:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 1:59:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/13/2018 1:59:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 1:59:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/13/2018 1:59:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/13/2018 12:59:00 PM	MTAService.OnSessionChange	0	None	12:59:00 PM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 12:52:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8922.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Warning	6/13/2018 12:16:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 11:12:06 AM	MTAService.OnSessionChange	0	None	11:12:06 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/13/2018 10:33:04 AM	MTAService.OnSessionChange	0	None	10:33:04 AM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 10:27:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/13/2018 10:24:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cbffa09c-6ec5-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/13/2018 10:22:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27813)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 10:22:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27813)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 10:22:17 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	6/13/2018 10:22:17 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/13/2018 10:22:16 AM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	6/13/2018 10:22:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/13/2018 10:22:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/13/2018 10:22:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/13/2018 10:18:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 10:07:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 10:06:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 10:04:17 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/13/2018 10:04:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/13/2018 9:45:10 AM	MTAService.OnSessionChange	0	None	9:45:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/13/2018 9:30:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/13/2018 9:10:56 AM	MTAService.OnSessionChange	0	None	9:10:56 AM - Session change notice received: SessionLock Session ID: 1
Information	6/13/2018 9:04:39 AM	MTAService.OnSessionChange	0	None	9:04:39 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/13/2018 8:21:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/13/2018 6:35:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 6:07:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 6:06:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 5:24:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e25ee3ed-6e9b-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/13/2018 5:12:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/13/2018 5:12:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:23Z. Reason: GVLK.
Information	6/13/2018 5:07:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/13/2018 5:07:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 5:07:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/13/2018 5:07:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/13/2018 5:05:50 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/13/2018 5:04:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/13/2018 5:04:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:02Z. Reason: GVLK.
Warning	6/13/2018 5:00:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	6/13/2018 4:59:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/13/2018 4:59:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/13/2018 4:59:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 4:59:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/13/2018 4:59:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/13/2018 4:14:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/13/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/13/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28185)(?)])(1 )(2 )]

"
Information	6/13/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/13/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/13/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/13/2018 4:09:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/13/2018 3:00:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 2:06:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 2:06:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/13/2018 1:27:51 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/13/2018 1:26:09 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	6/13/2018 1:01:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/13/2018 12:24:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f8c45bd6-6e71-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/13/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/12/2018 11:49:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 11:49:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:27Z. Reason: GVLK.
Information	6/12/2018 11:44:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/12/2018 11:44:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 11:44:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 11:44:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/12/2018 11:24:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 10:06:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/12/2018 10:06:42 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/12/2018 10:06:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/12/2018 9:52:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	6/12/2018 8:08:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 7:24:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f190d53-6e48-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/12/2018 6:25:11 PM	MTAService.OnSessionChange	0	None	6:25:11 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/12/2018 6:15:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 6:06:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/12/2018 6:01:02 PM	MTAService.OnSessionChange	0	None	6:01:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/12/2018 5:19:20 PM	MTAService.OnSessionChange	0	None	5:19:20 PM - Session change notice received: SessionLock Session ID: 1
Information	6/12/2018 4:23:21 PM	MTAService.OnSessionChange	0	None	4:23:21 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/12/2018 4:20:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 3:25:00 PM	MTAService.OnSessionChange	0	None	3:25:00 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/12/2018 2:36:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 2:23:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25531f5b-6e1e-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/12/2018 2:06:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/12/2018 2:00:02 PM	MTAService.OnSessionChange	0	None	2:00:02 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/12/2018 1:04:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 12:57:55 PM	MTAService.OnSessionChange	0	None	12:57:55 PM - Session change notice received: SessionLock Session ID: 1
Information	6/12/2018 12:39:35 PM	MTAService.OnSessionChange	0	None	12:39:35 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/12/2018 11:08:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/12/2018 10:56:53 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/12/2018 10:39:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 10:39:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:09Z. Reason: GVLK.
Information	6/12/2018 10:34:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/12/2018 10:34:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 10:34:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 10:34:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/12/2018 10:23:02 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8921.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/12/2018 10:14:26 AM	MTAService.OnSessionChange	0	None	10:14:26 AM - Session change notice received: SessionLock Session ID: 1
Information	6/12/2018 10:11:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 10:09:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 10:09:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:08Z. Reason: GVLK.
Information	6/12/2018 10:08:03 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 9, Deleted: 0, Modified: 105, Compared: 24264, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/12/2018 10:06:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/12/2018 10:06:03 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	6/12/2018 10:05:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/12/2018 10:05:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/12/2018 10:05:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29270)(?)])(1 )(2 )]

"
Information	6/12/2018 10:05:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29270)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 10:05:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/12/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/12/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29270)(?)])(1 )(2 )]

"
Information	6/12/2018 10:05:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29270)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 10:05:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/12/2018 10:05:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 10:05:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	6/12/2018 10:05:21 AM	Microsoft Office 16	2000	None	Microsoft Outlook: Accepted Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Information	6/12/2018 10:04:58 AM	MTAService.OnSessionChange	0	None	10:04:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/12/2018 10:04:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/12/2018 10:04:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 10:04:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 10:04:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/12/2018 9:58:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 9:58:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:15Z. Reason: GVLK.
Information	6/12/2018 9:53:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/12/2018 9:53:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 9:53:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 9:53:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/12/2018 9:51:47 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/12/2018 9:39:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 9:39:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:06Z. Reason: GVLK.
Information	6/12/2018 9:32:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/12/2018 9:27:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/12/2018 9:27:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29307)(?)])(1 )(2 )]

"
Information	6/12/2018 9:27:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29307)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	6/12/2018 9:25:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	6/12/2018 9:24:46 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/12/2018 9:23:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3ba5d231-6df4-11e8-bc3a-204747d02364
Report Status: 0"
Information	6/12/2018 9:23:11 AM	MTAService.OnSessionChange	0	None	9:23:11 AM - Session change notice received: SessionLock Session ID: 1
Error	6/12/2018 9:23:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/12/2018 9:22:54 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/12/2018 9:22:25 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/12/2018 9:22:23 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/12/2018 9:22:23 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/12/2018 9:22:18 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/12/2018 9:22:16 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/12/2018 9:22:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/12/2018 9:22:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29313)(?)])(1 )(2 )]

"
Information	6/12/2018 9:22:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29313)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 9:22:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/12/2018 9:22:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 9:22:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/12/2018 9:21:59 AM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	6/12/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/12/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/12/2018 9:21:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/12/2018 9:21:37 AM	ESENT	302	Logging/Recovery	Windows (9116) Windows: The database engine has successfully completed recovery steps.
Information	6/12/2018 9:21:37 AM	ESENT	301	Logging/Recovery	Windows (9116) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/12/2018 9:21:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/12/2018 9:21:17 AM	ESENT	301	Logging/Recovery	Windows (9116) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS008B3.log.
Information	6/12/2018 9:21:17 AM	ESENT	300	Logging/Recovery	Windows (9116) Windows: The database engine is initiating recovery steps.
Information	6/12/2018 9:21:17 AM	ESENT	102	General	Windows (9116) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	6/12/2018 9:20:40 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	6/12/2018 9:20:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8920.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	6/12/2018 9:19:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/12/2018 9:19:55 AM	Service1	0	None	Service started successfully.
Error	6/12/2018 9:19:46 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/12/2018 9:19:41 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/12/2018 9:19:01 AM	PostgreSQL	0	None	"2018-06-12 09:19:01 IST LOG:  redirecting log output to logging collector process
2018-06-12 09:19:01 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/12/2018 9:18:57 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/12/2018 9:18:56 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/12/2018 9:18:55 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/12/2018 9:18:51 AM	MTAService.OnSessionChange	0	None	9:18:51 AM - Logon : 212558710
Information	6/12/2018 9:18:51 AM	MTAService.OnSessionChange	0	None	9:18:51 AM - Session change notice received: SessionLogon Session ID: 1
Information	6/12/2018 9:18:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/12/2018 9:18:50 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/12/2018 9:18:50 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/12/2018 9:18:50 AM	MTAService	0	None	Service started successfully.
Information	6/12/2018 9:18:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/12/2018 9:18:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/12/2018 9:18:49 AM	MTAService.OnStart	0	None	9:18:49 AM - Waiting for user to Logon
Information	6/12/2018 9:18:46 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/12/2018 9:18:41 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/12/2018 9:18:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/12/2018 9:18:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/12/2018 9:18:40 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/12/2018 9:18:39 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:38 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/12/2018 9:18:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/12/2018 9:18:37 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/12/2018 9:18:37 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/12/2018 9:18:29 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:29 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:29 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/12/2018 9:18:29 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/12/2018 9:18:28 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:28 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/12/2018 9:18:28 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/12/2018 9:18:28 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/12/2018 9:18:28 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3680 at 6/11/2018 9:16:59 AM (local) 6/11/2018 3:46:59 AM (UTC). This is an informational message only; no user action is required.
Information	6/12/2018 9:18:23 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/12/2018 9:18:23 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/12/2018 9:18:23 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/12/2018 9:18:23 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/12/2018 9:18:23 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3968.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/12/2018 9:18:22 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/12/2018 9:17:06 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/12/2018 9:16:57 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/12/2018 9:16:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/12/2018 9:16:39 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/12/2018 9:16:39 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	6/11/2018 6:41:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 6:05:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/11/2018 5:38:20 PM	MTAService.OnSessionChange	0	None	5:38:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 5:26:53 PM	MTAService.OnSessionChange	0	None	5:26:53 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 5:20:58 PM	MTAService.OnSessionChange	0	None	5:20:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 5:12:24 PM	MTAService.OnSessionChange	0	None	5:12:24 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 5:11:57 PM	MTAService.OnSessionChange	0	None	5:11:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 5:07:50 PM	MTAService.OnSessionChange	0	None	5:07:50 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 5:04:31 PM	MTAService.OnSessionChange	0	None	5:04:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 4:56:23 PM	MTAService.OnSessionChange	0	None	4:56:23 PM - Session change notice received: SessionLock Session ID: 1
Warning	6/11/2018 4:53:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 4:53:25 PM	MTAService.OnSessionChange	0	None	4:53:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 4:51:17 PM	MTAService.OnSessionChange	0	None	4:51:17 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 4:47:23 PM	MTAService.OnSessionChange	0	None	4:47:23 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/11/2018 3:17:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 2:21:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ee94c75-6d54-11e8-821a-204747d02364
Report Status: 0"
Information	6/11/2018 2:15:04 PM	MTAService.OnSessionChange	0	None	2:15:04 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 2:09:24 PM	MTAService.OnSessionChange	0	None	2:09:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 2:05:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	6/11/2018 1:20:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 1:02:02 PM	MTAService.OnSessionChange	0	None	1:02:02 PM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 12:49:51 PM	MTAService.OnSessionChange	0	None	12:49:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 12:25:39 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/11/2018 12:23:29 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/11/2018 12:09:00 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/11/2018 11:27:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 11:27:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:52:57Z. Reason: GVLK.
Information	6/11/2018 11:22:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/11/2018 11:22:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 11:22:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 11:22:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	6/11/2018 11:21:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 11:12:38 AM	MTAService.OnSessionChange	0	None	11:12:38 AM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 11:05:04 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎06‎-‎11T05:34:15.729375800Z.
Information	6/11/2018 11:05:04 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 13592.
Information	6/11/2018 11:05:04 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.204. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/11/2018 11:05:04 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	6/11/2018 11:04:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎06‎-‎11T05:34:15.729375800Z.
Information	6/11/2018 11:03:11 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 13592.
Information	6/11/2018 10:47:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 10:42:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/11/2018 10:42:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30673)(?)])(1 )(2 )]

"
Information	6/11/2018 10:42:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30673)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 10:42:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/11/2018 10:42:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 10:42:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 10:38:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 10:38:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:03Z. Reason: GVLK.
Information	6/11/2018 10:33:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/11/2018 10:33:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 10:33:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 10:33:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	6/11/2018 10:25:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/11/2018 10:13:54 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8920.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/11/2018 10:10:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 10:08:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 10:08:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:01Z. Reason: GVLK.
Information	6/11/2018 10:07:03 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 318, Deleted: 0, Modified: 186, Compared: 24229, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/11/2018 10:05:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/11/2018 10:05:30 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	6/11/2018 10:05:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/11/2018 10:05:26 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/11/2018 10:05:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/11/2018 10:05:23 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 32

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 32

Information	6/11/2018 10:05:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/11/2018 10:05:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/11/2018 10:05:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30710)(?)])(1 )(2 )]

"
Information	6/11/2018 10:05:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30710)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 10:05:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/11/2018 10:05:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 10:05:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 10:03:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/11/2018 10:03:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 10:03:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 10:03:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 9:57:11 AM	MTAService.OnSessionChange	0	None	9:57:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/11/2018 9:45:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 9:45:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:15Z. Reason: GVLK.
Information	6/11/2018 9:42:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	6/11/2018 9:38:02 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/11/2018 9:37:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/11/2018 9:37:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30738)(?)])(1 )(2 )]

"
Information	6/11/2018 9:37:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30738)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:37:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/11/2018 9:37:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 9:37:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 9:32:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/11/2018 9:32:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:32:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 9:32:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 9:28:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 9:28:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-18T03:53:17Z. Reason: GVLK.
Information	6/11/2018 9:24:27 AM	MTAService.OnSessionChange	0	None	9:24:27 AM - Session change notice received: SessionLock Session ID: 1
Information	6/11/2018 9:24:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/11/2018 9:23:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:23:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:23:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/06/11 03:53"
Information	6/11/2018 9:23:16 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/06/11 03:53, 0, 1, 242220, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	6/11/2018 9:23:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/11/2018 9:21:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	6/11/2018 9:21:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/11/2018 9:21:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b27740ff-6d2a-11e8-821a-204747d02364
Report Status: 0"
Information	6/11/2018 9:21:18 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, May 18, 2018 11:54:43 PM.
Information	6/11/2018 9:20:10 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/11/2018 9:19:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8910.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/11/2018 9:19:13 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/11/2018 9:19:12 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/11/2018 9:19:12 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	6/11/2018 9:19:11 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {57A796A0-F512-4610-B297-D6D6699B98FC}
Error	6/11/2018 9:19:11 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {57A796A0-F512-4610-B297-D6D6699B98FC}
Information	6/11/2018 9:19:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/11/2018 9:18:51 AM	ESENT	302	Logging/Recovery	Windows (8832) Windows: The database engine has successfully completed recovery steps.
Information	6/11/2018 9:18:46 AM	ESENT	301	Logging/Recovery	Windows (8832) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/11/2018 9:18:40 AM	ESENT	301	Logging/Recovery	Windows (8832) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00853.log.
Information	6/11/2018 9:18:39 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	6/11/2018 9:18:31 AM	ESENT	301	Logging/Recovery	Windows (8832) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00852.log.
Information	6/11/2018 9:18:31 AM	ESENT	300	Logging/Recovery	Windows (8832) Windows: The database engine is initiating recovery steps.
Information	6/11/2018 9:18:29 AM	ESENT	102	General	Windows (8832) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	6/11/2018 9:18:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/11/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/11/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 242220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:18:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 9:18:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/11/2018 9:18:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30757)(?)])(1 )(2 )]

"
Information	6/11/2018 9:18:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30757)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/11/2018 9:18:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/11/2018 9:18:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/11/2018 9:18:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 9:18:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/11/2018 9:17:45 AM	MTAService.OnSessionChange	0	None	9:17:45 AM - Logon : 212558710
Information	6/11/2018 9:17:45 AM	MTAService.OnSessionChange	0	None	9:17:45 AM - Session change notice received: SessionLogon Session ID: 1
Information	6/11/2018 9:17:26 AM	Service1	0	None	Service started successfully.
Error	6/11/2018 9:17:22 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/11/2018 9:17:22 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/11/2018 9:17:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/11/2018 9:17:14 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/11/2018 9:17:14 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/11/2018 9:17:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/11/2018 9:17:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/11/2018 9:17:12 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/11/2018 9:17:11 AM	PostgreSQL	0	None	Server started and accepting connections

Information	6/11/2018 9:17:08 AM	PostgreSQL	0	None	"2018-06-11 09:17:08 IST LOG:  redirecting log output to logging collector process
2018-06-11 09:17:08 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/11/2018 9:17:08 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/11/2018 9:17:06 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/11/2018 9:17:05 AM	MTAService	0	None	Service started successfully.
Information	6/11/2018 9:17:05 AM	MTAService.OnStart	0	None	9:17:05 AM - Waiting for user to Logon
Information	6/11/2018 9:17:04 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/11/2018 9:17:01 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/11/2018 9:16:59 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4068 at 6/1/2018 10:02:15 AM (local) 6/1/2018 4:32:15 AM (UTC). This is an informational message only; no user action is required.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3680.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/11/2018 9:16:57 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	6/11/2018 9:16:44 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	6/11/2018 9:16:42 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/11/2018 9:16:36 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/11/2018 9:16:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/11/2018 9:16:36 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	6/1/2018 1:35:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/1/2018 1:04:02 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/1/2018 1:01:41 PM	MTAService.OnSessionChange	0	None	1:01:41 PM - Session change notice received: SessionLock Session ID: 1
Information	6/1/2018 12:59:05 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 390

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	6/1/2018 12:58:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/1/2018 12:58:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/1/2018 12:58:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44937)(?)])(1 )(2 )]

"
Information	6/1/2018 12:58:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 12:57:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/1/2018 12:57:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44937)(?)])(1 )(2 )]

"
Information	6/1/2018 12:57:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 12:57:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/1/2018 12:57:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 12:57:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 12:54:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8910.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	6/1/2018 12:13:31 PM	MTAService.OnSessionChange	0	None	12:13:31 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	6/1/2018 12:04:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/1/2018 11:23:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/1/2018 11:23:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:31Z. Reason: GVLK.
Information	6/1/2018 11:18:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/1/2018 11:18:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 11:18:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 11:18:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 11:13:46 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/1/2018 10:53:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/1/2018 10:53:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:30Z. Reason: GVLK.
Information	6/1/2018 10:48:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/1/2018 10:48:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 10:48:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 10:48:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 10:34:15 AM	MTAService.OnSessionChange	0	None	10:34:15 AM - Session change notice received: SessionLock Session ID: 1
Information	6/1/2018 10:30:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/1/2018 10:30:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:13Z. Reason: GVLK.
Information	6/1/2018 10:25:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/1/2018 10:25:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 10:25:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 10:25:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 10:23:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/1/2018 10:23:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:29Z. Reason: GVLK.
Error	6/1/2018 10:23:17 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	6/1/2018 10:21:48 AM	McLogEvent	257	None	The scan of D:\intecal_setup_10_0_10\intecal_setup.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8909.0000.
Information	6/1/2018 10:20:22 AM	MTAService.OnSessionChange	0	None	10:20:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	6/1/2018 10:13:25 AM	MTAService.OnSessionChange	0	None	10:13:25 AM - Session change notice received: SessionLock Session ID: 1
Error	6/1/2018 10:12:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/1/2018 10:11:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	6/1/2018 10:09:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/1/2018 10:07:30 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/1/2018 10:06:10 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/1/2018 10:06:05 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/1/2018 10:06:03 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	6/1/2018 10:06:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/1/2018 10:05:54 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/1/2018 10:05:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/1/2018 10:05:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 10:05:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 10:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/1/2018 10:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45109)(?)])(1 )(2 )]

"
Information	6/1/2018 10:05:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45109)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 10:05:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/1/2018 10:05:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 10:05:38 AM	ESENT	302	Logging/Recovery	Windows (9100) Windows: The database engine has successfully completed recovery steps.
Warning	6/1/2018 10:05:36 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	6/1/2018 10:05:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 10:05:34 AM	ESENT	301	Logging/Recovery	Windows (9100) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/1/2018 10:05:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 10:05:30 AM	ESENT	301	Logging/Recovery	Windows (9100) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0084E.log.
Information	6/1/2018 10:05:30 AM	ESENT	300	Logging/Recovery	Windows (9100) Windows: The database engine is initiating recovery steps.
Information	6/1/2018 10:05:30 AM	ESENT	102	General	Windows (9100) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/1/2018 10:05:23 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8909.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	6/1/2018 10:04:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/1/2018 10:03:36 AM	Service1	0	None	Service started successfully.
Error	6/1/2018 10:03:34 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/1/2018 10:03:32 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/1/2018 10:03:28 AM	PostgreSQL	0	None	Server started and accepting connections

Error	6/1/2018 10:03:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/1/2018 10:03:02 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	6/1/2018 10:03:01 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/1/2018 10:02:49 AM	MTAService	0	None	Service started successfully.
Information	6/1/2018 10:02:39 AM	PostgreSQL	0	None	"2018-06-01 10:02:39 IST LOG:  redirecting log output to logging collector process
2018-06-01 10:02:39 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/1/2018 10:02:37 AM	PostgreSQL	0	None	Waiting for server startup...

Information	6/1/2018 10:02:34 AM	MTAService.OnStart	0	None	10:02:34 AM - User is already logged in : 212558710
Information	6/1/2018 10:02:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/1/2018 10:02:32 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/1/2018 10:02:32 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/1/2018 10:02:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/1/2018 10:02:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/1/2018 10:02:30 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/1/2018 10:02:29 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/1/2018 10:02:21 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/1/2018 10:02:21 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/1/2018 10:02:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/1/2018 10:02:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/1/2018 10:02:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/1/2018 10:02:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/1/2018 10:02:18 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:18 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:18 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/1/2018 10:02:15 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3656 at 5/31/2018 4:08:59 PM (local) 5/31/2018 10:38:59 AM (UTC). This is an informational message only; no user action is required.
Information	6/1/2018 10:02:13 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/1/2018 10:02:13 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/1/2018 10:02:13 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/1/2018 10:02:13 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/1/2018 10:02:13 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4068.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/1/2018 10:02:12 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	6/1/2018 10:01:36 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/1/2018 10:01:25 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/1/2018 10:01:25 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/1/2018 10:01:25 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/1/2018 9:51:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 9:51:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/1/2018 9:51:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45124)(?)])(1 )(2 )]

"
Information	6/1/2018 9:51:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45124)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/1/2018 9:51:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/1/2018 9:51:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/1/2018 9:51:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/1/2018 9:50:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2a375712-6553-11e8-a651-204747d02364
Report Status: 0"
Warning	6/1/2018 9:43:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	6/1/2018 9:41:45 AM	MTAService.OnSessionChange	0	None	9:41:45 AM - Session change notice received: SessionLock Session ID: 1
Information	6/1/2018 9:40:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/1/2018 9:40:42 AM	MTAService.OnSessionChange	0	None	9:40:42 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/31/2018 11:09:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 11:04:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 10:15:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 10:15:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:05Z. Reason: GVLK.
Information	5/31/2018 10:10:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 10:10:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 10:10:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 10:10:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 10:09:52 PM	MTAService.OnSessionChange	0	None	10:09:52 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 10:06:23 PM	MTAService.OnSessionChange	0	None	10:06:23 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/31/2018 9:17:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 8:21:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 14a98206-64e2-11e8-a651-204747d02364
Report Status: 0"
Information	5/31/2018 8:12:13 PM	MTAService.OnSessionChange	0	None	8:12:13 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 8:10:39 PM	MTAService.OnSessionChange	0	None	8:10:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 8:07:32 PM	MTAService.OnSessionChange	0	None	8:07:32 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/31/2018 7:40:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 7:09:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 7:06:20 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 30, Deleted: 0, Modified: 0, Compared: 23965, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/31/2018 7:04:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 7:04:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/31/2018 7:04:49 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 390

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 796

Information	5/31/2018 7:04:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 7:04:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 7:04:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46011)(?)])(1 )(2 )]

"
Information	5/31/2018 7:04:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46011)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 7:04:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 7:04:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 7:04:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/31/2018 5:59:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/31/2018 5:43:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/31/2018 5:43:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/31/2018 5:41:54 PM	MTAService.OnSessionChange	0	None	5:41:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 5:31:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 5:31:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:08Z. Reason: GVLK.
Information	5/31/2018 5:30:23 PM	MTAService.OnSessionChange	0	None	5:30:23 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 5:26:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 5:26:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 5:26:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 5:26:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 5:25:54 PM	MTAService.OnSessionChange	0	None	5:25:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 5:24:02 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/31/2018 5:01:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 5:01:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:08Z. Reason: GVLK.
Information	5/31/2018 4:56:32 PM	MTAService.OnSessionChange	0	None	4:56:32 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 4:56:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 4:56:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:56:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 4:56:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 4:31:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 4:31:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:09Z. Reason: GVLK.
Information	5/31/2018 4:26:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 4:26:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:26:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 4:26:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 4:19:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 4:18:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 4:18:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:32Z. Reason: GVLK.
Warning	5/31/2018 4:15:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 4:13:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 4:13:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46181)(?)])(1 )(2 )]

"
Information	5/31/2018 4:13:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46181)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:12:46 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/31/2018 4:12:37 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/31/2018 4:12:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 4:12:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46183)(?)])(1 )(2 )]

"
Information	5/31/2018 4:12:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46183)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:12:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 4:12:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 4:12:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/31/2018 4:12:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 4:11:53 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 4:11:50 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 4:11:48 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 4:11:47 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/31/2018 4:11:17 PM	ESENT	302	Logging/Recovery	Windows (7780) Windows: The database engine has successfully completed recovery steps.
Information	5/31/2018 4:11:15 PM	ESENT	301	Logging/Recovery	Windows (7780) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/31/2018 4:11:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 4:11:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:11:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 4:11:07 PM	ESENT	301	Logging/Recovery	Windows (7780) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00848.log.
Information	5/31/2018 4:11:07 PM	ESENT	300	Logging/Recovery	Windows (7780) Windows: The database engine is initiating recovery steps.
Information	5/31/2018 4:11:07 PM	ESENT	102	General	Windows (7780) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/31/2018 4:11:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 4:10:50 PM	MTAService.OnSessionChange	0	None	4:10:50 PM - Logon : 212558710
Information	5/31/2018 4:10:50 PM	MTAService.OnSessionChange	0	None	4:10:50 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/31/2018 4:10:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/31/2018 4:10:47 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/31/2018 4:10:47 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/31/2018 4:10:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/31/2018 4:10:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/31/2018 4:10:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8909.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/31/2018 4:09:31 PM	Service1	0	None	Service started successfully.
Error	5/31/2018 4:09:27 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/31/2018 4:09:27 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/31/2018 4:09:20 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/31/2018 4:09:13 PM	PostgreSQL	0	None	"2018-05-31 16:09:13 IST LOG:  redirecting log output to logging collector process
2018-05-31 16:09:13 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/31/2018 4:09:12 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/31/2018 4:09:12 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/31/2018 4:09:10 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/31/2018 4:09:10 PM	MTAService	0	None	Service started successfully.
Information	5/31/2018 4:09:10 PM	MTAService.OnStart	0	None	4:09:09 PM - Waiting for user to Logon
Information	5/31/2018 4:09:07 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/31/2018 4:09:04 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/31/2018 4:09:04 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/31/2018 4:09:04 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/31/2018 4:09:04 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/31/2018 4:09:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/31/2018 4:09:03 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/31/2018 4:09:02 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/31/2018 4:09:02 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/31/2018 4:09:02 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/31/2018 4:09:00 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/31/2018 4:09:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/31/2018 4:09:00 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/31/2018 4:09:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/31/2018 4:08:59 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3876 at 5/31/2018 1:27:26 PM (local) 5/31/2018 7:57:26 AM (UTC). This is an informational message only; no user action is required.
Information	5/31/2018 4:08:57 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/31/2018 4:08:57 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/31/2018 4:08:57 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/31/2018 4:08:57 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/31/2018 4:08:57 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3656.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/31/2018 4:08:56 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/31/2018 4:08:44 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/31/2018 4:08:39 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 4:08:32 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/31/2018 4:08:32 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/31/2018 4:08:32 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/31/2018 3:21:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2b2c74a9-64b8-11e8-adb5-0205857feb80
Report Status: 0"
Warning	5/31/2018 3:09:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 2:59:47 PM	MTAService.OnSessionChange	0	None	2:59:47 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 2:49:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 2:49:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:17Z. Reason: GVLK.
Information	5/31/2018 2:46:54 PM	MTAService.OnSessionChange	0	None	2:46:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 2:44:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 2:44:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:44:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 2:44:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 2:33:02 PM	MTAService.OnSessionChange	0	None	2:33:02 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 2:23:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 2:19:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 2:19:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:16Z. Reason: GVLK.
Information	5/31/2018 2:18:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46297)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:18:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46297)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:18:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/31/2018 2:18:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/31/2018 2:18:16 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	5/31/2018 2:17:16 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 14, Deleted: 0, Modified: 0, Compared: 23929, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/31/2018 2:15:34 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/31/2018 2:15:29 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 46

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 32

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	5/31/2018 2:15:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 2:15:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 2:15:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46300)(?)])(1 )(2 )]

"
Information	5/31/2018 2:15:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:15:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 2:15:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 2:15:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 2:14:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 2:14:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:14:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 2:14:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 2:08:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 2:03:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 2:03:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46312)(?)])(1 )(2 )]

"
Information	5/31/2018 2:03:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46312)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 2:03:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 2:03:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 2:03:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 1:49:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 1:49:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:18Z. Reason: GVLK.
Information	5/31/2018 1:44:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 1:44:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 1:44:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 1:44:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 1:42:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 1:38:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 1:38:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:13Z. Reason: GVLK.
Information	5/31/2018 1:37:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 1:37:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46337)(?)])(1 )(2 )]

"
Information	5/31/2018 1:37:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46337)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 1:37:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 1:37:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 1:37:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 1:36:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/31/2018 1:32:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 1:32:30 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	5/31/2018 1:32:26 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/31/2018 1:31:00 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/31/2018 1:31:00 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 1:30:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 1:30:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 1:30:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 1:30:56 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 1:30:53 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 1:30:47 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/31/2018 1:30:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 1:30:31 PM	ESENT	302	Logging/Recovery	Windows (10148) Windows: The database engine has successfully completed recovery steps.
Information	5/31/2018 1:30:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 1:30:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46345)(?)])(1 )(2 )]

"
Information	5/31/2018 1:30:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 1:30:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 1:30:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 1:30:29 PM	ESENT	301	Logging/Recovery	Windows (10148) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/31/2018 1:30:27 PM	ESENT	301	Logging/Recovery	Windows (10148) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00842.log.
Information	5/31/2018 1:30:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 1:30:25 PM	ESENT	301	Logging/Recovery	Windows (10148) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00841.log.
Information	5/31/2018 1:30:25 PM	ESENT	300	Logging/Recovery	Windows (10148) Windows: The database engine is initiating recovery steps.
Information	5/31/2018 1:30:24 PM	ESENT	102	General	Windows (10148) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/31/2018 1:30:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8909.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	5/31/2018 1:29:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/31/2018 1:28:55 PM	MTAService.OnSessionChange	0	None	1:28:55 PM - Logon : 212558710
Information	5/31/2018 1:28:55 PM	MTAService.OnSessionChange	0	None	1:28:55 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/31/2018 1:28:41 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/31/2018 1:28:41 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/31/2018 1:28:41 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/31/2018 1:28:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/31/2018 1:28:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/31/2018 1:28:10 PM	Service1	0	None	Service started successfully.
Information	5/31/2018 1:28:06 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	5/31/2018 1:28:06 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/31/2018 1:27:44 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/31/2018 1:27:40 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/31/2018 1:27:39 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/31/2018 1:27:36 PM	PostgreSQL	0	None	"2018-05-31 13:27:36 IST LOG:  redirecting log output to logging collector process
2018-05-31 13:27:36 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/31/2018 1:27:35 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:35 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/31/2018 1:27:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/31/2018 1:27:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/31/2018 1:27:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/31/2018 1:27:34 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:34 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/31/2018 1:27:34 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/31/2018 1:27:33 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/31/2018 1:27:32 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:32 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/31/2018 1:27:32 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/31/2018 1:27:30 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/31/2018 1:27:30 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/31/2018 1:27:30 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/31/2018 1:27:28 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/31/2018 1:27:27 PM	MTAService	0	None	Service started successfully.
Information	5/31/2018 1:27:27 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:27 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:27 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:27 PM	MTAService.OnStart	0	None	1:27:26 PM - Waiting for user to Logon
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/31/2018 1:27:26 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4328 at 5/30/2018 8:34:03 PM (local) 5/30/2018 3:04:03 PM (UTC). This is an informational message only; no user action is required.
Information	5/31/2018 1:27:22 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/31/2018 1:27:21 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/31/2018 1:27:21 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/31/2018 1:27:21 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/31/2018 1:27:21 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3876.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/31/2018 1:26:59 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/31/2018 1:26:33 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/31/2018 1:26:26 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/31/2018 1:26:06 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/31/2018 1:26:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/31/2018 1:26:06 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/31/2018 12:57:27 PM	MTAService.OnSessionChange	0	None	12:57:27 PM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 12:52:03 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8909.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/31/2018 12:41:50 PM	MTAService.OnSessionChange	0	None	12:41:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 12:32:50 PM	MTAService.OnSessionChange	0	None	12:32:50 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/31/2018 12:04:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 11:44:40 AM	MTAService.OnSessionChange	0	None	11:44:40 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 11:34:03 AM	MTAService.OnSessionChange	0	None	11:34:03 AM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 11:11:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 11:11:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:26Z. Reason: GVLK.
Information	5/31/2018 11:06:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 11:06:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 11:06:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 11:06:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 10:26:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 10:21:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 41a070d4-648e-11e8-842e-0205857feb80
Report Status: 0"
Information	5/31/2018 10:21:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 10:21:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46534)(?)])(1 )(2 )]

"
Information	5/31/2018 10:21:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46534)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 10:20:13 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 452

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 312

Information	5/31/2018 10:20:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 10:19:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 10:19:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46535)(?)])(1 )(2 )]

"
Information	5/31/2018 10:19:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 10:19:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 10:19:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 10:19:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/31/2018 10:12:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/31/2018 10:11:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/31/2018 9:40:50 AM	MTAService.OnSessionChange	0	None	9:40:50 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 9:25:16 AM	MTAService.OnSessionChange	0	None	9:25:16 AM - Session change notice received: SessionLock Session ID: 1
Information	5/31/2018 9:11:58 AM	MTAService.OnSessionChange	0	None	9:11:58 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/31/2018 8:43:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/31/2018 8:36:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/31/2018 6:38:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 5:21:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57d49a98-6464-11e8-842e-0205857feb80
Report Status: 0"
Warning	5/31/2018 5:04:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 4:42:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 4:14:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 4:09:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/31/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46905)(?)])(1 )(2 )]

"
Information	5/31/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/31/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 4:09:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/31/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:02Z. Reason: GVLK.
Information	5/31/2018 3:34:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 3:34:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 3:34:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 3:34:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/31/2018 3:32:28 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/31/2018 3:30:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/31/2018 3:30:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:46Z. Reason: GVLK.
Error	5/31/2018 3:26:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/31/2018 3:25:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/31/2018 3:25:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/31/2018 3:25:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/31/2018 3:25:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/31/2018 3:25:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/31/2018 1:46:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 12:42:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/31/2018 12:21:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6e3fb984-643a-11e8-842e-0205857feb80
Report Status: 0"
Warning	5/31/2018 12:09:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/31/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/30/2018 10:45:13 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/30/2018 10:43:11 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/30/2018 10:29:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/30/2018 10:25:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 10:02:10 PM	MTAService.OnSessionChange	0	None	10:02:10 PM - Session change notice received: SessionLock Session ID: 1
Information	5/30/2018 9:54:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 9:54:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:18Z. Reason: GVLK.
Information	5/30/2018 9:49:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 9:49:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 9:49:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 9:49:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 9:24:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 9:24:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:18Z. Reason: GVLK.
Information	5/30/2018 9:19:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 9:19:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 9:19:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 9:19:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:56:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:54:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:54:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:18Z. Reason: GVLK.
Information	5/30/2018 8:50:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:50:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47344)(?)])(1 )(2 )]

"
Information	5/30/2018 8:50:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47344)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:50:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 8:50:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:50:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:49:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:49:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 8:49:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:49:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:49:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:44:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:44:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47351)(?)])(1 )(2 )]

"
Information	5/30/2018 8:44:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47351)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:43:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:43:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:37Z. Reason: GVLK.
Information	5/30/2018 8:42:52 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	5/30/2018 8:42:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/30/2018 8:42:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:42:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47353)(?)])(1 )(2 )]

"
Information	5/30/2018 8:42:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47353)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:42:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 8:42:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:42:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:41:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:36:50 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/30/2018 8:36:21 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/30/2018 8:36:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:36:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47359)(?)])(1 )(2 )]

"
Information	5/30/2018 8:36:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47359)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:36:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 8:36:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:36:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:35:31 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:35:31 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:35:31 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:35:04 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/30/2018 8:34:56 PM	ESENT	302	Logging/Recovery	Windows (2736) Windows: The database engine has successfully completed recovery steps.
Information	5/30/2018 8:34:51 PM	ESENT	301	Logging/Recovery	Windows (2736) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/30/2018 8:34:50 PM	ESENT	300	Logging/Recovery	Windows (2736) Windows: The database engine is initiating recovery steps.
Information	5/30/2018 8:34:50 PM	ESENT	102	General	Windows (2736) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/30/2018 8:34:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 8:34:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:34:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:34:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:34:36 PM	MTAService	0	None	Service started successfully.
Information	5/30/2018 8:34:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8908.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/30/2018 8:34:14 PM	Service1	0	None	Service started successfully.
Information	5/30/2018 8:34:14 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:14 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/30/2018 8:34:13 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/30/2018 8:34:13 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/30/2018 8:34:13 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/30/2018 8:34:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/30/2018 8:34:12 PM	PostgreSQL	0	None	"2018-05-30 20:34:12 IST LOG:  redirecting log output to logging collector process
2018-05-30 20:34:12 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/30/2018 8:34:11 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/30/2018 8:34:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Error	5/30/2018 8:34:09 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/30/2018 8:34:09 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/30/2018 8:34:08 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:08 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/30/2018 8:34:07 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/30/2018 8:34:06 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 8:34:06 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/30/2018 8:34:06 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/30/2018 8:34:05 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/30/2018 8:34:03 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3900 at 5/30/2018 8:31:53 PM (local) 5/30/2018 3:01:53 PM (UTC). This is an informational message only; no user action is required.
Information	5/30/2018 8:34:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/30/2018 8:34:01 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/30/2018 8:34:01 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/30/2018 8:34:01 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/30/2018 8:34:01 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/30/2018 8:34:01 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/30/2018 8:34:01 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/30/2018 8:34:01 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/30/2018 8:34:00 PM	MTAService.OnStart	0	None	8:33:59 PM - User is already logged in : 212558710
Information	5/30/2018 8:33:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/30/2018 8:33:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4328.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/30/2018 8:33:53 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/30/2018 8:33:30 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/30/2018 8:33:30 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:33:13 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/30/2018 8:33:13 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/30/2018 8:33:13 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/30/2018 8:31:59 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	5/30/2018 8:31:53 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	5/30/2018 8:31:48 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 192 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4012 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 4012 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
"
Information	5/30/2018 8:31:48 PM	MTAService.OnSessionChange	0	None	8:31:48 PM - Logoff
Information	5/30/2018 8:31:48 PM	MTAService.OnSessionChange	0	None	8:31:48 PM - Session change notice received: SessionLogoff Session ID: 1
Information	5/30/2018 8:31:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	5/30/2018 8:31:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	5/30/2018 8:31:47 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	5/30/2018 8:31:37 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Error	5/30/2018 8:31:14 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:31:13 PM	PostgreSQL	0	None	"2018-05-30 20:31:13 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:31:13 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:31:13 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:28:23 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:28:22 PM	PostgreSQL	0	None	"2018-05-30 20:28:22 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:28:22 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:28:22 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 8:27:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:27:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:20:10Z. Reason: GVLK.
Information	5/30/2018 8:26:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	5/30/2018 8:26:03 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:26:02 PM	PostgreSQL	0	None	"2018-05-30 20:26:02 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:26:02 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:26:02 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:25:17 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:25:16 PM	PostgreSQL	0	None	"2018-05-30 20:25:16 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:25:16 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:25:16 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:24:59 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:24:58 PM	PostgreSQL	0	None	"2018-05-30 20:24:58 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:24:58 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:24:58 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:24:48 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:24:47 PM	PostgreSQL	0	None	"2018-05-30 20:24:47 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:24:47 IST HINT:  Is another postmaster (PID 9000) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:24:47 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:24:30 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/30/2018 8:24:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 12415, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/30/2018 8:23:25 PM	PostgreSQL	0	None	"2018-05-30 20:23:25 IST LOG:  redirecting log output to logging collector process
2018-05-30 20:23:25 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/30/2018 8:23:25 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:22:12 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:22:11 PM	PostgreSQL	0	None	"2018-05-30 20:22:11 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:22:11 IST HINT:  Is another postmaster (PID 5700) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:22:11 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/30/2018 8:21:47 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:21:46 PM	PostgreSQL	0	None	"2018-05-30 20:21:46 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:21:46 IST HINT:  Is another postmaster (PID 5700) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:21:46 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 8:21:44 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/30/2018 8:21:39 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 561

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 484

Error	5/30/2018 8:21:32 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:21:32 PM	PostgreSQL	0	None	"2018-05-30 20:21:32 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-30 20:21:32 IST HINT:  Is another postmaster (PID 5700) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/30/2018 8:21:31 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 8:21:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/30/2018 8:21:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:21:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47374)(?)])(1 )(2 )]

"
Information	5/30/2018 8:21:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47374)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:20:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 8:20:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:20:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:17:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 8:17:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:17:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:17:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:15:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:15:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:56Z. Reason: GVLK.
Information	5/30/2018 8:13:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 8:13:47 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	5/30/2018 8:10:09 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/30/2018 8:08:45 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/30/2018 8:08:40 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:08:37 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:08:35 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:08:30 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/30/2018 8:08:18 PM	ESENT	302	Logging/Recovery	Windows (8484) Windows: The database engine has successfully completed recovery steps.
Information	5/30/2018 8:08:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 8:08:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47387)(?)])(1 )(2 )]

"
Information	5/30/2018 8:08:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47387)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:08:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 8:08:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 8:08:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 8:08:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:08:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 8:08:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:08:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 8:08:10 PM	ESENT	301	Logging/Recovery	Windows (8484) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/30/2018 8:08:10 PM	ESENT	300	Logging/Recovery	Windows (8484) Windows: The database engine is initiating recovery steps.
Information	5/30/2018 8:08:10 PM	ESENT	102	General	Windows (8484) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/30/2018 8:08:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8908.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	5/30/2018 8:07:49 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/30/2018 8:07:43 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/30/2018 8:07:23 PM	Service1	0	None	Service started successfully.
Error	5/30/2018 8:07:18 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/30/2018 8:07:17 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	5/30/2018 8:07:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/30/2018 8:07:07 PM	MTAService	0	None	Service started successfully.
Information	5/30/2018 8:06:52 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/30/2018 8:06:40 PM	PostgreSQL	0	None	"2018-05-30 20:06:40 IST LOG:  redirecting log output to logging collector process
2018-05-30 20:06:40 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/30/2018 8:06:34 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/30/2018 8:06:33 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 8:06:28 PM	MTAService.OnStart	0	None	8:06:27 PM - User is already logged in : 212558710
Information	5/30/2018 8:06:23 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/30/2018 8:06:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/30/2018 8:06:19 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/30/2018 8:06:19 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/30/2018 8:06:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/30/2018 8:06:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/30/2018 8:06:10 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:10 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/30/2018 8:06:09 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/30/2018 8:06:09 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/30/2018 8:06:09 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/30/2018 8:06:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/30/2018 8:06:08 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/30/2018 8:06:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/30/2018 8:06:07 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/30/2018 8:06:03 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/30/2018 8:06:03 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/30/2018 8:06:03 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/30/2018 8:06:02 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3784 at 5/29/2018 2:12:05 PM (local) 5/29/2018 8:42:05 AM (UTC). This is an informational message only; no user action is required.
Information	5/30/2018 8:05:59 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/30/2018 8:05:59 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/30/2018 8:05:59 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/30/2018 8:05:59 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/30/2018 8:05:59 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3900.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/30/2018 8:05:58 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/30/2018 8:05:19 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/30/2018 8:05:12 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/30/2018 8:04:54 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/30/2018 8:04:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/30/2018 8:04:54 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/30/2018 7:29:48 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.204. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/30/2018 7:29:48 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/30/2018 7:29:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T13:55:27.380947500Z.
Information	5/30/2018 7:29:45 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{233B943D-0033-4FE0-B9A0-8C89C77606CC}\4Sight™ 2.msi. Client Process Id: 11404.
Information	5/30/2018 7:25:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T13:55:27.380947500Z.
Information	5/30/2018 7:25:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{233B943D-0033-4FE0-B9A0-8C89C77606CC}\4Sight™ 2.msi. Client Process Id: 11404.
Warning	5/30/2018 7:21:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 7:21:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 84cbe543-6410-11e8-8df8-0205857feb80
Report Status: 0"
Information	5/30/2018 7:16:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T13:45:30.450947500Z.
Information	5/30/2018 7:16:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	5/30/2018 7:16:03 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.204. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/30/2018 7:16:03 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/30/2018 7:15:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T13:45:30.450947500Z.
Information	5/30/2018 7:15:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	5/30/2018 7:06:33 PM	Microsoft-Windows-MSDTC 2	4202	TM	MSDTC started with the following settings:

 Security Configuration (OFF = 0 and ON = 1):
 Allow Remote Administrator = 0,
 Network Clients = 0,
 Trasaction Manager Communication: 
 Allow Inbound Transactions = 0,
 Allow Outbound Transactions = 0,
 Transaction Internet Protocol (TIP) = 0,
  Enable XA Transactions = 0,
  Enable SNA LU 6.2 Transactions = 1,
  MSDTC Communications Security = Mutual Authentication Required,
 Account = NT AUTHORITY\NetworkService,
  Firewall Exclusion Detected = 0

 Transaction Bridge Installed = 0
 Filtering Duplicate Events = 1

Information	5/30/2018 7:06:32 PM	Microsoft-Windows-Complus	781	None	The COM+ sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\COM3\Eventlog.
Information	5/30/2018 6:46:23 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 1603.
Information	5/30/2018 6:46:23 PM	MsiInstaller	11708	None	Product: Adobe Reader XI (11.0.08) -- Installation operation failed.
Information	5/30/2018 6:46:23 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.07). Installation success or error status: 1603.
Error	5/30/2018 6:46:23 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.07)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI1ff73.LOG.
Information	5/30/2018 6:46:23 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.08). Installation success or error status: 1603.
Error	5/30/2018 6:46:23 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.08)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI1ff73.LOG.
Error	5/30/2018 6:46:22 PM	MsiInstaller	1013	None	Product: Adobe Reader XI (11.0.08) -- Setup has detected that you already have a more functional product installed.  Setup will now terminate.
Warning	5/30/2018 5:48:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 5:39:55 PM	MTAService.OnSessionChange	0	None	5:39:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/30/2018 4:59:44 PM	MTAService.OnSessionChange	0	None	4:59:44 PM - Session change notice received: SessionLock Session ID: 1
Information	5/30/2018 4:02:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 4:02:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47632)(?)])(1 )(2 )]

"
Information	5/30/2018 4:02:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47632)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	5/30/2018 4:02:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 3:55:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	5/30/2018 3:34:32 PM	Application Error	1000	(100)	"Faulting application name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x57316441
Faulting module name: wxbase28u_vc_custom.dll, version: 2.8.12.0, time stamp: 0x5359fda3
Exception code: 0xc0000005
Fault offset: 0x00000000000c8e80
Faulting process id: 0x47dc
Faulting application start time: 0x01d3f7fd7262ac31
Faulting application path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Faulting module path: C:\Program Files\PostgreSQL\9.5\bin\wxbase28u_vc_custom.dll
Report Id: d8bbd8da-63f0-11e8-8df8-0205857feb80"
Information	5/30/2018 3:24:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 3:24:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 3:24:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 3:09:05 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.204. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/30/2018 3:09:05 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/30/2018 3:08:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{561CBBD6-DFDA-4A62-98ED-17F42B8B6685}\4Sight™ 2.msi. Client Process Id: 11456.
Information	5/30/2018 3:08:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T09:34:46.145428900Z.
Information	5/30/2018 3:04:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T09:34:46.145428900Z.
Information	5/30/2018 3:04:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{561CBBD6-DFDA-4A62-98ED-17F42B8B6685}\4Sight™ 2.msi. Client Process Id: 11456.
Information	5/30/2018 3:04:13 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/30/2018 3:04:12 PM	PostgreSQL	0	None	"2018-05-30 15:04:12 IST LOG:  redirecting log output to logging collector process
2018-05-30 15:04:12 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/30/2018 3:04:12 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/30/2018 3:00:49 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T09:30:49.016718400Z.
Information	5/30/2018 3:00:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\Desktop\R1.3_SetUpFile_2018_05_29_Tu_22_12_33_204\DISK1\ISSetupPrerequisites\{7588C9AC-B194-4CDD-B57C-0652484931DF}\psqlodbc_x86.msi. Client Process Id: 6312.
Information	5/30/2018 3:00:49 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: psqlODBC. Product Version: 09.05.0300. Product Language: 1033. Manufacturer: PostgreSQL Global Development Group. Installation success or error status: 0.
Information	5/30/2018 3:00:49 PM	MsiInstaller	11707	None	Product: psqlODBC -- Installation completed successfully.
Information	5/30/2018 3:00:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T09:30:49.016718400Z.
Information	5/30/2018 3:00:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\Desktop\R1.3_SetUpFile_2018_05_29_Tu_22_12_33_204\DISK1\ISSetupPrerequisites\{7588C9AC-B194-4CDD-B57C-0652484931DF}\psqlodbc_x86.msi. Client Process Id: 6312.
Information	5/30/2018 2:33:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 2:33:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:50Z. Reason: GVLK.
Information	5/30/2018 2:29:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T08:59:47.148550200Z.
Information	5/30/2018 2:29:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E4691A23-1FD1-41DB-8936-77AEF0B8A07F}. Client Process Id: 15848.
Information	5/30/2018 2:29:48 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: psqlODBC. Product Version: 09.05.0300. Product Language: 1033. Manufacturer: PostgreSQL Global Development Group. Removal success or error status: 0.
Information	5/30/2018 2:29:48 PM	MsiInstaller	11724	None	Product: psqlODBC -- Removal completed successfully.
Information	5/30/2018 2:29:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T08:59:47.148550200Z.
Information	5/30/2018 2:29:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E4691A23-1FD1-41DB-8936-77AEF0B8A07F}. Client Process Id: 15848.
Information	5/30/2018 2:28:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 2:28:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 2:28:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 2:28:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 2:24:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎30T08:52:57.141553600Z.
Information	5/30/2018 2:24:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	5/30/2018 2:24:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.202. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/30/2018 2:24:36 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/30/2018 2:22:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎30T08:52:57.141553600Z.
Information	5/30/2018 2:22:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	5/30/2018 2:21:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9b1dd88a-63e6-11e8-8df8-0205857feb80
Report Status: 0"
Information	5/30/2018 2:21:11 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/30/2018 2:21:02 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/30/2018 2:21:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/30/2018 2:19:45 PM	MTAService.OnSessionChange	0	None	2:19:45 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/30/2018 2:13:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 1:55:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 1:55:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-06-06T08:19:12Z. Reason: GVLK.
Information	5/30/2018 1:50:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 1:50:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 1:50:11 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/05/30 08:20"
Information	5/30/2018 1:50:10 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/05/30 08:20, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	5/30/2018 1:45:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 1:45:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 1:45:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 1:45:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 1:37:49 PM	MTAService.OnSessionChange	0	None	1:37:49 PM - Session change notice received: SessionLock Session ID: 1
Information	5/30/2018 1:36:37 PM	MTAService.OnSessionChange	0	None	1:36:36 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/30/2018 1:28:16 PM	MTAService.OnSessionChange	0	None	1:28:15 PM - Session change notice received: SessionLock Session ID: 1
Information	5/30/2018 12:59:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8908.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/30/2018 12:53:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 12:53:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:04Z. Reason: GVLK.
Information	5/30/2018 12:48:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 12:48:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 12:48:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 12:47:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/30/2018 12:40:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 11:54:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	5/30/2018 10:52:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 10:37:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47963)(?)])(1 )(2 )]

"
Information	5/30/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47963)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 10:32:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 10:32:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 10:32:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/30/2018 10:11:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/30/2018 10:11:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/30/2018 9:52:59 AM	MTAService.OnSessionChange	0	None	9:52:59 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/30/2018 9:25:41 AM	MTAService.OnSessionChange	0	None	9:25:41 AM - Session change notice received: SessionLock Session ID: 1
Information	5/30/2018 9:21:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b11be11d-63bc-11e8-8df8-0205857feb80
Report Status: 0"
Warning	5/30/2018 9:18:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 9:15:08 AM	MTAService.OnSessionChange	0	None	9:15:08 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/30/2018 7:54:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/30/2018 7:42:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 7:40:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 7:40:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:10Z. Reason: GVLK.
Information	5/30/2018 7:35:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 7:35:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 7:35:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 7:35:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/30/2018 5:55:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/30/2018 4:22:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 4:21:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c7628046-6392-11e8-8df8-0205857feb80
Report Status: 0"
Information	5/30/2018 4:14:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/30/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48345)(?)])(1 )(2 )]

"
Information	5/30/2018 4:09:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 4:09:48 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/30/2018 4:09:48 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 4:09:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/30/2018 3:54:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/30/2018 3:22:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 3:22:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:41Z. Reason: GVLK.
Information	5/30/2018 3:17:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 3:17:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 3:17:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 3:17:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/30/2018 3:15:16 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/30/2018 3:11:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/30/2018 3:11:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:46Z. Reason: GVLK.
Error	5/30/2018 3:07:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/30/2018 3:06:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/30/2018 3:06:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/30/2018 3:06:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/30/2018 3:06:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/30/2018 2:43:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/30/2018 2:06:43 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/30/2018 2:03:48 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/30/2018 1:23:37 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/30/2018 12:45:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 11:54:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 11:21:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dd84c175-6368-11e8-8df8-0205857feb80
Report Status: 0"
Warning	5/29/2018 11:02:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 10:06:38 PM	MTAService.OnSessionChange	0	None	10:06:38 PM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 9:40:03 PM	MTAService.OnSessionChange	0	None	9:40:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 9:27:12 PM	MTAService.OnSessionChange	0	None	9:27:12 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/29/2018 9:25:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 9:12:21 PM	MTAService.OnSessionChange	0	None	9:12:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 9:09:29 PM	MTAService.OnSessionChange	0	None	9:09:28 PM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 9:08:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48772)(?)])(1 )(2 )]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48772)(?)])(1 )(2 )]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48772)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48772)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 9:02:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 9:02:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 8:05:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 8:03:08 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 38, Deleted: 0, Modified: 0, Compared: 23796, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/29/2018 8:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 8:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48835)(?)])(1 )(2 )]

"
Information	5/29/2018 8:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48835)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 7:57:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48837)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 7:57:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48837)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 7:57:44 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/29/2018 7:57:44 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/29/2018 7:57:44 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	5/29/2018 7:55:37 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 141

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 109

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 62

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 733

Information	5/29/2018 7:54:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 7:54:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 7:54:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48841)(?)])(1 )(2 )]

"
Information	5/29/2018 7:54:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48841)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 7:53:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 7:53:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 7:53:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/29/2018 7:38:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 7:14:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 7:09:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 7:09:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48886)(?)])(1 )(2 )]

"
Information	5/29/2018 7:09:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48886)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 7:09:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 7:09:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 7:09:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 6:23:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.202. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/29/2018 6:23:42 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/29/2018 6:23:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎29T12:49:42.322098300Z.
Information	5/29/2018 6:23:03 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D51E79DF-91B0-4774-9901-31EDF72539F6}\4Sight™ 2.msi. Client Process Id: 15112.
Information	5/29/2018 6:22:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 6:21:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f2f9aba7-633e-11e8-8df8-0205857feb80
Report Status: 0"
Information	5/29/2018 6:19:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎29T12:49:42.322098300Z.
Information	5/29/2018 6:19:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D51E79DF-91B0-4774-9901-31EDF72539F6}\4Sight™ 2.msi. Client Process Id: 15112.
Information	5/29/2018 6:17:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 6:17:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48938)(?)])(1 )(2 )]

"
Information	5/29/2018 6:17:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48938)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 6:17:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 6:17:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 6:17:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 6:06:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/29/2018 6:05:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 6:01:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 6:01:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48954)(?)])(1 )(2 )]

"
Information	5/29/2018 6:01:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48954)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 6:01:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 6:01:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 6:01:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 5:56:04 PM	MTAService.OnSessionChange	0	None	5:56:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 5:36:23 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/29/2018 4:56:52 PM	MTAService.OnSessionChange	0	None	4:56:52 PM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 4:53:09 PM	MTAService.OnSessionChange	0	None	4:53:09 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 4:51:13 PM	MTAService.OnSessionChange	0	None	4:51:13 PM - Session change notice received: SessionLock Session ID: 1
Error	5/29/2018 4:27:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/29/2018 4:13:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 3:35:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 3:35:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:04Z. Reason: GVLK.
Information	5/29/2018 3:30:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 3:30:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 3:30:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 3:30:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 3:05:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 3:05:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:03Z. Reason: GVLK.
Information	5/29/2018 3:02:21 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/29/2018 3:02:20 PM	PostgreSQL	0	None	"2018-05-29 15:02:20 IST LOG:  redirecting log output to logging collector process
2018-05-29 15:02:20 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/29/2018 3:02:20 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/29/2018 3:00:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 3:00:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 3:00:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 3:00:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 2:56:17 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/29/2018 2:56:16 PM	PostgreSQL	0	None	"2018-05-29 14:56:16 IST LOG:  redirecting log output to logging collector process
2018-05-29 14:56:16 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/29/2018 2:56:16 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/29/2018 2:48:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎29T09:18:22.969913600Z.
Information	5/29/2018 2:48:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8292.
Information	5/29/2018 2:48:46 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.196. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/29/2018 2:48:46 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/29/2018 2:48:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎29T09:18:22.969913600Z.
Information	5/29/2018 2:48:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8292.
Information	5/29/2018 2:35:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 2:35:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:03Z. Reason: GVLK.
Information	5/29/2018 2:30:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 2:30:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 2:30:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 2:30:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 2:21:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 2:20:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 2:20:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:30Z. Reason: GVLK.
Warning	5/29/2018 2:18:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/29/2018 2:16:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/29/2018 2:16:04 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/29/2018 2:16:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 2:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49179)(?)])(1 )(2 )]

"
Information	5/29/2018 2:16:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49179)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 2:16:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 2:16:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 2:16:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 2:14:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/29/2018 2:14:46 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/29/2018 2:14:46 PM	MTAService.OnSessionChange	0	None	2:14:46 PM - Logon : 212558710
Information	5/29/2018 2:14:46 PM	MTAService.OnSessionChange	0	None	2:14:46 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/29/2018 2:14:45 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/29/2018 2:14:45 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/29/2018 2:14:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 2:14:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 2:14:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 2:14:42 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/29/2018 2:14:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 2:14:37 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 2:14:36 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 2:14:35 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 2:13:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8907.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/29/2018 2:12:56 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/29/2018 2:12:47 PM	ESENT	302	Logging/Recovery	Windows (7104) Windows: The database engine has successfully completed recovery steps.
Information	5/29/2018 2:12:47 PM	ESENT	301	Logging/Recovery	Windows (7104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/29/2018 2:12:43 PM	ESENT	301	Logging/Recovery	Windows (7104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00829.log.
Information	5/29/2018 2:12:43 PM	ESENT	300	Logging/Recovery	Windows (7104) Windows: The database engine is initiating recovery steps.
Information	5/29/2018 2:12:42 PM	ESENT	102	General	Windows (7104) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/29/2018 2:12:29 PM	Service1	0	None	Service started successfully.
Error	5/29/2018 2:12:24 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/29/2018 2:12:24 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/29/2018 2:12:20 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/29/2018 2:12:20 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/29/2018 2:12:18 PM	MTAService	0	None	Service started successfully.
Information	5/29/2018 2:12:18 PM	MTAService.OnStart	0	None	2:12:17 PM - Waiting for user to Logon
Information	5/29/2018 2:12:15 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/29/2018 2:12:11 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:10 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/29/2018 2:12:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/29/2018 2:12:10 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/29/2018 2:12:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/29/2018 2:12:09 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/29/2018 2:12:08 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/29/2018 2:12:07 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/29/2018 2:12:07 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/29/2018 2:12:07 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/29/2018 2:12:05 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3952 at 5/29/2018 12:36:15 PM (local) 5/29/2018 7:06:15 AM (UTC). This is an informational message only; no user action is required.
Information	5/29/2018 2:12:04 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/29/2018 2:12:04 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/29/2018 2:12:04 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/29/2018 2:12:04 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/29/2018 2:12:04 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3784.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/29/2018 2:12:03 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/29/2018 2:11:51 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/29/2018 2:11:49 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 2:11:42 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/29/2018 2:11:42 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/29/2018 2:11:42 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/29/2018 2:05:24 PM	MTAService.OnSessionChange	0	None	2:05:24 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 1:57:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 1:57:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:23Z. Reason: GVLK.
Information	5/29/2018 1:52:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 1:52:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 1:52:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 1:52:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 1:34:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8907.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/29/2018 1:31:47 PM	MTAService.OnSessionChange	0	None	1:31:47 PM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 1:27:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 1:27:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:21Z. Reason: GVLK.
Information	5/29/2018 1:22:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 1:22:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 1:22:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 1:22:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 1:21:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0914dc60-6315-11e8-baf7-204747d02364
Report Status: 0"
Information	5/29/2018 1:17:51 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/29/2018 1:17:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/29/2018 1:15:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 1:10:37 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/29/2018 1:10:37 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/29/2018 1:10:30 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 640

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 499

Information	5/29/2018 1:10:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49250)(?)])(1 )(2 )]

"
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49250)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 1:05:34 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 1:05:24 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	5/29/2018 12:57:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 12:57:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:24Z. Reason: GVLK.
Information	5/29/2018 12:52:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 12:52:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 12:52:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 12:52:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 12:46:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 12:46:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:06Z. Reason: GVLK.
Information	5/29/2018 12:44:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 12:40:20 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/29/2018 12:38:55 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 12:38:53 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 12:38:51 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/29/2018 12:38:46 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 12:38:32 PM	ESENT	302	Logging/Recovery	Windows (8572) Windows: The database engine has successfully completed recovery steps.
Information	5/29/2018 12:38:29 PM	ESENT	301	Logging/Recovery	Windows (8572) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/29/2018 12:38:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 12:38:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 12:38:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 12:38:23 PM	ESENT	301	Logging/Recovery	Windows (8572) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00828.log.
Information	5/29/2018 12:38:23 PM	ESENT	300	Logging/Recovery	Windows (8572) Windows: The database engine is initiating recovery steps.
Information	5/29/2018 12:38:23 PM	ESENT	102	General	Windows (8572) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/29/2018 12:38:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 12:38:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 12:38:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49277)(?)])(1 )(2 )]

"
Information	5/29/2018 12:38:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49277)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 12:38:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/29/2018 12:38:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 12:38:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/29/2018 12:38:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8906.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Error	5/29/2018 12:37:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/29/2018 12:37:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/29/2018 12:37:07 PM	MTAService	0	None	Service started successfully.
Information	5/29/2018 12:36:56 PM	Service1	0	None	Service started successfully.
Error	5/29/2018 12:36:51 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/29/2018 12:36:51 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/29/2018 12:36:37 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/29/2018 12:36:36 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/29/2018 12:36:33 PM	MTAService.OnStart	0	None	12:36:32 PM - User is already logged in : 212558710
Information	5/29/2018 12:36:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/29/2018 12:36:29 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/29/2018 12:36:29 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/29/2018 12:36:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/29/2018 12:36:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/29/2018 12:36:26 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/29/2018 12:36:25 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/29/2018 12:36:22 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:21 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/29/2018 12:36:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/29/2018 12:36:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/29/2018 12:36:20 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/29/2018 12:36:19 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/29/2018 12:36:18 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/29/2018 12:36:18 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/29/2018 12:36:18 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/29/2018 12:36:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/29/2018 12:36:18 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/29/2018 12:36:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/29/2018 12:36:15 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3276 at 5/26/2018 12:05:28 PM (local) 5/26/2018 6:35:28 AM (UTC). This is an informational message only; no user action is required.
Information	5/29/2018 12:36:13 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/29/2018 12:36:13 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/29/2018 12:36:13 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/29/2018 12:36:13 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/29/2018 12:36:13 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3952.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/29/2018 12:36:12 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/29/2018 12:35:31 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/29/2018 12:35:21 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/29/2018 12:35:05 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/29/2018 12:35:05 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/29/2018 12:35:05 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/29/2018 12:23:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 12:23:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 11:50:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/29/2018 11:50:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/29/2018 11:49:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 8, Compared: 23747, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/29/2018 11:48:10 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	5/29/2018 11:29:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 11:29:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49346)(?)])(1 )(2 )]

"
Information	5/29/2018 11:29:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49346)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 11:28:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 11:28:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49347)(?)])(1 )(2 )]

"
Information	5/29/2018 11:28:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49347)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 11:27:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 11:27:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49347)(?)])(1 )(2 )]

"
Information	5/29/2018 11:27:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49347)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/29/2018 11:27:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/29/2018 11:27:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 11:27:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49348)(?)])(1 )(2 )]

"
Information	5/29/2018 11:27:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49348)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 10:53:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 10:53:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49382)(?)])(1 )(2 )]

"
Information	5/29/2018 10:53:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49382)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	5/29/2018 10:45:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/29/2018 10:11:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/29/2018 10:08:46 AM	MTAService.OnSessionChange	0	None	10:08:46 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 9:46:32 AM	MTAService.OnSessionChange	0	None	9:46:32 AM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 9:26:12 AM	MTAService.OnSessionChange	0	None	9:26:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/29/2018 9:21:54 AM	MTAService.OnSessionChange	0	None	9:21:54 AM - Session change notice received: SessionLock Session ID: 1
Information	5/29/2018 9:07:32 AM	MTAService.OnSessionChange	0	None	9:07:32 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/29/2018 8:59:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 8:23:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 8:23:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 8:21:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ef57d23-62eb-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/29/2018 7:09:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/29/2018 5:12:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 4:23:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 4:23:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 4:23:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 4:21:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 4:21:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:37Z. Reason: GVLK.
Information	5/29/2018 4:16:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 4:16:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 4:16:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 4:16:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/29/2018 4:14:30 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/29/2018 4:10:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 4:10:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:40Z. Reason: GVLK.
Information	5/29/2018 4:09:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/29/2018 4:09:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49785)(?)])(1 )(2 )]

"
Information	5/29/2018 4:09:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/29/2018 4:06:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/29/2018 4:05:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 4:05:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 4:05:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 4:05:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/29/2018 3:35:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 3:21:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 352dd1a4-62c1-11e8-a13d-0205857feb80
Report Status: 0"
Information	5/29/2018 3:08:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/29/2018 3:08:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:07Z. Reason: GVLK.
Information	5/29/2018 3:03:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/29/2018 3:03:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/29/2018 3:03:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/29/2018 3:03:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/29/2018 1:39:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/29/2018 12:23:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 12:23:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 12:23:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/29/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/28/2018 11:42:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 10:45:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 10:45:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:06Z. Reason: GVLK.
Information	5/28/2018 10:40:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/28/2018 10:40:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 10:40:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 10:40:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 10:20:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b607fc3-6297-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/28/2018 9:52:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 9:13:24 PM	MTAService.OnSessionChange	0	None	9:13:24 PM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 8:41:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 8:41:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50233)(?)])(1 )(2 )]

"
Information	5/28/2018 8:41:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50233)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 8:34:14 PM	MTAService.OnSessionChange	0	None	8:34:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 8:26:38 PM	MTAService.OnSessionChange	0	None	8:26:38 PM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 8:23:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 8:23:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 8:23:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/28/2018 8:22:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/28/2018 8:09:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/28/2018 6:36:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 6:32:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 6:32:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50362)(?)])(1 )(2 )]

"
Information	5/28/2018 6:32:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50362)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 6:12:22 PM	MTAService.OnSessionChange	0	None	6:12:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 5:21:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5c9b2ac3-626d-11e8-a13d-0205857feb80
Report Status: 0"
Information	5/28/2018 4:59:17 PM	MTAService.OnSessionChange	0	None	4:59:17 PM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 4:40:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/28/2018 4:40:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 4:40:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/28/2018 4:36:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 4:28:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8906.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!f520828b8fea (ED)
"
Information	5/28/2018 4:23:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 4:23:15 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/28/2018 4:22:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 3:32:04 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.196. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/28/2018 3:32:04 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/28/2018 3:32:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎28T09:57:19.742181900Z.
Information	5/28/2018 3:32:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FBE74C80-6EC2-42D6-9007-E37E51604864}\4Sight™ 2.msi. Client Process Id: 11620.
Information	5/28/2018 3:27:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎28T09:57:19.742181900Z.
Information	5/28/2018 3:27:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FBE74C80-6EC2-42D6-9007-E37E51604864}\4Sight™ 2.msi. Client Process Id: 11620.
Information	5/28/2018 3:25:38 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.196. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	5/28/2018 3:25:38 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	5/28/2018 3:10:45 PM	MTAService.OnSessionChange	0	None	3:10:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 3:03:01 PM	MTAService.OnSessionChange	0	None	3:03:01 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/28/2018 2:36:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 2:35:51 PM	MTAService.OnSessionChange	0	None	2:35:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 2:14:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 2:14:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:03Z. Reason: GVLK.
Information	5/28/2018 2:09:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/28/2018 2:09:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 2:09:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 2:09:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 2:08:37 PM	MTAService.OnSessionChange	0	None	2:08:37 PM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 1:54:52 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/28/2018 1:54:31 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/28/2018 1:53:46 PM	MTAService.OnSessionChange	0	None	1:53:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 1:15:52 PM	MTAService.OnSessionChange	0	None	1:15:52 PM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 1:09:29 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/28/2018 1:07:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/28/2018 1:05:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 1:02:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 1:02:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50693)(?)])(1 )(2 )]

"
Information	5/28/2018 1:02:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 1:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 1:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50695)(?)])(1 )(2 )]

"
Information	5/28/2018 1:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50695)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 1:00:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/28/2018 1:00:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 1:00:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 12:58:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎28T07:27:42.580970500Z.
Information	5/28/2018 12:58:13 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10756.
Information	5/28/2018 12:58:13 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.193. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/28/2018 12:58:13 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/28/2018 12:57:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎28T07:27:42.580970500Z.
Information	5/28/2018 12:57:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10756.
Information	5/28/2018 12:52:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 12:47:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 12:47:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50708)(?)])(1 )(2 )]

"
Information	5/28/2018 12:47:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50708)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 12:47:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/28/2018 12:47:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 12:47:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 12:28:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8906.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/28/2018 12:22:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/28/2018 12:20:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d3fb39f-6243-11e8-a13d-0205857feb80
Report Status: 0"
Information	5/28/2018 12:07:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 12:02:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 12:02:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50752)(?)])(1 )(2 )]

"
Information	5/28/2018 12:02:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50752)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 12:02:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/28/2018 12:02:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 12:02:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/28/2018 11:32:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/28/2018 10:11:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/28/2018 10:06:45 AM	MTAService.OnSessionChange	0	None	10:06:45 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/28/2018 9:51:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 9:28:30 AM	MTAService.OnSessionChange	0	None	9:28:30 AM - Session change notice received: SessionLock Session ID: 1
Information	5/28/2018 9:09:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/28/2018 9:08:55 AM	MTAService.OnSessionChange	0	None	9:08:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/28/2018 8:30:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/28/2018 8:30:23 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/28/2018 8:30:23 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/28/2018 8:22:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/28/2018 8:06:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 7:20:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 83a2237c-6219-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/28/2018 6:23:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 5:11:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 5:11:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:49Z. Reason: GVLK.
Information	5/28/2018 5:06:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/28/2018 5:06:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 5:06:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 5:06:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/28/2018 5:05:20 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/28/2018 5:03:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 5:03:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:48Z. Reason: GVLK.
Error	5/28/2018 4:59:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/28/2018 4:58:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/28/2018 4:58:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 4:58:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 4:58:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 4:50:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 4:50:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:33Z. Reason: GVLK.
Warning	5/28/2018 4:48:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 4:45:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/28/2018 4:45:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 4:45:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 4:45:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/28/2018 4:22:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 4:14:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/28/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/28/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51225)(?)])(1 )(2 )]

"
Information	5/28/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51225)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/28/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/28/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/28/2018 4:09:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/28/2018 3:17:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 2:20:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 99f4902b-61ef-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/28/2018 1:17:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/28/2018 12:22:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/28/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/27/2018 11:40:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 10:15:44 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	5/27/2018 10:00:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 9:20:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b05973b0-61c5-11e8-a13d-0205857feb80
Report Status: 0"
Information	5/27/2018 8:21:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/27/2018 8:01:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/27/2018 6:21:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 4:58:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 4:58:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:49Z. Reason: GVLK.
Information	5/27/2018 4:53:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/27/2018 4:53:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 4:53:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 4:53:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/27/2018 4:36:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 4:21:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/27/2018 4:20:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c6a95159-619b-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/27/2018 2:42:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/27/2018 12:59:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 12:21:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/27/2018 12:18:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8905.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/27/2018 11:38:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 11:38:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:16Z. Reason: GVLK.
Information	5/27/2018 11:33:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/27/2018 11:33:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 11:33:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 11:33:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/27/2018 11:20:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dd012443-6171-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/27/2018 11:13:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/27/2018 10:11:12 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/27/2018 9:39:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 8:21:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/27/2018 7:48:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 7:32:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 7:32:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:09Z. Reason: GVLK.
Information	5/27/2018 7:27:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/27/2018 7:27:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 7:27:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 7:27:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/27/2018 6:20:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f364bc60-6147-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/27/2018 6:08:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 4:56:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 4:56:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:29Z. Reason: GVLK.
Error	5/27/2018 4:49:41 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/27/2018 4:47:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/27/2018 4:47:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 4:47:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 4:47:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/27/2018 4:47:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 4:47:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:20Z. Reason: GVLK.
Error	5/27/2018 4:42:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/27/2018 4:42:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/27/2018 4:42:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 4:42:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 4:42:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/27/2018 4:20:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/27/2018 4:14:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52665)(?)])(1 )(2 )]

"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52665)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/27/2018 4:09:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/27/2018 4:08:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/27/2018 2:24:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 1:20:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 09a22db4-611e-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/27/2018 12:32:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/27/2018 12:20:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/27/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/26/2018 10:47:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 9:57:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	5/26/2018 9:43:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	5/26/2018 9:16:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 8:20:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 8:20:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f9fa37f-60f4-11e8-a13d-0205857feb80
Report Status: 0"
Warning	5/26/2018 7:17:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/26/2018 5:40:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 5:11:46 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/26/2018 4:32:12 PM	MTAService.OnSessionChange	0	None	4:32:12 PM - Session change notice received: SessionLock Session ID: 1
Information	5/26/2018 4:31:49 PM	MTAService.OnSessionChange	0	None	4:31:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/26/2018 4:29:56 PM	MTAService.OnSessionChange	0	None	4:29:56 PM - Session change notice received: SessionLock Session ID: 1
Information	5/26/2018 4:20:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 4:12:24 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.193. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/26/2018 4:12:24 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/26/2018 4:11:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎26T10:38:05.035138700Z.
Information	5/26/2018 4:11:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F72794AC-9B86-4EB6-A41B-28C05615F5FE}\4Sight™ 2.msi. Client Process Id: 8452.
Information	5/26/2018 4:08:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎26T10:38:05.035138700Z.
Information	5/26/2018 4:08:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F72794AC-9B86-4EB6-A41B-28C05615F5FE}\4Sight™ 2.msi. Client Process Id: 8452.
Information	5/26/2018 4:07:45 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/26/2018 4:07:45 PM	PostgreSQL	0	None	"2018-05-26 16:07:45 IST LOG:  redirecting log output to logging collector process
2018-05-26 16:07:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/26/2018 4:07:44 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/26/2018 3:59:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:29:26.518292200Z.
Information	5/26/2018 3:59:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:59:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:29:26.518292200Z.
Information	5/26/2018 3:59:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:29:25.855225900Z.
Information	5/26/2018 3:59:25 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:59:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:29:25.855225900Z.
Information	5/26/2018 3:59:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:29:24.487089100Z.
Information	5/26/2018 3:59:24 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:59:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:29:24.487089100Z.
Information	5/26/2018 3:58:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:28:10.459687100Z.
Information	5/26/2018 3:58:10 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:58:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:28:10.459687100Z.
Information	5/26/2018 3:58:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:28:09.320573200Z.
Information	5/26/2018 3:58:09 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:58:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:28:09.320573200Z.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:27:40.433684800Z.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:27:40.433684800Z.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:27:40.115653000Z.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:57:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:27:40.115653000Z.
Information	5/26/2018 3:57:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:27:39.571598600Z.
Information	5/26/2018 3:57:39 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:57:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:27:39.571598600Z.
Information	5/26/2018 3:57:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎26T10:27:34.386080100Z.
Information	5/26/2018 3:57:34 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/26/2018 3:57:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎26T10:27:34.386080100Z.
Error	5/26/2018 3:55:25 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:55:24 PM	PostgreSQL	0	None	"2018-05-26 15:55:24 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:55:24 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:55:24 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/26/2018 3:53:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎26T10:23:41.604804300Z.
Information	5/26/2018 3:53:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15136.
Information	5/26/2018 3:53:55 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.193. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/26/2018 3:53:55 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/26/2018 3:53:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎26T10:23:41.604804300Z.
Information	5/26/2018 3:53:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15136.
Error	5/26/2018 3:52:40 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:52:40 PM	PostgreSQL	0	None	"2018-05-26 15:52:40 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:52:40 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:52:39 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:50:42 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:50:41 PM	PostgreSQL	0	None	"2018-05-26 15:50:41 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:50:41 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:50:41 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:50:28 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:50:27 PM	PostgreSQL	0	None	"2018-05-26 15:50:27 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:50:27 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:50:27 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:49:40 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:49:40 PM	PostgreSQL	0	None	"2018-05-26 15:49:40 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:49:40 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:49:39 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/26/2018 3:45:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.193. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/26/2018 3:45:42 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Warning	5/26/2018 3:44:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 3:43:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎26T10:09:28.383474100Z.
Information	5/26/2018 3:43:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BD100D3A-5BD0-4470-834C-32BE48D2BBB3}\4Sight™ 2.msi. Client Process Id: 9964.
Error	5/26/2018 3:43:20 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:43:19 PM	PostgreSQL	0	None	"2018-05-26 15:43:19 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:43:19 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:43:19 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:43:15 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:43:15 PM	PostgreSQL	0	None	"2018-05-26 15:43:15 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:43:15 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:43:14 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:43:11 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:43:10 PM	PostgreSQL	0	None	"2018-05-26 15:43:10 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:43:10 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:43:10 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:43:06 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:43:06 PM	PostgreSQL	0	None	"2018-05-26 15:43:06 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:43:06 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:43:05 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:43:02 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:43:01 PM	PostgreSQL	0	None	"2018-05-26 15:43:01 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:43:01 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:43:01 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:42:58 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:42:57 PM	PostgreSQL	0	None	"2018-05-26 15:42:57 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:42:57 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:42:57 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:42:53 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:42:52 PM	PostgreSQL	0	None	"2018-05-26 15:42:52 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:42:52 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:42:52 PM	PostgreSQL	0	None	Waiting for server startup...

Error	5/26/2018 3:42:49 PM	PostgreSQL	0	None	Timed out waiting for server startup

Error	5/26/2018 3:42:48 PM	PostgreSQL	0	None	"2018-05-26 15:42:48 IST FATAL:  lock file ""postmaster.pid"" already exists
2018-05-26 15:42:48 IST HINT:  Is another postmaster (PID 5800) running in data directory ""C:/Program Files/PostgreSQL/9.5/data""?
"
Information	5/26/2018 3:42:48 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/26/2018 3:39:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎26T10:09:28.383474100Z.
Information	5/26/2018 3:39:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{BD100D3A-5BD0-4470-834C-32BE48D2BBB3}\4Sight™ 2.msi. Client Process Id: 9964.
Information	5/26/2018 3:20:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35b14770-60ca-11e8-a13d-0205857feb80
Report Status: 0"
Information	5/26/2018 3:12:52 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎26T09:42:28.475502000Z.
Information	5/26/2018 3:12:52 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15656.
Information	5/26/2018 3:12:52 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.168. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/26/2018 3:12:52 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/26/2018 3:12:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎26T09:42:28.475502000Z.
Information	5/26/2018 3:12:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15656.
Information	5/26/2018 2:57:08 PM	MTAService.OnSessionChange	0	None	2:57:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/26/2018 2:24:37 PM	MTAService.OnSessionChange	0	None	2:24:37 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/26/2018 1:51:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 1:26:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 1:26:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:01Z. Reason: GVLK.
Information	5/26/2018 1:21:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 1:21:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 1:21:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 1:21:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 1:05:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 1:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/26/2018 1:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53575)(?)])(1 )(2 )]

"
Information	5/26/2018 1:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53575)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 1:00:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/26/2018 1:00:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 1:00:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:56:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:56:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:01Z. Reason: GVLK.
Information	5/26/2018 12:51:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 12:51:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:51:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:51:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:49:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:44:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/26/2018 12:44:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53591)(?)])(1 )(2 )]

"
Information	5/26/2018 12:44:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53591)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:44:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/26/2018 12:44:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:44:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:39:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8904.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/26/2018 12:26:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:26:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:04Z. Reason: GVLK.
Information	5/26/2018 12:25:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:21:54 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 23688, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/26/2018 12:21:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 12:21:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:21:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:21:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:20:16 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/26/2018 12:20:08 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 358

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 452

Information	5/26/2018 12:19:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53616)(?)])(1 )(2 )]

"
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53616)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:19:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:15:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:15:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:05Z. Reason: GVLK.
Information	5/26/2018 12:13:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 12:09:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	5/26/2018 12:09:19 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/26/2018 12:08:20 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/26/2018 12:08:17 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/26/2018 12:08:17 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/26/2018 12:08:15 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/26/2018 12:08:01 PM	ESENT	302	Logging/Recovery	Windows (7772) Windows: The database engine has successfully completed recovery steps.
Information	5/26/2018 12:07:58 PM	ESENT	301	Logging/Recovery	Windows (7772) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Error	5/26/2018 12:07:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/26/2018 12:07:49 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/26/2018 12:07:42 PM	ESENT	301	Logging/Recovery	Windows (7772) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0081B.log.
Information	5/26/2018 12:07:42 PM	ESENT	300	Logging/Recovery	Windows (7772) Windows: The database engine is initiating recovery steps.
Information	5/26/2018 12:07:41 PM	ESENT	102	General	Windows (7772) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/26/2018 12:07:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 12:07:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:07:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:07:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/26/2018 12:07:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53628)(?)])(1 )(2 )]

"
Information	5/26/2018 12:07:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53628)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 12:07:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/26/2018 12:07:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 12:07:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 12:07:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/26/2018 12:07:17 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/26/2018 12:06:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8903.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	5/26/2018 12:06:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/26/2018 12:06:36 PM	Service1	0	None	Service started successfully.
Information	5/26/2018 12:06:35 PM	MTAService	0	None	Service started successfully.
Error	5/26/2018 12:06:17 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/26/2018 12:06:17 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/26/2018 12:05:59 PM	PostgreSQL	0	None	"2018-05-26 12:05:59 IST LOG:  redirecting log output to logging collector process
2018-05-26 12:05:59 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/26/2018 12:05:54 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/26/2018 12:05:53 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/26/2018 12:05:51 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/26/2018 12:05:49 PM	MTAService.OnStart	0	None	12:05:49 PM - User is already logged in : 212558710
Information	5/26/2018 12:05:44 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/26/2018 12:05:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/26/2018 12:05:43 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/26/2018 12:05:43 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/26/2018 12:05:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/26/2018 12:05:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/26/2018 12:05:35 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:34 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/26/2018 12:05:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/26/2018 12:05:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/26/2018 12:05:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/26/2018 12:05:34 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/26/2018 12:05:33 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:32 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/26/2018 12:05:32 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/26/2018 12:05:32 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/26/2018 12:05:32 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/26/2018 12:05:29 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/26/2018 12:05:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/26/2018 12:05:29 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/26/2018 12:05:28 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4044 at 5/25/2018 2:16:28 PM (local) 5/25/2018 8:46:28 AM (UTC). This is an informational message only; no user action is required.
Information	5/26/2018 12:05:26 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/26/2018 12:05:26 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/26/2018 12:05:26 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/26/2018 12:05:26 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/26/2018 12:05:26 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3276.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/26/2018 12:05:25 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/26/2018 12:04:14 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/26/2018 12:03:30 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/26/2018 12:03:08 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/26/2018 12:03:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/26/2018 12:03:08 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/26/2018 10:52:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 10:52:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:59Z. Reason: GVLK.
Information	5/26/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 10:20:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4bf2e9c3-60a0-11e8-810d-0205857feb80
Report Status: 0"
Error	5/26/2018 10:11:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/26/2018 9:48:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/26/2018 8:07:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 7:07:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 7:07:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/26/2018 6:23:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 5:20:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6238719c-6076-11e8-810d-0205857feb80
Report Status: 0"
Information	5/26/2018 4:42:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 4:42:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:25Z. Reason: GVLK.
Information	5/26/2018 4:37:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 4:37:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 4:37:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 4:37:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/26/2018 4:35:40 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/26/2018 4:33:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 4:33:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:34Z. Reason: GVLK.
Warning	5/26/2018 4:28:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/26/2018 4:28:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/26/2018 4:28:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/26/2018 4:28:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 4:28:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 4:28:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 4:14:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/26/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/26/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54105)(?)])(1 )(2 )]

"
Information	5/26/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54105)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/26/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/26/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/26/2018 4:09:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/26/2018 3:07:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 3:07:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/26/2018 2:42:45 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/26/2018 2:38:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/26/2018 12:57:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/26/2018 12:20:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7855fdb1-604c-11e8-810d-0205857feb80
Report Status: 0"
Information	5/25/2018 11:36:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 11:36:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:11Z. Reason: GVLK.
Information	5/25/2018 11:31:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 11:31:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 11:31:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 11:31:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 11:07:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 11:07:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/25/2018 10:57:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 10:03:12 PM	MTAService.OnSessionChange	0	None	10:03:12 PM - Session change notice received: SessionLock Session ID: 1
Information	5/25/2018 9:46:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54494)(?)])(1 )(2 )]

"
Information	5/25/2018 9:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54494)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:36:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:36:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54498)(?)])(1 )(2 )]

"
Information	5/25/2018 9:36:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54498)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:36:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 9:36:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:36:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 9:34:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:31:35 PM	MTAService.OnSessionChange	0	None	9:31:35 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/25/2018 9:29:51 PM	MTAService.OnSessionChange	0	None	9:29:51 PM - Session change notice received: SessionLock Session ID: 1
Information	5/25/2018 9:29:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:29:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54506)(?)])(1 )(2 )]

"
Information	5/25/2018 9:29:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54506)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:29:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 9:29:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:29:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 9:24:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:18:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:18:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54516)(?)])(1 )(2 )]

"
Information	5/25/2018 9:18:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54516)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:17:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54518)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:17:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54518)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:17:18 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/25/2018 9:17:18 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/25/2018 9:17:17 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	5/25/2018 9:17:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 9:17:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:17:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/25/2018 9:06:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 7:20:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e98b4f9-6022-11e8-810d-204747d02364
Report Status: 0"
Warning	5/25/2018 7:16:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 7:07:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 7:07:40 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/25/2018 7:07:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 7:04:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 6:59:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 6:59:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54656)(?)])(1 )(2 )]

"
Information	5/25/2018 6:59:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54656)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 6:59:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 6:59:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 6:59:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 6:31:45 PM	MTAService.OnSessionChange	0	None	6:31:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/25/2018 5:53:24 PM	MTAService.OnSessionChange	0	None	5:53:24 PM - Session change notice received: SessionLock Session ID: 1
Information	5/25/2018 5:51:15 PM	MTAService.OnSessionChange	0	None	5:51:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/25/2018 5:48:14 PM	MTAService.OnSessionChange	0	None	5:48:14 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/25/2018 5:39:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 5:11:23 PM	MTAService.OnSessionChange	0	None	5:11:23 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/25/2018 4:33:57 PM	MTAService.OnSessionChange	0	None	4:33:57 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/25/2018 4:06:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 3:38:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 3:38:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:02Z. Reason: GVLK.
Information	5/25/2018 3:33:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 3:33:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 3:33:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 3:33:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 3:12:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 3:08:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 3:08:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:03Z. Reason: GVLK.
Information	5/25/2018 3:07:22 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 390

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 390

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 577

Information	5/25/2018 3:07:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 3:06:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 3:06:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54888)(?)])(1 )(2 )]

"
Information	5/25/2018 3:06:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54888)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 3:06:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 3:06:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 3:06:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 3:03:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 3:03:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 3:03:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 3:03:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 2:38:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 2:38:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:03Z. Reason: GVLK.
Information	5/25/2018 2:33:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 2:33:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 2:33:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 2:33:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 2:25:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 2:25:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:12Z. Reason: GVLK.
Information	5/25/2018 2:24:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/25/2018 2:21:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 2:19:25 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/25/2018 2:19:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/25/2018 2:19:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 2:19:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54936)(?)])(1 )(2 )]

"
Information	5/25/2018 2:19:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54936)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 2:19:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 2:19:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 2:19:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 2:18:33 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 2:18:31 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 2:18:30 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 2:18:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 2:18:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 2:18:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 2:18:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 2:17:53 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/25/2018 2:17:44 PM	MTAService.OnSessionChange	0	None	2:17:44 PM - Logon : 212558710
Information	5/25/2018 2:17:44 PM	MTAService.OnSessionChange	0	None	2:17:44 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/25/2018 2:17:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/25/2018 2:17:44 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/25/2018 2:17:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/25/2018 2:17:43 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/25/2018 2:17:38 PM	ESENT	302	Logging/Recovery	Windows (7312) Windows: The database engine has successfully completed recovery steps.
Information	5/25/2018 2:17:36 PM	ESENT	301	Logging/Recovery	Windows (7312) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/25/2018 2:17:32 PM	ESENT	301	Logging/Recovery	Windows (7312) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00816.log.
Information	5/25/2018 2:17:32 PM	ESENT	300	Logging/Recovery	Windows (7312) Windows: The database engine is initiating recovery steps.
Information	5/25/2018 2:17:32 PM	ESENT	102	General	Windows (7312) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/25/2018 2:17:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8903.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/25/2018 2:17:05 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/25/2018 2:17:04 PM	Service1	0	None	Service started successfully.
Error	5/25/2018 2:17:00 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/25/2018 2:17:00 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/25/2018 2:16:55 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/25/2018 2:16:44 PM	PostgreSQL	0	None	"2018-05-25 14:16:44 IST LOG:  redirecting log output to logging collector process
2018-05-25 14:16:44 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/25/2018 2:16:44 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/25/2018 2:16:42 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/25/2018 2:16:41 PM	MTAService	0	None	Service started successfully.
Information	5/25/2018 2:16:40 PM	MTAService.OnStart	0	None	2:16:40 PM - Waiting for user to Logon
Information	5/25/2018 2:16:39 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:38 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/25/2018 2:16:38 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/25/2018 2:16:37 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/25/2018 2:16:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/25/2018 2:16:37 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/25/2018 2:16:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/25/2018 2:16:36 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/25/2018 2:16:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/25/2018 2:16:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/25/2018 2:16:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/25/2018 2:16:30 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:30 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/25/2018 2:16:29 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/25/2018 2:16:29 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/25/2018 2:16:29 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/25/2018 2:16:28 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3660 at 5/25/2018 9:13:35 AM (local) 5/25/2018 3:43:35 AM (UTC). This is an informational message only; no user action is required.
Information	5/25/2018 2:16:27 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/25/2018 2:16:26 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/25/2018 2:16:26 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/25/2018 2:16:26 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/25/2018 2:16:26 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4044.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/25/2018 2:16:23 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/25/2018 2:15:45 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/25/2018 2:15:38 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 2:15:31 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/25/2018 2:15:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/25/2018 2:15:31 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/25/2018 1:22:45 PM	MTAService.OnSessionChange	0	None	1:22:45 PM - Session change notice received: SessionLock Session ID: 1
Information	5/25/2018 1:22:26 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.3.0.191. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/25/2018 1:22:26 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	5/25/2018 1:22:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎25T07:51:40.863586600Z.
Information	5/25/2018 1:22:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0E089F16-712E-4638-BB35-9A8BD5B77803}\DeviceManager.msi. Client Process Id: 2848.
Information	5/25/2018 1:21:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎25T07:51:40.863586600Z.
Information	5/25/2018 1:21:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0E089F16-712E-4638-BB35-9A8BD5B77803}\DeviceManager.msi. Client Process Id: 2848.
Information	5/25/2018 1:21:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎25T07:51:16.195586600Z.
Information	5/25/2018 1:21:32 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D1807E13-00B8-419F-8F12-F8338423606C}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 13408.
Information	5/25/2018 1:21:32 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.191. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/25/2018 1:21:32 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	5/25/2018 1:21:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎25T07:51:16.195586600Z.
Information	5/25/2018 1:21:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D1807E13-00B8-419F-8F12-F8338423606C}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 13408.
Information	5/25/2018 1:20:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 1:20:17 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/25/2018 1:19:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 1:12:26 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.3.0.181. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	5/25/2018 1:12:26 PM	MsiInstaller	11708	None	Product: DeviceManager -- Installation operation failed.
Information	5/25/2018 1:11:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎25T07:41:14.633642100Z.
Information	5/25/2018 1:11:15 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{44725E28-50AD-4524-874A-4810BF0F6239}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 13868.
Information	5/25/2018 1:11:15 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.181. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	5/25/2018 1:11:15 PM	MsiInstaller	11708	None	Product: DeviceDriver -- Installation operation failed.
Error	5/25/2018 1:11:15 PM	MsiInstaller	11334	None	Product: DeviceDriver -- Error 1334. The file 'gedevice2.dll' cannot be installed because the file cannot be found in cabinet file 'Data1.cab'. This could indicate a network error, an error reading from the CD-ROM, or a problem with this package.
Information	5/25/2018 1:11:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎25T07:41:14.633642100Z.
Information	5/25/2018 1:11:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{44725E28-50AD-4524-874A-4810BF0F6239}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 13868.
Information	5/25/2018 1:07:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 12556.
Information	5/25/2018 1:07:00 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Driver Manager. Product Version: 1.3.0.0. Product Language: 1033. Manufacturer: GE. Reconfiguration success or error status: 1602.
Information	5/25/2018 1:07:00 PM	MsiInstaller	11729	None	Product: Driver Manager -- Configuration failed.
Information	5/25/2018 1:06:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 12556.
Information	5/25/2018 1:06:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎25T07:36:41.655347000Z.
Information	5/25/2018 1:06:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 12556.
Information	5/25/2018 1:06:46 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.168. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/25/2018 1:06:46 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	5/25/2018 1:06:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎25T07:36:41.655347000Z.
Information	5/25/2018 1:06:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 12556.
Information	5/25/2018 1:06:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎25T07:35:46.646846700Z.
Information	5/25/2018 1:06:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 12556.
Information	5/25/2018 1:06:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.3.0.168. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/25/2018 1:06:27 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	5/25/2018 1:05:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎25T07:35:46.646846700Z.
Information	5/25/2018 1:05:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 12556.
Warning	5/25/2018 12:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 12:04:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8903.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/25/2018 11:13:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 11:08:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 11:08:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55126)(?)])(1 )(2 )]

"
Information	5/25/2018 11:08:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55126)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 11:08:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 11:08:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 11:08:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/25/2018 10:50:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/25/2018 10:34:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 10:34:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:11Z. Reason: GVLK.
Information	5/25/2018 10:29:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 10:29:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 10:29:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 10:29:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/25/2018 10:11:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/25/2018 10:04:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 10:04:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:10Z. Reason: GVLK.
Information	5/25/2018 10:04:08 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/25/2018 10:03:59 AM	MTAService.OnSessionChange	0	None	10:03:59 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/25/2018 9:59:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 9:59:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:59:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:59:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 9:43:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:43:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:13Z. Reason: GVLK.
Information	5/25/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:38:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/25/2018 9:36:41 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/25/2018 9:34:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:34:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:09Z. Reason: GVLK.
Information	5/25/2018 9:29:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/25/2018 9:29:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/25/2018 9:27:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/25/2018 9:26:29 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 14, Deleted: 0, Modified: 42, Compared: 23621, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/25/2018 9:24:37 AM	MTAService.OnSessionChange	0	None	9:24:37 AM - Session change notice received: SessionLock Session ID: 1
Information	5/25/2018 9:22:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:22:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55233)(?)])(1 )(2 )]

"
Information	5/25/2018 9:22:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55233)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:20:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/25/2018 9:20:46 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 219

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 577

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 250

Information	5/25/2018 9:19:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/25/2018 9:19:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	5/25/2018 9:19:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:18:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89a8f85b-5fce-11e8-8ce0-204747d02364
Report Status: 0"
Information	5/25/2018 9:18:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55236)(?)])(1 )(2 )]

"
Information	5/25/2018 9:18:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55236)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:17:46 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/25/2018 9:17:11 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/25/2018 9:16:21 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 9:16:19 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 9:16:16 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 9:16:06 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/25/2018 9:15:52 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/25/2018 9:15:47 AM	ESENT	302	Logging/Recovery	Windows (8704) Windows: The database engine has successfully completed recovery steps.
Information	5/25/2018 9:15:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/25/2018 9:15:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55239)(?)])(1 )(2 )]

"
Information	5/25/2018 9:15:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55239)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:15:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/25/2018 9:15:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:15:40 AM	ESENT	301	Logging/Recovery	Windows (8704) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/25/2018 9:15:40 AM	ESENT	300	Logging/Recovery	Windows (8704) Windows: The database engine is initiating recovery steps.
Information	5/25/2018 9:15:40 AM	ESENT	102	General	Windows (8704) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/25/2018 9:15:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/25/2018 9:15:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/25/2018 9:15:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/25/2018 9:15:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/25/2018 9:15:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/25/2018 9:15:30 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/25/2018 9:15:07 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8902.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	5/25/2018 9:15:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/25/2018 9:15:03 AM	Service1	0	None	Service started successfully.
Error	5/25/2018 9:14:53 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/25/2018 9:14:52 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/25/2018 9:14:44 AM	MTAService	0	None	Service started successfully.
Error	5/25/2018 9:14:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/25/2018 9:14:21 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/25/2018 9:14:18 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/25/2018 9:14:01 AM	PostgreSQL	0	None	"2018-05-25 09:14:01 IST LOG:  redirecting log output to logging collector process
2018-05-25 09:14:01 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/25/2018 9:13:58 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/25/2018 9:13:56 AM	MTAService.OnStart	0	None	9:13:55 AM - User is already logged in : 212558710
Information	5/25/2018 9:13:54 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/25/2018 9:13:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/25/2018 9:13:53 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/25/2018 9:13:53 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/25/2018 9:13:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/25/2018 9:13:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/25/2018 9:13:47 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:47 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/25/2018 9:13:46 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/25/2018 9:13:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/25/2018 9:13:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/25/2018 9:13:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/25/2018 9:13:45 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/25/2018 9:13:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/25/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:43 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/25/2018 9:13:43 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/25/2018 9:13:43 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/25/2018 9:13:43 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/25/2018 9:13:36 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/25/2018 9:13:36 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/25/2018 9:13:36 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/25/2018 9:13:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/25/2018 9:13:35 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 2268 at 5/23/2018 6:09:09 PM (local) 5/23/2018 12:39:09 PM (UTC). This is an informational message only; no user action is required.
Information	5/25/2018 9:13:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/25/2018 9:13:33 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/25/2018 9:13:33 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/25/2018 9:13:33 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/25/2018 9:13:33 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3660.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/25/2018 9:13:32 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/25/2018 9:12:33 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/25/2018 9:11:55 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/25/2018 9:11:36 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/25/2018 9:11:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/25/2018 9:11:36 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	5/24/2018 8:47:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 8:44:36 PM	MTAService.OnSessionChange	0	None	8:44:36 PM - Session change notice received: SessionLock Session ID: 1
Information	5/24/2018 8:13:14 PM	MTAService.OnSessionChange	0	None	8:13:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/24/2018 8:12:13 PM	MTAService.OnSessionChange	0	None	8:12:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/24/2018 6:53:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 6:46:04 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/24/2018 6:45:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/24/2018 6:12:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e2fb239a-5f4f-11e8-8936-204747d02364
Report Status: 0"
Information	5/24/2018 6:11:31 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/24/2018 5:53:07 PM	MTAService.OnSessionChange	0	None	5:53:07 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/24/2018 5:12:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 4:57:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/24/2018 4:55:48 PM	MTAService.OnSessionChange	0	None	4:55:48 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/24/2018 3:14:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 2:59:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/24/2018 2:59:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56336)(?)])(1 )(2 )]

"
Information	5/24/2018 2:59:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56336)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 2:16:04 PM	MTAService.OnSessionChange	0	None	2:16:04 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/24/2018 1:29:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 1:12:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f9570fd0-5f25-11e8-8936-204747d02364
Report Status: 0"
Information	5/24/2018 1:06:14 PM	MTAService.OnSessionChange	0	None	1:06:14 PM - Session change notice received: SessionLock Session ID: 1
Information	5/24/2018 12:58:42 PM	MTAService.OnSessionChange	0	None	12:58:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/24/2018 12:57:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/24/2018 12:51:08 PM	MTAService.OnSessionChange	0	None	12:51:08 PM - Session change notice received: SessionLock Session ID: 1
Information	5/24/2018 12:24:41 PM	MTAService.OnSessionChange	0	None	12:24:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/24/2018 12:18:55 PM	MTAService.OnSessionChange	0	None	12:18:55 PM - Session change notice received: SessionLock Session ID: 1
Information	5/24/2018 12:07:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8902.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/24/2018 11:44:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 11:31:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/24/2018 11:31:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:16Z. Reason: GVLK.
Information	5/24/2018 11:26:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/24/2018 11:26:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 11:26:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/24/2018 11:26:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/24/2018 10:11:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/24/2018 10:01:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 9:57:35 AM	MTAService.OnSessionChange	0	None	9:57:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/24/2018 9:24:02 AM	MTAService.OnSessionChange	0	None	9:24:02 AM - Session change notice received: SessionLock Session ID: 1
Information	5/24/2018 8:57:35 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 437

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 109

Information	5/24/2018 8:57:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/24/2018 8:57:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/24/2018 8:57:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56698)(?)])(1 )(2 )]

"
Information	5/24/2018 8:57:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56698)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 8:56:19 AM	MTAService.OnSessionChange	0	None	8:56:19 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/24/2018 8:40:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/24/2018 8:40:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:19Z. Reason: GVLK.
Information	5/24/2018 8:35:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/24/2018 8:35:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 8:35:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/24/2018 8:35:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/24/2018 8:20:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 8:12:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f96bc9f-5efc-11e8-8936-204747d02364
Report Status: 0"
Warning	5/24/2018 6:38:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/24/2018 4:49:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 4:48:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/24/2018 4:48:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:47Z. Reason: GVLK.
Information	5/24/2018 4:43:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/24/2018 4:43:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 4:43:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/24/2018 4:43:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/24/2018 4:41:44 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/24/2018 4:39:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/24/2018 4:39:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:09Z. Reason: GVLK.
Error	5/24/2018 4:34:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/24/2018 4:34:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/24/2018 4:34:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 4:34:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/24/2018 4:34:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/24/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/24/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56985)(?)])(1 )(2 )]

"
Information	5/24/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56985)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 3:12:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25f084dd-5ed2-11e8-8936-204747d02364
Report Status: 0"
Warning	5/24/2018 3:07:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/24/2018 1:17:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/24/2018 12:12:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/24/2018 12:12:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:31Z. Reason: GVLK.
Information	5/24/2018 12:07:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/24/2018 12:07:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/24/2018 12:07:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/24/2018 12:07:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/24/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/23/2018 11:33:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 10:12:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3c45a9a3-5ea8-11e8-8936-204747d02364
Report Status: 0"
Warning	5/23/2018 9:46:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 9:10:07 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/23/2018 9:08:04 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/23/2018 9:03:20 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/23/2018 8:23:47 PM	MTAService.OnSessionChange	0	None	8:23:47 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/23/2018 8:01:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 7:50:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 7:50:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 7:50:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 7:50:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 7:44:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 7:44:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57490)(?)])(1 )(2 )]

"
Information	5/23/2018 7:44:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57490)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 7:44:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 7:44:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 7:44:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 7:35:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 7:30:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 7:30:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:07Z. Reason: GVLK.
Information	5/23/2018 7:29:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 7:29:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57505)(?)])(1 )(2 )]

"
Information	5/23/2018 7:29:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 7:29:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 7:29:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 7:29:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 7:25:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 7:25:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 7:25:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 7:25:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 7:24:19 PM	MTAService.OnSessionChange	0	None	7:24:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/23/2018 7:05:14 PM	MTAService.OnSessionChange	0	None	7:05:14 PM - Session change notice received: SessionLock Session ID: 1
Information	5/23/2018 7:00:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 7:00:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:06Z. Reason: GVLK.
Information	5/23/2018 6:55:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 6:55:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:55:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:55:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 6:51:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 6:46:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 6:46:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57548)(?)])(1 )(2 )]

"
Information	5/23/2018 6:46:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57548)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:46:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 6:46:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:46:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 6:30:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 6:30:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:15:07Z. Reason: GVLK.
Information	5/23/2018 6:25:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 6:25:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:25:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:25:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 6:18:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 6:18:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:46Z. Reason: GVLK.
Information	5/23/2018 6:18:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 6:12:59 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/23/2018 6:12:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 6:12:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57582)(?)])(1 )(2 )]

"
Information	5/23/2018 6:12:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57582)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/23/2018 6:12:18 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 6:12:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 6:12:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57583)(?)])(1 )(2 )]

"
Information	5/23/2018 6:12:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57583)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:12:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 6:12:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:12:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 6:11:48 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 6:11:46 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 6:11:43 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 6:11:39 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/23/2018 6:11:10 PM	ESENT	302	Logging/Recovery	Windows (5400) Windows: The database engine has successfully completed recovery steps.
Information	5/23/2018 6:11:10 PM	ESENT	301	Logging/Recovery	Windows (5400) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/23/2018 6:11:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 6:11:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:11:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:10:56 PM	ESENT	301	Logging/Recovery	Windows (5400) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00808.log.
Information	5/23/2018 6:10:56 PM	ESENT	300	Logging/Recovery	Windows (5400) Windows: The database engine is initiating recovery steps.
Information	5/23/2018 6:10:56 PM	ESENT	102	General	Windows (5400) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/23/2018 6:10:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/23/2018 6:10:53 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/23/2018 6:10:51 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/23/2018 6:10:33 PM	Service1	0	None	Service started successfully.
Error	5/23/2018 6:09:59 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/23/2018 6:09:58 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/23/2018 6:09:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8901.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/23/2018 6:09:49 PM	MTAService.OnSessionChange	0	None	6:09:49 PM - Logon : 212558710
Information	5/23/2018 6:09:49 PM	MTAService.OnSessionChange	0	None	6:09:48 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/23/2018 6:09:33 PM	PostgreSQL	0	None	"2018-05-23 18:09:33 IST LOG:  redirecting log output to logging collector process
2018-05-23 18:09:33 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/23/2018 6:09:31 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/23/2018 6:09:31 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/23/2018 6:09:29 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/23/2018 6:09:25 PM	MTAService	0	None	Service started successfully.
Information	5/23/2018 6:09:25 PM	MTAService.OnStart	0	None	6:09:24 PM - Waiting for user to Logon
Information	5/23/2018 6:09:25 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/23/2018 6:09:25 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/23/2018 6:09:25 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/23/2018 6:09:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/23/2018 6:09:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/23/2018 6:09:21 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/23/2018 6:09:16 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:15 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/23/2018 6:09:14 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/23/2018 6:09:14 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/23/2018 6:09:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/23/2018 6:09:14 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/23/2018 6:09:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/23/2018 6:09:12 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:12 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/23/2018 6:09:12 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/23/2018 6:09:11 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/23/2018 6:09:11 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/23/2018 6:09:11 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/23/2018 6:09:11 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 6:09:11 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 6:09:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/23/2018 6:09:09 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/23/2018 6:09:09 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:09 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/23/2018 6:09:09 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/23/2018 6:09:08 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/23/2018 6:09:08 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 1004 at 5/23/2018 10:05:23 AM (local) 5/23/2018 4:35:23 AM (UTC). This is an informational message only; no user action is required.
Information	5/23/2018 6:09:06 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/23/2018 6:09:05 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/23/2018 6:09:05 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/23/2018 6:09:05 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/23/2018 6:09:05 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 2268.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/23/2018 6:09:02 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/23/2018 6:07:46 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/23/2018 6:07:08 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 6:06:45 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/23/2018 6:06:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/23/2018 6:06:46 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/23/2018 5:12:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 52c078e9-5e7e-11e8-a467-204747d02364
Report Status: 0"
Information	5/23/2018 4:57:29 PM	MTAService.OnSessionChange	0	None	4:57:29 PM - Session change notice received: SessionLock Session ID: 1
Information	5/23/2018 4:50:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/23/2018 4:41:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 3:46:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 3:46:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:54Z. Reason: GVLK.
Information	5/23/2018 3:41:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 3:41:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 3:41:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 3:41:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/23/2018 3:38:21 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/23/2018 3:24:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 3:24:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:21Z. Reason: GVLK.
Information	5/23/2018 3:19:04 PM	McLogEvent	257	None	The scan of D:\4sightv2\SetUpFile_2018_05_11_Fr_19_50_58_9382\DISK1\ISSetupPrerequisites\{7E4BD306-FC5C-4706-91E0-21DEB7567637}\postgresql-9.5.3-1-windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8901.0000.
Error	5/23/2018 3:15:31 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 3:14:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 3:14:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 3:14:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 3:14:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/23/2018 3:09:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 2:12:29 PM	MTAService.OnSessionChange	0	None	2:12:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/23/2018 1:50:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 1:50:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-30T08:14:13Z. Reason: GVLK.
Information	5/23/2018 1:45:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 1:45:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 1:45:13 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/05/23 08:15"
Information	5/23/2018 1:45:09 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/05/23 08:15, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	5/23/2018 1:39:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 1:39:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 1:39:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 1:39:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/23/2018 1:33:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 1:10:30 PM	MTAService.OnSessionChange	0	None	1:10:30 PM - Session change notice received: SessionLock Session ID: 1
Information	5/23/2018 12:50:50 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 530

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 608

Information	5/23/2018 12:50:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/23/2018 12:50:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 12:50:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57905)(?)])(1 )(2 )]

"
Information	5/23/2018 12:50:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 12:12:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 68d4e020-5e54-11e8-a467-204747d02364
Report Status: 0"
Warning	5/23/2018 11:40:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 11:40:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 11:40:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 11:40:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 11:25:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 11:25:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:55Z. Reason: GVLK.
Information	5/23/2018 11:23:02 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8901.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/23/2018 11:20:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 11:20:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 11:20:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 11:20:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 10:55:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 10:55:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:55Z. Reason: GVLK.
Information	5/23/2018 10:50:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 10:50:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 10:50:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 10:50:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 10:25:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 10:25:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:56Z. Reason: GVLK.
Information	5/23/2018 10:20:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 10:20:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 10:20:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 10:20:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 10:17:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 10:14:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 10:14:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:59Z. Reason: GVLK.
Information	5/23/2018 10:11:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 10:11:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58063)(?)])(1 )(2 )]

"
Information	5/23/2018 10:11:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58063)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/23/2018 10:10:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 10:09:12 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/23/2018 10:08:08 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 10:08:06 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 10:08:05 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 10:08:03 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/23/2018 10:07:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 10:07:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58067)(?)])(1 )(2 )]

"
Information	5/23/2018 10:07:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58067)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 10:07:48 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/23/2018 10:07:48 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 10:07:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 10:07:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 10:07:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 10:07:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 10:07:37 AM	ESENT	302	Logging/Recovery	Windows (8332) Windows: The database engine has successfully completed recovery steps.
Information	5/23/2018 10:07:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/23/2018 10:07:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 10:07:30 AM	ESENT	301	Logging/Recovery	Windows (8332) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/23/2018 10:07:30 AM	ESENT	300	Logging/Recovery	Windows (8332) Windows: The database engine is initiating recovery steps.
Information	5/23/2018 10:07:30 AM	ESENT	102	General	Windows (8332) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	5/23/2018 10:07:08 AM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/23/2018 10:06:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8900.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/23/2018 10:06:23 AM	Service1	0	None	Service started successfully.
Information	5/23/2018 10:06:22 AM	MTAService	0	None	Service started successfully.
Error	5/23/2018 10:06:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/23/2018 10:06:04 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/23/2018 10:06:04 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/23/2018 10:05:46 AM	PostgreSQL	0	None	"2018-05-23 10:05:46 IST LOG:  redirecting log output to logging collector process
2018-05-23 10:05:46 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/23/2018 10:05:44 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/23/2018 10:05:43 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/23/2018 10:05:42 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/23/2018 10:05:40 AM	MTAService.OnStart	0	None	10:05:39 AM - User is already logged in : 212558710
Information	5/23/2018 10:05:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/23/2018 10:05:38 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/23/2018 10:05:38 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/23/2018 10:05:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/23/2018 10:05:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/23/2018 10:05:37 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/23/2018 10:05:34 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:34 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/23/2018 10:05:34 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/23/2018 10:05:34 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/23/2018 10:05:34 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/23/2018 10:05:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/23/2018 10:05:33 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/23/2018 10:05:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/23/2018 10:05:32 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/23/2018 10:05:31 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:31 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/23/2018 10:05:31 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/23/2018 10:05:31 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/23/2018 10:05:31 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/23/2018 10:05:24 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/23/2018 10:05:24 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 10:05:24 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/23/2018 10:05:23 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 1156 at 5/22/2018 12:09:19 PM (local) 5/22/2018 6:39:19 AM (UTC). This is an informational message only; no user action is required.
Information	5/23/2018 10:05:21 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/23/2018 10:05:20 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/23/2018 10:05:20 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/23/2018 10:05:20 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/23/2018 10:05:20 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 1004.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/23/2018 10:05:19 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/23/2018 10:04:20 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/23/2018 10:03:45 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 10:03:25 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/23/2018 10:03:25 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/23/2018 10:03:25 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/23/2018 10:01:50 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8900.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/23/2018 10:01:48 AM	MTAService	0	None	Service started successfully.
Information	5/23/2018 10:01:48 AM	Service1	0	None	Service started successfully.
Error	5/23/2018 10:01:32 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/23/2018 10:01:29 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	5/23/2018 10:01:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 10:01:03 AM	PostgreSQL	0	None	"2018-05-23 10:01:03 IST LOG:  redirecting log output to logging collector process
2018-05-23 10:01:03 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/23/2018 10:00:59 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/23/2018 10:00:59 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/23/2018 10:00:57 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/23/2018 10:00:50 AM	MTAService.OnStart	0	None	10:00:50 AM - User is already logged in : 212558710
Information	5/23/2018 10:00:48 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/23/2018 10:00:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/23/2018 10:00:45 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/23/2018 10:00:45 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/23/2018 10:00:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/23/2018 10:00:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/23/2018 10:00:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:40 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/23/2018 10:00:40 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/23/2018 10:00:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/23/2018 10:00:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/23/2018 10:00:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/23/2018 10:00:39 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/23/2018 10:00:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:38 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/23/2018 10:00:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/23/2018 10:00:37 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/23/2018 10:00:37 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/23/2018 10:00:33 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/23/2018 10:00:33 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 10:00:33 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/23/2018 10:00:32 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 1156 at 5/22/2018 12:09:19 PM (local) 5/22/2018 6:39:19 AM (UTC). This is an informational message only; no user action is required.
Information	5/23/2018 10:00:28 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/23/2018 10:00:28 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/23/2018 10:00:28 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/23/2018 10:00:28 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/23/2018 10:00:28 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 1940.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/23/2018 10:00:27 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/23/2018 9:59:31 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/23/2018 9:58:51 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/23/2018 9:58:32 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/23/2018 9:58:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/23/2018 9:58:32 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/23/2018 9:32:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 9:32:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:06Z. Reason: GVLK.
Information	5/23/2018 9:27:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 9:27:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 9:27:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 9:27:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 9:23:03 AM	MTAService.OnSessionChange	0	None	9:23:03 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/23/2018 9:14:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 9:09:17 AM	MTAService.OnSessionChange	0	None	9:09:17 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/23/2018 8:32:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/23/2018 7:29:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 7:12:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7fbed330-5e2a-11e8-a61f-eb6664da13dc
Report Status: 0"
Information	5/23/2018 6:38:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 6:38:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:55Z. Reason: GVLK.
Information	5/23/2018 6:33:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 6:33:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 6:33:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 6:33:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/23/2018 5:52:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 4:31:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/23/2018 4:16:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 4:16:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:01Z. Reason: GVLK.
Information	5/23/2018 4:11:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 4:11:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 4:11:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 4:11:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/23/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58425)(?)])(1 )(2 )]

"
Information	5/23/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	5/23/2018 4:09:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/23/2018 4:09:17 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/23/2018 4:06:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/23/2018 4:06:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:11Z. Reason: GVLK.
Error	5/23/2018 4:01:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/23/2018 4:01:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/23/2018 4:01:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/23/2018 4:01:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/23/2018 4:01:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/23/2018 2:54:46 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/23/2018 2:52:22 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	5/23/2018 2:24:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 2:12:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 960ac3a4-5e00-11e8-a61f-eb6664da13dc
Report Status: 0"
Warning	5/23/2018 12:39:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/23/2018 12:31:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/23/2018 12:31:45 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/23/2018 12:31:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/23/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/22/2018 10:44:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 9:12:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac4c20d0-5dd6-11e8-a61f-eb6664da13dc
Report Status: 0"
Warning	5/22/2018 9:09:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 9:05:09 PM	MTAService.OnSessionChange	0	None	9:05:09 PM - Session change notice received: SessionLock Session ID: 1
Information	5/22/2018 8:31:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	5/22/2018 7:59:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 7:59:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 7:59:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58916)(?)])(1 )(2 )]

"
Information	5/22/2018 7:59:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58916)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 7:58:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 7:58:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58917)(?)])(1 )(2 )]

"
Information	5/22/2018 7:58:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58917)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	5/22/2018 7:34:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 6:13:10 PM	MTAService.OnSessionChange	0	None	6:13:10 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/22/2018 5:47:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 5:06:34 PM	MTAService.OnSessionChange	0	None	5:06:34 PM - Session change notice received: SessionLock Session ID: 1
Information	5/22/2018 5:02:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 5:02:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 5:02:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 4:31:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 4:12:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c298bf1b-5dac-11e8-a61f-204747d02364
Report Status: 0"
Warning	5/22/2018 3:48:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 3:47:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 3:42:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 3:42:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59173)(?)])(1 )(2 )]

"
Information	5/22/2018 3:42:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59173)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 3:42:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 3:42:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 3:42:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 3:17:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 3:12:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 3:12:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59202)(?)])(1 )(2 )]

"
Information	5/22/2018 3:12:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59202)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 3:12:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 3:12:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 3:12:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 2:40:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 2:35:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 2:35:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59240)(?)])(1 )(2 )]

"
Information	5/22/2018 2:34:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59240)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 2:34:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 2:34:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 2:34:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/22/2018 2:34:51 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/22/2018 2:34:51 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 2:14:48 PM	MTAService.OnSessionChange	0	None	2:14:48 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/22/2018 1:57:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 1:40:47 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/22/2018 1:30:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 1:30:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:08Z. Reason: GVLK.
Information	5/22/2018 1:25:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 1:25:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 1:25:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 1:25:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 1:16:20 PM	MTAService.OnSessionChange	0	None	1:16:20 PM - Session change notice received: SessionLock Session ID: 1
Information	5/22/2018 1:04:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8900.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/22/2018 1:00:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 1:00:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:08Z. Reason: GVLK.
Information	5/22/2018 12:55:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 12:55:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:55:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:55:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 12:39:58 PM	MTAService.OnSessionChange	0	None	12:39:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/22/2018 12:36:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 12:35:06 PM	MTAService.OnSessionChange	0	None	12:35:06 PM - Session change notice received: SessionLock Session ID: 1
Information	5/22/2018 12:34:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 12:34:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:30Z. Reason: GVLK.
Information	5/22/2018 12:33:03 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 21, Deleted: 0, Modified: 5, Compared: 23228, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/22/2018 12:31:41 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/22/2018 12:31:19 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 421

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 655

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 577

Information	5/22/2018 12:31:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 12:30:41 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	5/22/2018 12:30:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:30:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59364)(?)])(1 )(2 )]

"
Information	5/22/2018 12:30:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59364)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:29:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:29:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59365)(?)])(1 )(2 )]

"
Information	5/22/2018 12:29:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59365)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/22/2018 12:27:45 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/22/2018 12:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59368)(?)])(1 )(2 )]

"
Information	5/22/2018 12:27:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59368)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:26:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:26:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59368)(?)])(1 )(2 )]

"
Information	5/22/2018 12:26:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59368)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:26:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:26:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59369)(?)])(1 )(2 )]

"
Information	5/22/2018 12:26:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59369)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:25:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59369)(?)])(1 )(2 )]

"
Information	5/22/2018 12:25:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59369)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:25:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 12:25:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:25:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 12:25:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 12:25:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:25:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:25:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 12:23:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 12:22:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 12:22:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:28Z. Reason: GVLK.
Information	5/22/2018 12:18:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:18:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59376)(?)])(1 )(2 )]

"
Information	5/22/2018 12:18:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59376)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:18:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 12:18:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:18:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/22/2018 12:16:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 12:15:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 12:12:53 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/22/2018 12:12:25 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8899.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/22/2018 12:11:31 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/22/2018 12:11:31 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/22/2018 12:11:30 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/22/2018 12:11:25 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/22/2018 12:11:08 PM	ESENT	302	Logging/Recovery	Windows (8364) Windows: The database engine has successfully completed recovery steps.
Information	5/22/2018 12:11:07 PM	ESENT	301	Logging/Recovery	Windows (8364) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/22/2018 12:11:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 12:11:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:11:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:11:04 PM	ESENT	301	Logging/Recovery	Windows (8364) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS007FE.log.
Information	5/22/2018 12:11:04 PM	ESENT	300	Logging/Recovery	Windows (8364) Windows: The database engine is initiating recovery steps.
Information	5/22/2018 12:11:04 PM	ESENT	102	General	Windows (8364) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/22/2018 12:11:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 12:10:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 12:10:53 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/22/2018 12:10:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59384)(?)])(1 )(2 )]

"
Information	5/22/2018 12:10:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59384)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 12:10:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/22/2018 12:10:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 12:10:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 12:10:50 PM	PostgreSQL	0	None	Server started and accepting connections

Error	5/22/2018 12:10:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 12:10:35 PM	Service1	0	None	Service started successfully.
Error	5/22/2018 12:10:32 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Error	5/22/2018 12:10:31 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 12:10:30 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/22/2018 12:10:22 PM	MTAService	0	None	Service started successfully.
Information	5/22/2018 12:10:07 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/22/2018 12:10:06 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/22/2018 12:09:55 PM	PostgreSQL	0	None	"2018-05-22 12:09:55 IST LOG:  redirecting log output to logging collector process
2018-05-22 12:09:55 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/22/2018 12:09:53 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/22/2018 12:09:51 PM	MTAService.OnStart	0	None	12:09:51 PM - User is already logged in : 212558710
Information	5/22/2018 12:09:51 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/22/2018 12:09:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/22/2018 12:09:30 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/22/2018 12:09:30 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/22/2018 12:09:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/22/2018 12:09:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/22/2018 12:09:26 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/22/2018 12:09:25 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:25 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/22/2018 12:09:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/22/2018 12:09:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/22/2018 12:09:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/22/2018 12:09:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/22/2018 12:09:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'msdb' (4). This is an informational message only. No user action is required.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/22/2018 12:09:23 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/22/2018 12:09:22 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/22/2018 12:09:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/22/2018 12:09:19 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/22/2018 12:09:19 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:19 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/22/2018 12:09:19 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/22/2018 12:09:18 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3964 at 5/18/2018 7:40:12 PM (local) 5/18/2018 2:10:12 PM (UTC). This is an informational message only; no user action is required.
Information	5/22/2018 12:09:18 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/22/2018 12:09:16 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/22/2018 12:09:15 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/22/2018 12:09:15 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/22/2018 12:09:15 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/22/2018 12:09:15 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 1156.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/22/2018 12:09:14 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/22/2018 12:08:11 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/22/2018 12:07:48 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/22/2018 12:07:19 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/22/2018 12:07:19 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/22/2018 12:07:19 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	5/22/2018 11:21:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 11:12:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8e71354-5d82-11e8-ae03-204747d02364
Report Status: 0"
Information	5/22/2018 10:55:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 10:55:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59460)(?)])(1 )(2 )]

"
Information	5/22/2018 10:55:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 10:50:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 10:50:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:35Z. Reason: GVLK.
Information	5/22/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/22/2018 10:22:00 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/22/2018 10:21:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/22/2018 10:21:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/22/2018 10:10:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 10:10:06 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/22/2018 10:09:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 10:09:30 AM	MTAService.OnSessionChange	0	None	10:09:30 AM - Session change notice received: SessionUnlock Session ID: 1
Error	5/22/2018 10:02:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/22/2018 9:38:34 AM	MTAService.OnSessionChange	0	None	9:38:34 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/22/2018 9:32:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 8:51:12 AM	MTAService.OnSessionChange	0	None	8:51:12 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/22/2018 8:32:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/22/2018 8:32:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/22/2018 8:31:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/22/2018 8:31:36 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/22/2018 8:31:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 23354, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/22/2018 8:30:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	5/22/2018 7:43:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 6:11:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ef3d980a-5d58-11e8-ae03-204747d02364
Report Status: 0"
Information	5/22/2018 6:10:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 6:09:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 5:55:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/22/2018 5:55:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:39Z. Reason: GVLK.
Information	5/22/2018 5:50:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/22/2018 5:50:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/22/2018 5:50:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/22/2018 5:50:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/22/2018 5:43:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/22/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59865)(?)])(1 )(2 )]

"
Information	5/22/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59865)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	5/22/2018 4:09:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/22/2018 2:34:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/22/2018 2:09:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 2:09:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/22/2018 1:11:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0586f1d5-5d2f-11e8-ae03-204747d02364
Report Status: 0"
Warning	5/22/2018 12:59:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/21/2018 11:22:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 10:09:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 10:09:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/21/2018 9:27:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 8:26:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/21/2018 8:26:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:17Z. Reason: GVLK.
Information	5/21/2018 8:21:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/21/2018 8:21:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 8:21:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/21/2018 8:21:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/21/2018 8:11:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ba874e8-5d05-11e8-ae03-204747d02364
Report Status: 0"
Information	5/21/2018 8:07:13 PM	MTAService.OnSessionChange	0	None	8:07:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/21/2018 7:56:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 6:31:44 PM	MTAService.OnSessionChange	0	None	6:31:44 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/21/2018 6:26:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 6:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 6:09:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 5:48:46 PM	MTAService.OnSessionChange	0	None	5:48:46 PM - Session change notice received: SessionLock Session ID: 1
Error	5/21/2018 5:11:56 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/21/2018 5:11:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/21/2018 5:11:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60523)(?)])(1 )(2 )]

"
Information	5/21/2018 5:11:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60524)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 4:59:07 PM	MTAService.OnSessionChange	0	None	4:59:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/21/2018 4:57:00 PM	MTAService.OnSessionChange	0	None	4:57:00 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/21/2018 4:39:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 3:11:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31cfc036-5cdb-11e8-ae03-204747d02364
Report Status: 0"
Warning	5/21/2018 2:58:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 2:26:41 PM	MTAService.OnSessionChange	0	None	2:26:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/21/2018 2:09:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 2:09:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/21/2018 1:17:03 PM	MTAService.OnSessionChange	0	None	1:17:03 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/21/2018 1:10:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 12:21:40 PM	MTAService.OnSessionChange	0	None	12:21:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/21/2018 12:20:38 PM	MTAService.OnSessionChange	0	None	12:20:38 PM - Session change notice received: SessionLock Session ID: 1
Information	5/21/2018 12:18:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8899.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/21/2018 11:36:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/21/2018 10:51:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/21/2018 10:51:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:09Z. Reason: GVLK.
Information	5/21/2018 10:46:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/21/2018 10:46:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 10:46:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/21/2018 10:46:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/21/2018 10:32:37 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/21/2018 10:29:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/21/2018 10:29:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:10Z. Reason: GVLK.
Information	5/21/2018 10:24:15 AM	MTAService.OnSessionChange	0	None	10:24:15 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/21/2018 10:20:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/21/2018 10:20:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60934)(?)])(1 )(2 )]

"
Information	5/21/2018 10:20:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60934)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 10:20:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/21/2018 10:20:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 10:20:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/21/2018 10:20:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/21/2018 10:19:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/21/2018 10:19:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:42Z. Reason: GVLK.
Information	5/21/2018 10:19:48 AM	MTAService.OnSessionChange	0	None	10:19:47 AM - Session change notice received: SessionLock Session ID: 1
Information	5/21/2018 10:14:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/21/2018 10:14:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 10:14:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/21/2018 10:14:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/21/2018 10:11:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47eefcdc-5cb1-11e8-ae03-204747d02364
Report Status: 0"
Information	5/21/2018 10:11:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/21/2018 10:11:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:39Z. Reason: GVLK.
Information	5/21/2018 10:09:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/21/2018 10:09:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 10:09:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/21/2018 10:09:14 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/21/2018 10:09:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/21/2018 10:09:11 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	5/21/2018 10:08:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/21/2018 10:07:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/21/2018 10:07:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60947)(?)])(1 )(2 )]

"
Information	5/21/2018 10:07:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60948)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	5/21/2018 10:06:31 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/21/2018 10:04:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/21/2018 10:04:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/21/2018 10:04:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/21/2018 10:04:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/21/2018 10:03:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/21/2018 10:02:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/21/2018 10:01:55 AM	MTAService.OnSessionChange	0	None	10:01:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/19/2018 6:48:17 PM	MTAService.OnSessionChange	0	None	6:48:17 PM - Session change notice received: SessionLock Session ID: 1
Information	5/19/2018 6:20:21 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.3.0.168. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/19/2018 6:20:21 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	5/19/2018 6:20:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:49:47.884588400Z.
Information	5/19/2018 6:20:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AD298FF6-4FD3-4CE9-B13E-064A23591AA2}\DeviceManager.msi. Client Process Id: 16364.
Information	5/19/2018 6:19:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:49:47.884588400Z.
Information	5/19/2018 6:19:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AD298FF6-4FD3-4CE9-B13E-064A23591AA2}\DeviceManager.msi. Client Process Id: 16364.
Information	5/19/2018 6:19:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:48:53.037734800Z.
Information	5/19/2018 6:19:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{EF52C3FF-C504-4C79-829A-6C913A6286F9}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 15208.
Information	5/19/2018 6:19:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.168. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/19/2018 6:19:42 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	5/19/2018 6:18:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:48:53.037734800Z.
Information	5/19/2018 6:18:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{EF52C3FF-C504-4C79-829A-6C913A6286F9}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 15208.
Information	5/19/2018 6:10:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 6:10:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:59Z. Reason: GVLK.
Information	5/19/2018 6:09:03 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.168. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/19/2018 6:09:03 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/19/2018 6:09:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:36:20.105663600Z.
Information	5/19/2018 6:09:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D44365EA-1839-4F8C-B72D-7BBD282365EF}\4Sight™ 2.msi. Client Process Id: 5040.
Information	5/19/2018 6:06:20 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:36:20.105663600Z.
Information	5/19/2018 6:06:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D44365EA-1839-4F8C-B72D-7BBD282365EF}\4Sight™ 2.msi. Client Process Id: 5040.
Information	5/19/2018 6:05:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/19/2018 6:05:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 6:05:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 6:05:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 5:57:30 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9494. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	5/19/2018 5:57:30 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	5/19/2018 5:57:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:22:33.391113100Z.
Information	5/19/2018 5:57:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DD2611F7-0DE5-44D5-A022-D1B9CB1502F6}\4Sight™ 2.msi. Client Process Id: 13464.
Information	5/19/2018 5:52:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:22:33.391113100Z.
Information	5/19/2018 5:52:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DD2611F7-0DE5-44D5-A022-D1B9CB1502F6}\4Sight™ 2.msi. Client Process Id: 13464.
Information	5/19/2018 5:50:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9494. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	5/19/2018 5:50:25 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	5/19/2018 5:50:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:20:05.343309800Z.
Information	5/19/2018 5:50:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{68AAC18B-B3BB-4FFF-8FED-5541D14E1BD2}\4Sight™ 2.msi. Client Process Id: 17184.
Error	5/19/2018 5:50:23 PM	MsiInstaller	11720	None	"Product: 4Sight™ 2 -- Error 1720. There is a problem with this Windows Installer package. A script required for this install to complete could not be run. Contact your support personnel or package vendor. Custom action UserAndDBCreation script error -2147467259, Microsoft OLE DB Provider for ODBC Drivers: ERROR: role ""admin"" already exists;
Error while executing the query Line 55, Column 3, "
Information	5/19/2018 5:50:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:20:05.343309800Z.
Information	5/19/2018 5:50:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{68AAC18B-B3BB-4FFF-8FED-5541D14E1BD2}\4Sight™ 2.msi. Client Process Id: 17184.
Information	5/19/2018 5:49:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:19:53.531128700Z.
Information	5/19/2018 5:49:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:19:53.531128700Z.
Information	5/19/2018 5:49:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: D:\SetUpFile_2018_05_19_Sa_15_44_39_9494\DISK1\ISSetupPrerequisites\{7588C9AC-B194-4CDD-B57C-0652484931DF}\psqlodbc_x86.msi. Client Process Id: 11536.
Information	5/19/2018 5:49:54 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: psqlODBC. Product Version: 09.05.0300. Product Language: 1033. Manufacturer: PostgreSQL Global Development Group. Installation success or error status: 0.
Information	5/19/2018 5:49:54 PM	MsiInstaller	11707	None	Product: psqlODBC -- Installation completed successfully.
Information	5/19/2018 5:49:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: D:\SetUpFile_2018_05_19_Sa_15_44_39_9494\DISK1\ISSetupPrerequisites\{7588C9AC-B194-4CDD-B57C-0652484931DF}\psqlodbc_x86.msi. Client Process Id: 11536.
Information	5/19/2018 5:45:14 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 1603.
Information	5/19/2018 5:45:14 PM	MsiInstaller	11708	None	Product: Adobe Reader XI (11.0.08) -- Installation operation failed.
Information	5/19/2018 5:45:14 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.07). Installation success or error status: 1603.
Error	5/19/2018 5:45:14 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.07)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSIe9880.LOG.
Information	5/19/2018 5:45:14 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.08). Installation success or error status: 1603.
Error	5/19/2018 5:45:14 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.08)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSIe9880.LOG.
Error	5/19/2018 5:45:12 PM	MsiInstaller	1013	None	Product: Adobe Reader XI (11.0.08) -- Setup has detected that you already have a more functional product installed.  Setup will now terminate.
Information	5/19/2018 5:39:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Driver Manager. Product Version: 1.3.0.0. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	5/19/2018 5:39:42 PM	MsiInstaller	11707	None	Product: Driver Manager -- Installation operation completed successfully.
Error	5/19/2018 5:38:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/19/2018 5:38:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T12:08:46.893471600Z.
Information	5/19/2018 5:38:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B985874B-22A3-4159-BFBA-73320BEA7A85}\Driver Manager.msi. Client Process Id: 9856.
Information	5/19/2018 5:38:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T12:08:46.893471600Z.
Information	5/19/2018 5:38:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B985874B-22A3-4159-BFBA-73320BEA7A85}\Driver Manager.msi. Client Process Id: 9856.
Warning	5/19/2018 5:03:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 5:02:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/19/2018 5:01:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/19/2018 4:07:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 4:07:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:10Z. Reason: GVLK.
Information	5/19/2018 4:02:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/19/2018 4:02:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 4:02:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 4:02:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 3:59:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T10:28:47.001542400Z.
Information	5/19/2018 3:59:10 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15436.
Information	5/19/2018 3:59:10 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/19/2018 3:59:10 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	5/19/2018 3:58:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T10:28:47.001542400Z.
Information	5/19/2018 3:58:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15436.
Information	5/19/2018 3:58:04 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎19T10:27:56.636506400Z.
Information	5/19/2018 3:58:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15436.
Information	5/19/2018 3:58:04 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/19/2018 3:58:04 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	5/19/2018 3:57:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎19T10:27:56.636506400Z.
Information	5/19/2018 3:57:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15436.
Information	5/19/2018 3:57:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15436.
Information	5/19/2018 3:57:38 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	5/19/2018 3:57:38 PM	MsiInstaller	11729	None	Product: DeviceManager -- Configuration failed.
Information	5/19/2018 3:55:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15436.
Warning	5/19/2018 3:03:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 2:54:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63610530-5b46-11e8-ae03-204747d02364
Report Status: 0"
Information	5/19/2018 2:39:41 PM	MTAService.OnSessionChange	0	None	2:39:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/19/2018 2:10:56 PM	MTAService.OnSessionChange	0	None	2:10:56 PM - Session change notice received: SessionLock Session ID: 1
Information	5/19/2018 1:52:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 1:52:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 1:52:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/19/2018 1:03:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 1:01:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/19/2018 12:33:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8897.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/19/2018 12:27:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 12:22:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 12:22:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63693)(?)])(1 )(2 )]

"
Information	5/19/2018 12:22:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 12:22:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 12:22:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 12:22:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 11:49:10 AM	MTAService.OnSessionChange	0	None	11:49:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/19/2018 11:43:41 AM	MTAService.OnSessionChange	0	None	11:43:41 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/19/2018 11:17:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 10:22:23 AM	MTAService.OnSessionChange	0	None	10:22:23 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/19/2018 9:58:30 AM	MTAService.OnSessionChange	0	None	9:58:30 AM - Session change notice received: SessionLock Session ID: 1
Error	5/19/2018 9:55:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/19/2018 9:54:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 78edbd51-5b1c-11e8-ae03-204747d02364
Report Status: 0"
Information	5/19/2018 9:45:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/19/2018 9:42:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 9:40:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 9:40:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63855)(?)])(1 )(2 )]

"
Information	5/19/2018 9:40:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63855)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 9:38:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 9:38:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63857)(?)])(1 )(2 )]

"
Information	5/19/2018 9:38:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63857)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 9:38:06 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 9:38:06 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 9:38:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 9:37:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 9:32:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 9:32:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63863)(?)])(1 )(2 )]

"
Information	5/19/2018 9:32:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63863)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 9:32:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 9:32:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 9:32:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 9:30:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 9:25:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 9:25:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63869)(?)])(1 )(2 )]

"
Information	5/19/2018 9:25:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63869)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 9:25:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 9:25:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 9:25:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 9:06:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 9:02:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/19/2018 9:02:32 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/19/2018 9:02:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 52, Deleted: 0, Modified: 71, Compared: 23191, Queries: 0, Results: 0, Version: 16.0.8431.2250.
Information	5/19/2018 9:01:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/19/2018 9:01:29 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/19/2018 9:01:24 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 46

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	5/19/2018 9:01:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/19/2018 9:01:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63894)(?)])(1 )(2 )]

"
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63894)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 9:00:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 9:00:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 9:00:50 AM	MTAService.OnSessionChange	0	None	9:00:50 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/19/2018 7:59:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/19/2018 6:21:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 4:54:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8f43fdcf-5af2-11e8-ae03-204747d02364
Report Status: 0"
Warning	5/19/2018 4:22:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 4:14:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/19/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64185)(?)])(1 )(2 )]

"
Information	5/19/2018 4:09:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 4:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/19/2018 4:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 4:09:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 3:30:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 3:30:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:46Z. Reason: GVLK.
Error	5/19/2018 3:25:16 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	5/19/2018 3:22:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/19/2018 3:22:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/19/2018 3:22:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 3:22:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 3:22:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/19/2018 2:31:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/19/2018 2:31:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:08Z. Reason: GVLK.
Information	5/19/2018 2:26:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/19/2018 2:26:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/19/2018 2:26:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/19/2018 2:26:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/19/2018 2:24:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/19/2018 12:41:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/19/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/18/2018 11:54:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5a08271-5ac8-11e8-ae03-204747d02364
Report Status: 0"
Warning	5/18/2018 11:00:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/18/2018 9:13:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 9:02:30 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/18/2018 8:19:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 8:19:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:42Z. Reason: GVLK.
Information	5/18/2018 8:14:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/18/2018 8:14:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 8:14:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 8:14:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/18/2018 8:12:45 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/18/2018 8:00:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 7:55:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7292.
Information	5/18/2018 7:55:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8431.2250. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/18/2018 7:55:19 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	5/18/2018 7:55:19 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/18/2018 7:55:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64680)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 7:55:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/18/2018 7:55:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/18/2018 7:55:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 7:55:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 7:55:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 7:55:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 7:55:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 7:54:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:56 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2250. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/18/2018 7:54:56 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	5/18/2018 7:54:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:52 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:52 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2250. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/18/2018 7:54:52 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	5/18/2018 7:54:45 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/18/2018 7:54:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:45 PM	ESENT	102	General	Windows (11588) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/18/2018 7:54:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2250. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/18/2018 7:54:44 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	5/18/2018 7:54:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:32 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	5/18/2018 7:54:32 PM	ESENT	103	General	Windows (1324) Windows: The database engine stopped the instance (0).
Information	5/18/2018 7:54:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:54:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2250. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/18/2018 7:54:31 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	5/18/2018 7:53:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7292.
Information	5/18/2018 7:52:54 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/18/2018 7:52:54 PM	ESENT	102	General	Windows (1324) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/18/2018 7:52:51 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	5/18/2018 7:52:51 PM	ESENT	103	General	Windows (9116) Windows: The database engine stopped the instance (0).
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:50 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:49 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:49 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	5/18/2018 7:52:49 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:49 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:49 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	5/18/2018 7:52:00 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	5/18/2018 7:51:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	5/18/2018 7:51:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	5/18/2018 7:51:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	5/18/2018 7:51:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 7:51:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 7:51:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/18/2018 7:51:48 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/18/2018 7:50:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 7:50:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:04Z. Reason: GVLK.
Information	5/18/2018 7:49:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 7:48:52 PM	McLogEvent	257	None	The scan of D:\4sightv2\SetUpFile_2018_05_11_Fr_19_50_58_9382\DISK1\ISSetupPrerequisites\{39B44035-64F8-485C-902E-7A79A185BE70}\postgresql-9.5.3-1-windows-x64.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8896.0000.
Information	5/18/2018 7:47:55 PM	McLogEvent	257	None	The scan of D:\4sightv2\SetUpFile_2018_05_11_Fr_19_50_58_9382\DISK1\ISSetupPrerequisites\{7E4BD306-FC5C-4706-91E0-21DEB7567637}\postgresql-9.5.3-1-windows.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8896.0000.
Information	5/18/2018 7:46:59 PM	MTAService.OnSessionChange	0	None	7:46:59 PM - Session change notice received: SessionLock Session ID: 1
Error	5/18/2018 7:45:41 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/18/2018 7:44:59 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/18/2018 7:44:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/18/2018 7:44:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	5/18/2018 7:44:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\SearchProtocolHost.exe' (pid 8064) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/18/2018 7:44:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 8004) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/18/2018 7:44:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6324) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/18/2018 7:44:53 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 6248) cannot be restarted - Application SID does not match Conductor SID..
Information	5/18/2018 7:44:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎18T14:14:41.736141300Z.
Information	5/18/2018 7:43:39 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/18/2018 7:43:34 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/18/2018 7:43:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/18/2018 7:43:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 7:43:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 7:43:28 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/18/2018 7:43:24 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	5/18/2018 7:43:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 7:43:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/18/2018 7:43:16 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/18/2018 7:43:00 PM	ESENT	302	Logging/Recovery	Windows (9116) Windows: The database engine has successfully completed recovery steps.
Information	5/18/2018 7:42:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 7:42:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64692)(?)])(1 )(2 )]

"
Information	5/18/2018 7:42:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64692)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 7:42:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 7:42:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64692)(?)])(1 )(2 )]

"
Information	5/18/2018 7:42:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64692)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 7:42:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 7:42:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 7:42:52 PM	ESENT	301	Logging/Recovery	Windows (9116) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/18/2018 7:42:52 PM	ESENT	300	Logging/Recovery	Windows (9116) Windows: The database engine is initiating recovery steps.
Information	5/18/2018 7:42:52 PM	ESENT	102	General	Windows (9116) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/18/2018 7:42:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 7:42:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8896.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	5/18/2018 7:41:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/18/2018 7:41:51 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/18/2018 7:41:41 PM	Service1	0	None	Service started successfully.
Error	5/18/2018 7:41:33 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/18/2018 7:41:33 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	5/18/2018 7:41:24 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/18/2018 7:41:11 PM	MTAService	0	None	Service started successfully.
Information	5/18/2018 7:40:42 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/18/2018 7:40:40 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/18/2018 7:40:40 PM	PostgreSQL	0	None	"2018-05-18 19:40:40 IST LOG:  redirecting log output to logging collector process
2018-05-18 19:40:40 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/18/2018 7:40:37 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/18/2018 7:40:35 PM	MTAService.OnStart	0	None	7:40:35 PM - User is already logged in : 212558710
Information	5/18/2018 7:40:32 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/18/2018 7:40:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/18/2018 7:40:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/18/2018 7:40:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/18/2018 7:40:31 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/18/2018 7:40:31 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/18/2018 7:40:20 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:20 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/18/2018 7:40:19 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/18/2018 7:40:19 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/18/2018 7:40:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/18/2018 7:40:19 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'SignalDB' (6). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/18/2018 7:40:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/18/2018 7:40:17 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:17 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/18/2018 7:40:17 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/18/2018 7:40:17 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/18/2018 7:40:16 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/18/2018 7:40:13 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:13 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:13 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/18/2018 7:40:12 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3712 at 5/17/2018 5:34:15 PM (local) 5/17/2018 12:04:15 PM (UTC). This is an informational message only; no user action is required.
Information	5/18/2018 7:40:10 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/18/2018 7:40:10 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/18/2018 7:40:10 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/18/2018 7:40:10 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/18/2018 7:40:10 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3964.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/18/2018 7:40:08 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/18/2018 7:39:22 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/18/2018 7:39:15 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/18/2018 7:38:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/18/2018 7:38:57 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/18/2018 7:38:57 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/18/2018 6:54:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc586863-5a9e-11e8-9530-bf2abf7661f3
Report Status: 0"
Warning	5/18/2018 6:43:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 5:56:16 PM	MTAService.OnSessionChange	0	None	5:56:16 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 5:45:29 PM	MTAService.OnSessionChange	0	None	5:45:29 PM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 5:27:51 PM	MTAService.OnSessionChange	0	None	5:27:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 5:26:49 PM	MTAService.OnSessionChange	0	None	5:26:49 PM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 5:15:55 PM	MTAService.OnSessionChange	0	None	5:15:55 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/18/2018 5:12:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 4:49:24 PM	MTAService.OnSessionChange	0	None	4:49:24 PM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 4:47:04 PM	MTAService.OnSessionChange	0	None	4:47:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 4:44:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/18/2018 4:08:21 PM	MTAService.OnSessionChange	0	None	4:08:21 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/18/2018 3:36:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 3:00:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 3:00:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64975)(?)])(1 )(2 )]

"
Information	5/18/2018 3:00:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 2:59:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 2:59:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64976)(?)])(1 )(2 )]

"
Information	5/18/2018 2:59:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64976)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 2:50:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 2:50:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 2:50:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 2:08:32 PM	MTAService.OnSessionChange	0	None	2:08:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 1:54:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d28fb66f-5a74-11e8-9530-bf2abf7661f3
Report Status: 0"
Warning	5/18/2018 1:49:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 1:18:33 PM	MTAService.OnSessionChange	0	None	1:18:33 PM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 12:57:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 12:52:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:52:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65102)(?)])(1 )(2 )]

"
Information	5/18/2018 12:52:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65102)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:47:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]

"
Information	5/18/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:46:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65109)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 12:46:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 12:44:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/18/2018 12:42:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 12:37:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:37:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65118)(?)])(1 )(2 )]

"
Information	5/18/2018 12:37:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65118)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:37:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 12:37:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 12:37:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 12:35:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 12:35:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8896.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/18/2018 12:30:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 12:30:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65124)(?)])(1 )(2 )]

"
Information	5/18/2018 12:30:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65124)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:30:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 12:30:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 12:30:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 12:23:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 12:18:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65137)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:18:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65137)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 12:18:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/18/2018 12:18:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/18/2018 12:18:16 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	5/18/2018 12:18:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 12:18:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 12:18:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 12:14:06 PM	MTAService.OnSessionChange	0	None	12:14:06 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/18/2018 12:10:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 12:03:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 12:01:01 PM	MTAService.OnSessionChange	0	None	12:01:01 PM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 11:58:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 11:58:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65157)(?)])(1 )(2 )]

"
Information	5/18/2018 11:58:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65157)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 11:58:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 11:58:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 11:58:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 11:51:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65169)(?)])(1 )(2 )]

"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65169)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 11:46:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 11:33:23 AM	Microsoft-Windows-CertificateServicesClient-CertEnroll	65	None	Certificate enrollment for LOGON\212558710 is successfully authenticated by policy server {BA818FA0-1CAB-4745-9D99-F2D6B22CCA51}
Warning	5/18/2018 10:29:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/18/2018 9:55:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/18/2018 9:47:31 AM	MTAService.OnSessionChange	0	None	9:47:31 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 9:21:06 AM	MTAService.OnSessionChange	0	None	9:21:06 AM - Session change notice received: SessionLock Session ID: 1
Information	5/18/2018 9:05:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 9:05:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:44Z. Reason: GVLK.
Information	5/18/2018 9:05:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/18/2018 9:00:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎18T03:30:47.584767400Z.
Information	5/18/2018 9:00:31 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎18T03:30:31.216404400Z.
Information	5/18/2018 9:00:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎18T03:30:31.216404400Z.
Information	5/18/2018 9:00:31 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleUpdateHelper.msi. Client Process Id: 10376.
Information	5/18/2018 9:00:31 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.17. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	5/18/2018 9:00:31 AM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	5/18/2018 9:00:30 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleUpdateHelper.msi. Client Process Id: 10376.
Information	5/18/2018 9:00:30 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleUpdateHelper.msi. Client Process Id: 10376.
Information	5/18/2018 9:00:30 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.17. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 1638.
Information	5/18/2018 9:00:30 AM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	5/18/2018 9:00:30 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleUpdateHelper.msi. Client Process Id: 10376.
Information	5/18/2018 9:00:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/18/2018 9:00:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]

"
Information	5/18/2018 9:00:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 9:00:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/18/2018 9:00:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 9:00:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 8:59:03 AM	GE Software	0	(1)	++Installation complete
Information	5/18/2018 8:59:03 AM	GE Software	0	(1)	++Installation complete with an exit code of: 14
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++Started the installation of GE IntelUSB30eXtensibleHostControllerDriver 5.0.4.43 V01 with the following commandline: /Q
Information	5/18/2018 8:58:05 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	5/18/2018 8:58:02 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	5/18/2018 8:56:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/18/2018 8:56:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/18/2018 8:56:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/18/2018 8:56:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/18/2018 8:54:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.24085
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e84bd2d9-5a4a-11e8-9530-bf2abf7661f3
Report Status: 0"
Warning	5/18/2018 8:46:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/18/2018 8:44:18 AM	MTAService.OnSessionChange	0	None	8:44:18 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/18/2018 8:44:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/17/2018 8:13:17 PM	MTAService.OnSessionChange	0	None	8:13:17 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/17/2018 7:44:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 7:05:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 7:05:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:09Z. Reason: GVLK.
Information	5/17/2018 7:00:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎17T13:30:11.857309200Z.
Information	5/17/2018 7:00:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 7:00:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 7:00:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 7:00:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 6:55:19 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 1, Deleted: 0, Modified: 2, Compared: 22909, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/17/2018 6:53:54 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	5/17/2018 6:35:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 6:35:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:08Z. Reason: GVLK.
Information	5/17/2018 6:30:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎17T13:00:11.637428900Z.
Information	5/17/2018 6:30:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 6:30:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 6:30:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 6:30:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 6:06:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎17T12:36:57.174677000Z.
Information	5/17/2018 6:05:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 6:05:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:09Z. Reason: GVLK.
Information	5/17/2018 6:00:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 6:00:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 6:00:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 6:00:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 5:58:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:54:01 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/17/2018 5:53:54 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 437

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 172

Information	5/17/2018 5:53:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 5:53:11 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	5/17/2018 5:53:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 5:53:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66242)(?)])(1 )(2 )]

"
Information	5/17/2018 5:53:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66242)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:52:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 5:52:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66242)(?)])(1 )(2 )]

"
Information	5/17/2018 5:52:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66242)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:52:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 5:52:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 5:52:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 5:51:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:50:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:50:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:14Z. Reason: GVLK.
Warning	5/17/2018 5:49:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/17/2018 5:46:10 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/17/2018 5:45:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 5:45:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66249)(?)])(1 )(2 )]

"
Information	5/17/2018 5:45:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66249)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:45:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 5:45:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 5:45:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 5:45:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 5:45:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:45:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 5:45:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 5:44:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/17/2018 5:44:51 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/17/2018 5:44:51 PM	MTAService.OnSessionChange	0	None	5:44:51 PM - Logon : 212558710
Information	5/17/2018 5:44:51 PM	MTAService.OnSessionChange	0	None	5:44:51 PM - Session change notice received: SessionLogon Session ID: 1
Information	5/17/2018 5:44:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/17/2018 5:44:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/17/2018 5:43:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:43:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:08Z. Reason: GVLK.
Information	5/17/2018 5:39:51 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/17/2018 5:39:51 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/17/2018 5:37:20 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/17/2018 5:37:13 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/17/2018 5:37:12 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/17/2018 5:37:11 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/17/2018 5:35:54 PM	MTAService.OnSessionChange	0	None	5:35:54 PM - Session change notice received: ConsoleConnect Session ID: 1
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (SMBServer)
License Id=72265f61-2ae6-0dcf-a15e-3495ea6c5663"
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	5/17/2018 5:35:42 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	5/17/2018 5:35:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 5:35:40 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/17/2018 5:35:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 5:35:27 PM	ESENT	302	Logging/Recovery	Windows (6752) Windows: The database engine has successfully completed recovery steps.
Information	5/17/2018 5:35:22 PM	ESENT	301	Logging/Recovery	Windows (6752) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/17/2018 5:35:22 PM	ESENT	300	Logging/Recovery	Windows (6752) Windows: The database engine is initiating recovery steps.
Information	5/17/2018 5:35:22 PM	ESENT	102	General	Windows (6752) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	5/17/2018 5:35:10 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	5/17/2018 5:34:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8895.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/17/2018 5:34:31 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:29 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/17/2018 5:34:29 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/17/2018 5:34:29 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/17/2018 5:34:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/17/2018 5:34:27 PM	Service1	0	None	Service started successfully.
Information	5/17/2018 5:34:27 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database msdb (database ID 4) in 1 second(s) (analysis 198 ms, redo 774 ms, undo 239 ms.) This is an informational message only. No user action is required.
Information	5/17/2018 5:34:27 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/17/2018 5:34:27 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'msdb' (4). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:27 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:26 PM	MSSQL$SQLEXPRESS	3406	Server	3 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/17/2018 5:34:25 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/17/2018 5:34:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/17/2018 5:34:23 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:23 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Error	5/17/2018 5:34:22 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/17/2018 5:34:21 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/17/2018 5:34:21 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/17/2018 5:34:21 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/17/2018 5:34:20 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/17/2018 5:34:19 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/17/2018 5:34:17 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:17 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:17 PM	MSSQL$SQLEXPRESS	3406	Server	7 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/17/2018 5:34:15 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 7524 at 5/15/2018 9:14:34 AM (local) 5/15/2018 3:44:34 AM (UTC). This is an informational message only; no user action is required.
Information	5/17/2018 5:34:08 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/17/2018 5:34:07 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/17/2018 5:34:06 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/17/2018 5:34:06 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/17/2018 5:34:06 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/17/2018 5:33:55 PM	PostgreSQL	0	None	"2018-05-17 17:33:55 IST LOG:  redirecting log output to logging collector process
2018-05-17 17:33:55 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/17/2018 5:33:52 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/17/2018 5:33:51 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/17/2018 5:33:49 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/17/2018 5:33:45 PM	MTAService	0	None	Service started successfully.
Information	5/17/2018 5:33:45 PM	MTAService.OnStart	0	None	5:33:43 PM - Waiting for user to Logon
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3712.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/17/2018 5:33:29 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/17/2018 5:32:03 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/17/2018 5:30:20 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/17/2018 5:29:59 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/17/2018 5:29:59 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/17/2018 5:29:59 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	5/17/2018 2:52:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 2:45:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 2:45:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 2:14:16 PM	MTAService.OnSessionChange	0	None	2:14:16 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/17/2018 2:09:26 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/17/2018 2:06:38 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/17/2018 1:53:32 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/17/2018 1:02:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 12:44:24 PM	MTAService.OnSessionChange	0	None	12:44:24 PM - Session change notice received: SessionLock Session ID: 1
Information	5/17/2018 12:31:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 12:31:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:04Z. Reason: GVLK.
Information	5/17/2018 12:27:41 PM	MTAService.OnSessionChange	0	None	12:27:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/17/2018 12:26:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 12:26:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 12:26:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 12:26:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 12:24:55 PM	MTAService.OnSessionChange	0	None	12:24:55 PM - Session change notice received: SessionLock Session ID: 1
Information	5/17/2018 12:23:49 PM	MTAService.OnSessionChange	0	None	12:23:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/17/2018 12:18:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8895.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/17/2018 11:40:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 11:40:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:37Z. Reason: GVLK.
Information	5/17/2018 11:35:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 11:35:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 11:35:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 11:35:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 11:34:09 AM	MTAService.OnSessionChange	0	None	11:34:09 AM - Session change notice received: SessionLock Session ID: 1
Information	5/17/2018 11:21:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 11:16:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 11:16:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66638)(?)])(1 )(2 )]

"
Information	5/17/2018 11:16:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66638)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 11:16:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 11:16:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66639)(?)])(1 )(2 )]

"
Information	5/17/2018 11:16:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66639)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 11:15:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 11:15:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66640)(?)])(1 )(2 )]

"
Information	5/17/2018 11:15:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66640)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 11:15:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 11:15:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 11:15:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 11:12:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 11:07:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 11:07:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66648)(?)])(1 )(2 )]

"
Information	5/17/2018 11:07:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66648)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 11:07:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 11:07:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 11:07:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/17/2018 11:03:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 10:45:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 10:45:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 10:42:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5e29c15-5990-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/17/2018 10:33:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎17T05:03:34.726858900Z.
Information	5/17/2018 10:33:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/17/2018 10:33:53 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/17/2018 10:33:53 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/17/2018 10:33:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎17T05:03:34.726858900Z.
Information	5/17/2018 10:33:01 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/17/2018 10:13:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 10:08:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 10:08:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66707)(?)])(1 )(2 )]

"
Information	5/17/2018 10:08:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66707)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 10:08:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 10:08:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 10:08:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 10:07:25 AM	MTAService.OnSessionChange	0	None	10:07:25 AM - Session change notice received: SessionUnlock Session ID: 1
Error	5/17/2018 9:55:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/17/2018 9:34:49 AM	MTAService.OnSessionChange	0	None	9:34:49 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/17/2018 9:17:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 9:04:28 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 8:59:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 8:59:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66776)(?)])(1 )(2 )]

"
Information	5/17/2018 8:59:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66776)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 8:55:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 8:55:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66779)(?)])(1 )(2 )]

"
Information	5/17/2018 8:55:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66779)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 8:55:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 8:55:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66780)(?)])(1 )(2 )]

"
Information	5/17/2018 8:55:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66780)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 8:55:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 8:55:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 8:55:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 8:28:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 8:23:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 8:23:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66811)(?)])(1 )(2 )]

"
Information	5/17/2018 8:23:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66811)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 8:23:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 8:23:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 8:23:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 8:13:15 AM	MTAService.OnSessionChange	0	None	8:13:15 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/17/2018 7:28:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 6:45:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 6:44:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 5:42:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0abca6b0-5967-11e8-8b6b-204747d02364
Report Status: 0"
Warning	5/17/2018 5:38:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 5:14:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:14:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:18Z. Reason: GVLK.
Information	5/17/2018 5:09:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 5:09:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 5:09:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 5:09:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/17/2018 5:07:07 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/17/2018 5:02:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 5:02:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:46Z. Reason: GVLK.
Error	5/17/2018 4:58:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/17/2018 4:57:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 4:57:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 4:57:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 4:57:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/17/2018 4:14:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 4:09:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/17/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67065)(?)])(1 )(2 )]

"
Information	5/17/2018 4:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 4:09:49 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	5/17/2018 4:09:49 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/17/2018 4:09:49 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 4:09:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/17/2018 4:07:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 2:45:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/17/2018 2:44:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/17/2018 2:34:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 2:06:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17256.
Information	5/17/2018 2:06:00 AM	MsiInstaller	1029	None	Product: Adobe Acrobat Reader DC. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	5/17/2018 2:06:00 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20040. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Type of System Restart: 2. Reason for Restart: 4.
Information	5/17/2018 2:06:00 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20040. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	5/17/2018 2:06:00 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	5/17/2018 2:06:00 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20040. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20040). Installation success or error status: 0.
Information	5/17/2018 2:06:00 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20040)' installed successfully.
Information	5/17/2018 2:05:59 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/17/2018 2:05:34 AM	MsiInstaller	1025	None	Product: Adobe Acrobat Reader DC. The file C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe is being used by the following process: Name: AcroRd32 , Id 5744.
Information	5/17/2018 2:05:09 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/17/2018 2:05:07 AM	ESENT	102	General	Windows (18112) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/17/2018 2:05:05 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	5/17/2018 2:05:04 AM	ESENT	103	General	Windows (8872) Windows: The database engine stopped the instance (0).
Information	5/17/2018 2:05:01 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	5/17/2018 2:04:21 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 17256.
Information	5/17/2018 1:37:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/17/2018 1:37:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:10:14Z. Reason: GVLK.
Information	5/17/2018 1:32:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/17/2018 1:32:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/17/2018 1:32:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/17/2018 1:32:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/17/2018 12:56:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/17/2018 12:42:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2114a797-593d-11e8-8b6b-204747d02364
Report Status: 0"
Warning	5/16/2018 11:21:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 10:45:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 10:45:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/16/2018 10:44:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/16/2018 9:38:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 8:02:31 PM	MTAService.OnSessionChange	0	None	8:02:31 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/16/2018 7:48:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 7:42:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 375f9b5f-5913-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/16/2018 6:44:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 6:42:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67637)(?)])(1 )(2 )]

"
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110837  Grace type=8.
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=63c2ce6b-ca64-4eb1-a9ac-41e9be658ae6"
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=a12239fc-51df-49c4-8ff3-44e65a5ee845"
Information	5/16/2018 6:37:38 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	5/16/2018 6:37:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/16/2018 6:37:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21557)(?)])(1 )(2 )]

"
Information	5/16/2018 6:37:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21557)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 6:37:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/16/2018 6:37:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 6:37:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 6:33:23 PM	MTAService.OnSessionChange	0	None	6:33:23 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/16/2018 6:04:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 6:01:06 PM	MTAService.OnSessionChange	0	None	6:01:06 PM - Session change notice received: SessionLock Session ID: 1
Information	5/16/2018 5:41:33 PM	MTAService.OnSessionChange	0	None	5:41:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/16/2018 5:26:34 PM	MTAService.OnSessionChange	0	None	5:26:34 PM - Session change notice received: SessionLock Session ID: 1
Information	5/16/2018 5:09:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:18.776299400Z.
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:18.776299400Z.
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:18.464299400Z.
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:18.464299400Z.
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:18.162299400Z.
Information	5/16/2018 5:08:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:18.162299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:17.840299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:17.840299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:17.672299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:17.672299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:17.073299400Z.
Information	5/16/2018 5:08:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:17.073299400Z.
Information	5/16/2018 5:08:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎16T11:38:15.582299400Z.
Information	5/16/2018 5:08:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎16T11:38:15.582299400Z.
Information	5/16/2018 5:04:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/16/2018 5:04:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21650)(?)])(1 )(2 )]

"
Information	5/16/2018 5:04:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21650)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 5:04:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/16/2018 5:04:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 5:04:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 5:01:57 PM	MTAService.OnSessionChange	0	None	5:01:57 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/16/2018 4:33:25 PM	MTAService.OnSessionChange	0	None	4:33:25 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/16/2018 4:23:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 3:43:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 3:38:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/16/2018 3:38:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21736)(?)])(1 )(2 )]

"
Information	5/16/2018 3:38:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21736)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 3:38:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/16/2018 3:38:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 3:38:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 3:20:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 3:20:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:26Z. Reason: GVLK.
Information	5/16/2018 3:15:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/16/2018 3:15:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 3:15:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 3:15:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 2:51:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/16/2018 2:51:10 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/16/2018 2:50:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 2:45:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 328

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 671

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 515

Information	5/16/2018 2:44:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 2:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/16/2018 2:43:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21791)(?)])(1 )(2 )]

"
Information	5/16/2018 2:43:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21791)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 2:43:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/16/2018 2:43:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 2:43:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/16/2018 2:42:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 2:42:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c9770d9-58e9-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/16/2018 2:09:22 PM	MTAService.OnSessionChange	0	None	2:09:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/16/2018 1:45:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 1:45:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-23T08:09:26Z. Reason: GVLK.
Information	5/16/2018 1:40:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 1:40:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 1:40:26 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/05/16 08:10"
Information	5/16/2018 1:40:20 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/05/16 08:10, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	5/16/2018 1:35:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/16/2018 1:35:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 1:35:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 1:35:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 1:17:53 PM	MTAService.OnSessionChange	0	None	1:17:53 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/16/2018 12:56:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 12:56:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8894.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/16/2018 12:52:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/16/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21907)(?)])(1 )(2 )]

"
Information	5/16/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21907)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/16/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 12:47:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/16/2018 12:33:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 12:33:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4660.
Information	5/16/2018 12:33:49 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20040. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	5/16/2018 12:33:49 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	5/16/2018 12:33:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 4660.
Information	5/16/2018 12:14:08 PM	MTAService.OnSessionChange	0	None	12:14:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/16/2018 11:52:57 AM	MTAService.OnSessionChange	0	None	11:52:57 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/16/2018 11:20:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 11:07:51 AM	MTAService.OnSessionChange	0	None	11:07:51 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/16/2018 10:36:44 AM	MTAService.OnSessionChange	0	None	10:36:44 AM - Session change notice received: SessionLock Session ID: 1
Information	5/16/2018 10:12:54 AM	MTAService.OnSessionChange	0	None	10:12:54 AM - Session change notice received: SessionUnlock Session ID: 1
Error	5/16/2018 9:55:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/16/2018 9:42:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 624c60ca-58bf-11e8-8b6b-204747d02364
Report Status: 0"
Warning	5/16/2018 9:31:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 9:14:47 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/16/2018 8:33:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/16/2018 7:36:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/16/2018 5:55:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 4:42:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 789295a1-5895-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/16/2018 4:33:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 4:33:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/16/2018 3:56:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 3:28:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/16/2018 3:28:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:09Z. Reason: GVLK.
Information	5/16/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/16/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/16/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/16/2018 3:23:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/16/2018 2:11:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/16/2018 2:10:44 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/16/2018 2:07:36 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/16/2018 12:33:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/16/2018 12:33:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/16/2018 12:18:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 11:42:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8ec8b553-586b-11e8-8b6b-204747d02364
Report Status: 0"
Warning	5/15/2018 10:40:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 10:34:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 5124.
Information	5/15/2018 10:34:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20040. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	5/15/2018 10:34:20 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	5/15/2018 10:33:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 5124.
Information	5/15/2018 10:23:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 10:23:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:49Z. Reason: GVLK.
Information	5/15/2018 10:19:36 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/15/2018 10:18:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/15/2018 10:18:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 10:18:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 10:18:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 10:16:09 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/15/2018 10:14:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T16:43:49.800538500Z.
Information	5/15/2018 10:14:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 3680.
Information	5/15/2018 10:14:26 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 10:14:26 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	5/15/2018 10:14:26 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4096237. Installation success or error status: 0.
Information	5/15/2018 10:14:26 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4096237' installed successfully.
Information	5/15/2018 10:14:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 10:14:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 10:13:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T16:43:49.800538500Z.
Information	5/15/2018 10:13:47 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 3680.
Information	5/15/2018 9:47:45 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/15/2018 9:42:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T16:09:18.400538500Z.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 9280.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:42:37 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4096418. Installation success or error status: 0.
Information	5/15/2018 9:42:37 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4096418' installed successfully.
Information	5/15/2018 9:41:09 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:09 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:09 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:08 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:08 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:06 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 9:41:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:02Z. Reason: GVLK.
Information	5/15/2018 9:41:06 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:04 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:41:03 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:40:58 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/15/2018 9:40:58 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00001.log
Information	5/15/2018 9:40:54 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/15/2018 9:40:54 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:40:51 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	5/15/2018 9:40:50 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/15/2018 9:40:50 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00000.log
Information	5/15/2018 9:40:47 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/15/2018 9:40:47 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:40:38 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/15/2018 9:40:37 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/15/2018 9:40:33 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	5/15/2018 9:40:26 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:40:26 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	5/15/2018 9:40:14 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:13 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4744.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4744.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4744.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 4308.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4744.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 4992.
Information	5/15/2018 9:40:10 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: MTA.Controller , Id 3940.
Information	5/15/2018 9:39:34 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	5/15/2018 9:39:34 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Notepad++\notepad++.exe' (pid 18164) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/15/2018 9:39:34 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 13008) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/15/2018 9:39:34 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 4308) cannot be restarted - Application SID does not match Conductor SID..
Warning	5/15/2018 9:39:34 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4744) cannot be restarted - Application SID does not match Conductor SID..
Information	5/15/2018 9:39:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T16:09:18.400538500Z.
Information	5/15/2018 9:39:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 9280.
Information	5/15/2018 9:36:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/15/2018 9:36:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 9:36:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 9:35:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/15/2018 8:58:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 8:35:23 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/15/2018 8:35:21 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/15/2018 8:35:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/15/2018 8:35:01 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/15/2018 8:33:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 8:33:28 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/15/2018 8:33:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 8:28:59 PM	MTAService.OnSessionChange	0	None	8:28:59 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/15/2018 7:07:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 6:42:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4fd3194-5841-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/15/2018 5:44:55 PM	MTAService.OnSessionChange	0	None	5:44:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/15/2018 5:38:57 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/15/2018 5:11:26 PM	MTAService.OnSessionChange	0	None	5:11:26 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/15/2018 5:09:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 4:38:50 PM	MTAService.OnSessionChange	0	None	4:38:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/15/2018 4:33:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 4:32:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 4:31:15 PM	MTAService.OnSessionChange	0	None	4:31:15 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/15/2018 3:12:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 2:07:53 PM	MTAService.OnSessionChange	0	None	2:07:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/15/2018 1:42:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb6184d2-5817-11e8-8b6b-204747d02364
Report Status: 0"
Warning	5/15/2018 1:39:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 1:12:12 PM	MTAService.OnSessionChange	0	None	1:12:12 PM - Session change notice received: SessionLock Session ID: 1
Information	5/15/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23347)(?)])(1 )(2 )]

"
Information	5/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23347)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/15/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 12:33:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 12:32:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/15/2018 12:28:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8893.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/15/2018 12:04:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/15/2018 12:04:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 11:59:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 11:59:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23395)(?)])(1 )(2 )]

"
Information	5/15/2018 11:59:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23395)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 11:59:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/15/2018 11:59:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 11:59:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 11:57:11 AM	MTAService.OnSessionChange	0	None	11:57:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/15/2018 11:33:08 AM	MTAService.OnSessionChange	0	None	11:33:08 AM - Session change notice received: SessionLock Session ID: 1
Information	5/15/2018 11:15:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 11:15:19 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/15/2018 11:15:19 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/15/2018 11:14:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T05:39:08.233169200Z.
Information	5/15/2018 11:14:29 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DE00BB62-3129-4159-93BD-66AA6BE812EF}\4Sight™ 2.msi. Client Process Id: 10732.
Information	5/15/2018 11:10:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 11:10:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23444)(?)])(1 )(2 )]

"
Information	5/15/2018 11:10:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23444)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 11:10:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 11:10:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23444)(?)])(1 )(2 )]

"
Information	5/15/2018 11:10:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23444)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 11:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 11:09:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23445)(?)])(1 )(2 )]

"
Information	5/15/2018 11:09:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23445)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 11:09:48 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/15/2018 11:09:48 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 11:09:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 11:09:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T05:39:08.233169200Z.
Information	5/15/2018 11:09:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{DE00BB62-3129-4159-93BD-66AA6BE812EF}\4Sight™ 2.msi. Client Process Id: 10732.
Information	5/15/2018 11:08:37 AM	PostgreSQL	0	None	Server started and accepting connections

Information	5/15/2018 11:08:36 AM	PostgreSQL	0	None	"2018-05-15 11:08:36 IST LOG:  redirecting log output to logging collector process
2018-05-15 11:08:36 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/15/2018 11:08:35 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/15/2018 11:02:53 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	5/15/2018 11:02:53 AM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	5/15/2018 11:00:11 AM	PostgreSQL	0	None	Server started and accepting connections

Information	5/15/2018 11:00:10 AM	PostgreSQL	0	None	"2018-05-15 11:00:10 IST LOG:  redirecting log output to logging collector process
2018-05-15 11:00:10 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/15/2018 11:00:10 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/15/2018 10:51:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎15T05:21:28.063458700Z.
Information	5/15/2018 10:51:28 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	5/15/2018 10:51:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎15T05:21:28.063458700Z.
Information	5/15/2018 10:44:16 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	5/15/2018 10:44:16 AM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	5/15/2018 10:41:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎15T05:11:28.874231100Z.
Information	5/15/2018 10:41:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎15T05:11:28.874231100Z.
Information	5/15/2018 10:40:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 10:37:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T05:06:29.655954600Z.
Information	5/15/2018 10:37:49 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/15/2018 10:37:49 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/15/2018 10:37:49 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/15/2018 10:36:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T05:06:29.655954600Z.
Information	5/15/2018 10:36:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/15/2018 10:35:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 10:35:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23479)(?)])(1 )(2 )]

"
Information	5/15/2018 10:35:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23479)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/15/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23482)(?)])(1 )(2 )]

"
Information	5/15/2018 10:32:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23482)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 10:32:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/15/2018 10:32:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 10:32:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/15/2018 10:28:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 10:17:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/15/2018 10:16:06 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/15/2018 10:05:13 AM	MTAService.OnSessionChange	0	None	10:05:13 AM - Session change notice received: SessionUnlock Session ID: 1
Error	5/15/2018 9:55:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/15/2018 9:26:06 AM	MTAService.OnSessionChange	0	None	9:26:06 AM - Session change notice received: SessionLock Session ID: 1
Information	5/15/2018 9:25:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/15/2018 9:23:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 9:23:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:31Z. Reason: GVLK.
Information	5/15/2018 9:18:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/15/2018 9:18:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 9:18:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 9:18:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 9:14:43 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/15/2018 9:14:42 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:42 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/15/2018 9:14:42 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/15/2018 9:14:42 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/15/2018 9:14:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/15/2018 9:14:40 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/15/2018 9:14:39 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:38 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/15/2018 9:14:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/15/2018 9:14:37 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:14:37 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:14:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/15/2018 9:14:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/15/2018 9:14:35 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/15/2018 9:14:35 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:35 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 11668 at 5/15/2018 9:14:01 AM (local) 5/15/2018 3:44:01 AM (UTC). This is an informational message only; no user action is required.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/15/2018 9:14:34 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 7524.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/15/2018 9:14:32 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	5/15/2018 9:14:22 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/15/2018 9:14:19 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/15/2018 9:14:00 AM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	5/15/2018 9:13:50 AM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	5/15/2018 9:13:50 AM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	5/15/2018 9:13:49 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/15/2018 9:13:49 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/15/2018 9:13:49 AM	MSSQL$SQLEXPRESS	919	Server	User 'sa' is changing database script level entry 17 to a value of 500.
Information	5/15/2018 9:13:48 AM	MSSQL$SQLEXPRESS	919	Server	User 'sa' is changing database script level entry 15 to a value of 500.
Information	5/15/2018 9:13:48 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:48 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:47 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	5/15/2018 9:13:34 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:34 AM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 4606, server process ID (SPID) 7. This is an informational message only; no user action is required.
Information	5/15/2018 9:13:34 AM	MSSQL$SQLEXPRESS	17550	Server	DBCC TRACEON 4606, server process ID (SPID) 7. This is an informational message only; no user action is required.
Information	5/15/2018 9:13:31 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:31 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:29 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:29 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:29 AM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 4606, server process ID (SPID) 7. This is an informational message only; no user action is required.
Information	5/15/2018 9:13:29 AM	MSSQL$SQLEXPRESS	17550	Server	DBCC TRACEON 4606, server process ID (SPID) 7. This is an informational message only; no user action is required.
Information	5/15/2018 9:13:26 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:26 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:23 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:23 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:13:00 AM	MSSQL$SQLEXPRESS	5084	Server	Setting database option RECOVERY to SIMPLE for database 'msdb'.
Information	5/15/2018 9:13:00 AM	MSSQL$SQLEXPRESS	5084	Server	Setting database option TRUSTWORTHY to ON for database 'msdb'.
Information	5/15/2018 9:13:00 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:12:59 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:12:58 AM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 1717, server process ID (SPID) 7. This is an informational message only; no user action is required.
Information	5/15/2018 9:12:58 AM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	5/15/2018 9:12:58 AM	MSSQL$SQLEXPRESS	5084	Server	Setting database option COMPATIBILITY_LEVEL to 120 for database 'msdb'.
Information	5/15/2018 9:12:57 AM	MSSQL$SQLEXPRESS	5084	Server	Setting database option COMPATIBILITY_LEVEL to 100 for database 'msdb'.
Information	5/15/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	5/15/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	5/15/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Error	5/15/2018 9:12:51 AM	MSSQL$SQLEXPRESS	5105	Server	A file activation error occurred. The physical file name 'C:\filestreamss\tp\NorthPole_fs' may be incorrect. Diagnose and correct additional errors, and retry the operation.
Error	5/15/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17204	Server	FCB::Startup () failed: Could not open file C:\filestreamss\tp\NorthPole_fs for file number 65537.  OS error: 2(The system cannot find the file specified.).
Error	5/15/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17207	Server	STREAMFCB::Startup: Operating system error 2(The system cannot find the file specified.) occurred while creating or opening file 'C:\filestreamss\tp\NorthPole_fs'. Diagnose and correct the operating system error, and retry the operation.
Information	5/15/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	5/15/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	5/15/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	5/15/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	5/15/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	5/15/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	5/15/2018 9:12:49 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/15/2018 9:12:48 AM	MSSQL$SQLEXPRESS	8128	Server	Using 'xpstar.dll' version '2014.120.5214' to execute extended stored procedure 'xp_instance_regread'. This is an informational message only; no user action is required.
Information	5/15/2018 9:12:48 AM	MSSQL$SQLEXPRESS	33090	Server	Attempting to load library 'xpstar.dll' into memory. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/15/2018 9:12:45 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/15/2018 9:12:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/15/2018 9:12:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:12:43 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:12:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/15/2018 9:12:42 AM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	5/15/2018 9:12:42 AM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3352 at 5/15/2018 9:00:18 AM (local) 5/15/2018 3:30:18 AM (UTC). This is an informational message only; no user action is required.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	5/15/2018 9:12:41 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/15/2018 9:12:40 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/15/2018 9:12:40 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/15/2018 9:12:40 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/15/2018 9:12:40 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 11668.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/15/2018 9:12:37 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4057120) - 12.0.5214.6 (X64) 
	Jan  9 2018 15:03:12 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	5/15/2018 9:12:30 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the MSSQL$SQLEXPRESS (SQL Server (SQLEXPRESS)) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	5/15/2018 9:12:28 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the MSSQL$SQLEXPRESS (SQL Server (SQLEXPRESS)) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	5/15/2018 9:12:21 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:41:43.625246800Z.
Information	5/15/2018 9:12:21 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 12060.
Information	5/15/2018 9:12:21 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:12:21 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	5/15/2018 9:12:21 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:12:21 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'GDR 5214 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:11:43 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:41:43.625246800Z.
Information	5/15/2018 9:11:43 AM	MsiInstaller	11724	None	Product: SQL Server 2014 Client Tools -- Install started.
Information	5/15/2018 9:11:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 12060.
Information	5/15/2018 9:11:38 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:40:56.545127000Z.
Information	5/15/2018 9:11:38 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 12060.
Information	5/15/2018 9:11:38 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:11:38 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	5/15/2018 9:11:38 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server 2014 sql_ssms (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:11:38 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'GDR 5214 for SQL Server 2014 sql_ssms (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:10:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:40:56.545127000Z.
Information	5/15/2018 9:10:55 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:40:36.928243700Z.
Information	5/15/2018 9:10:56 AM	MsiInstaller	11724	None	Product: SQL Server 2014 Management Studio -- Install started.
Information	5/15/2018 9:10:55 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 12060.
Information	5/15/2018 9:10:55 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 12060.
Information	5/15/2018 9:10:55 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:10:55 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Services -- Configuration completed successfully.
Information	5/15/2018 9:10:55 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Database Services 2008 Core Instance (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:10:55 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'GDR 5214 for SQL Server Database Services 2008 Core Instance (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:10:37 AM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Services -- Install started.
Information	5/15/2018 9:10:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:40:36.928243700Z.
Information	5/15/2018 9:10:35 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 12060.
Information	5/15/2018 9:10:35 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:55.919944900Z.
Information	5/15/2018 9:10:35 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {ACC530B8-B6B4-40D6-B59B-152468CF47D0}. Client Process Id: 12060.
Information	5/15/2018 9:10:35 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:10:35 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	5/15/2018 9:10:35 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Database Services 2008 Core Shared (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:10:35 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'GDR 5214 for SQL Server Database Services 2008 Core Shared (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:09:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:55.919944900Z.
Information	5/15/2018 9:09:56 AM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Shared -- Install started.
Information	5/15/2018 9:09:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:33.139112700Z.
Information	5/15/2018 9:09:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {ACC530B8-B6B4-40D6-B59B-152468CF47D0}. Client Process Id: 12060.
Information	5/15/2018 9:09:49 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {F7012F84-80F5-4C25-852E-B1BA03276FE6}. Client Process Id: 12060.
Information	5/15/2018 9:09:49 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:09:49 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	5/15/2018 9:09:49 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Database Services 2008 Common Core (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:09:49 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'GDR 5214 for SQL Server Database Services 2008 Common Core (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:09:33 AM	MsiInstaller	11724	None	Product: SQL Server 2014 Common Files -- Install started.
Information	5/15/2018 9:09:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:33.139112700Z.
Information	5/15/2018 9:09:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:30.808413700Z.
Information	5/15/2018 9:09:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:21.451607500Z.
Information	5/15/2018 9:09:32 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {F7012F84-80F5-4C25-852E-B1BA03276FE6}. Client Process Id: 12060.
Information	5/15/2018 9:09:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\SQLSysClrTypes.msi. Client Process Id: 12060.
Information	5/15/2018 9:09:32 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft System CLR Types for SQL Server 2014 (x64). Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	5/15/2018 9:09:32 AM	MsiInstaller	11707	None	Product: Microsoft System CLR Types for SQL Server 2014 (x64) -- Installation completed successfully.
Information	5/15/2018 9:09:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:30.808413700Z.
Information	5/15/2018 9:09:21 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:21.451607500Z.
Information	5/15/2018 9:09:21 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\SQLSysClrTypes.msi. Client Process Id: 12060.
Information	5/15/2018 9:09:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:18.223639400Z.
Information	5/15/2018 9:09:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3204DE95-97D2-4261-A286-98A262E171D4}. Client Process Id: 12060.
Information	5/15/2018 9:09:20 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:09:20 AM	MsiInstaller	11728	None	Product: SQL Server Browser for SQL Server 2014 -- Configuration completed successfully.
Information	5/15/2018 9:09:20 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for Microsoft SQL Server Browser (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:09:20 AM	MsiInstaller	1022	None	Product: SQL Server Browser for SQL Server 2014 - Update 'GDR 5214 for Microsoft SQL Server Browser (KB4057120)' installed successfully.
Information	5/15/2018 9:09:18 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:18.223639400Z.
Information	5/15/2018 9:09:17 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:09.351978700Z.
Information	5/15/2018 9:09:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3204DE95-97D2-4261-A286-98A262E171D4}. Client Process Id: 12060.
Information	5/15/2018 9:09:17 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {366CD715-2FF4-40B4-A8B4-A05E5D21A945}. Client Process Id: 12060.
Information	5/15/2018 9:09:17 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 9:09:17 AM	MsiInstaller	11728	None	Product: Microsoft VSS Writer for SQL Server 2014 -- Configuration completed successfully.
Information	5/15/2018 9:09:17 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for Microsoft SQL Server VSS Writer (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 9:09:17 AM	MsiInstaller	1022	None	Product: Microsoft VSS Writer for SQL Server 2014 - Update 'GDR 5214 for Microsoft SQL Server VSS Writer (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 9:09:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:09.351978700Z.
Information	5/15/2018 9:09:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:39:04.134413900Z.
Information	5/15/2018 9:09:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:38:47.104306400Z.
Information	5/15/2018 9:09:08 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {366CD715-2FF4-40B4-A8B4-A05E5D21A945}. Client Process Id: 12060.
Information	5/15/2018 9:09:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 12060.
Information	5/15/2018 9:09:08 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Transact-SQL Compiler Service . Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	5/15/2018 9:09:08 AM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Transact-SQL Compiler Service  -- Installation completed successfully.
Information	5/15/2018 9:09:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:39:04.134413900Z.
Information	5/15/2018 9:08:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:38:47.104306400Z.
Information	5/15/2018 9:08:46 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:38:39.135916600Z.
Information	5/15/2018 9:08:46 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:36:57.532444700Z.
Information	5/15/2018 9:08:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 12060.
Information	5/15/2018 9:08:46 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 12060.
Information	5/15/2018 9:08:45 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Express LocalDB . Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	5/15/2018 9:08:45 AM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Express LocalDB  -- Installation completed successfully.
Information	5/15/2018 9:08:39 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:38:39.135916600Z.
Information	5/15/2018 9:06:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:36:57.532444700Z.
Information	5/15/2018 9:06:55 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:36:50.882015100Z.
Information	5/15/2018 9:06:55 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:36:32.884015100Z.
Information	5/15/2018 9:06:55 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 12060.
Information	5/15/2018 9:06:55 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\msodbcsql.msi. Client Process Id: 12060.
Information	5/15/2018 9:06:55 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft ODBC Driver 11 for SQL Server. Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	5/15/2018 9:06:55 AM	MsiInstaller	11707	None	Product: Microsoft ODBC Driver 11 for SQL Server -- Installation completed successfully.
Information	5/15/2018 9:06:50 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:36:50.882015100Z.
Information	5/15/2018 9:06:32 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:36:32.884015100Z.
Information	5/15/2018 9:06:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:36:01.132015100Z.
Information	5/15/2018 9:06:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎15T03:31:03.173015100Z.
Information	5/15/2018 9:06:32 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\x64\msodbcsql.msi. Client Process Id: 12060.
Information	5/15/2018 9:06:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 12060.
Information	5/15/2018 9:06:32 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Setup (English). Product Version: 12.2.5214.6. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	5/15/2018 9:06:32 AM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Setup (English) -- Installation completed successfully.
Information	5/15/2018 9:06:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:36:01.132015100Z.
Information	5/15/2018 9:01:03 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎15T03:31:03.173015100Z.
Information	5/15/2018 9:01:01 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4057120\GDR\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 12060.
Information	5/15/2018 9:00:18 AM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	5/15/2018 9:00:18 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/15/2018 9:00:17 AM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	5/15/2018 9:00:17 AM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:14 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/15/2018 9:00:14 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/15/2018 9:00:13 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/15/2018 9:00:13 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/15/2018 9:00:13 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:13 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/15/2018 9:00:13 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/15/2018 9:00:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/15/2018 9:00:11 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/15/2018 9:00:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/15/2018 9:00:10 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:10 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/15/2018 9:00:10 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/15/2018 9:00:09 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:00:09 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/15/2018 9:00:09 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/15/2018 9:00:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3836 at 5/15/2018 8:59:58 AM (local) 5/15/2018 3:29:58 AM (UTC). This is an informational message only; no user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/15/2018 9:00:06 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3352.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/15/2018 9:00:04 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/15/2018 8:59:59 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133:
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\My
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\CA
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\trust
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\TrustedPeople
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\Disallowed
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\Root
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\Root
Process 956 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\SmartCardRoot
"
Information	5/15/2018 8:59:58 AM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	5/15/2018 8:59:57 AM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	5/15/2018 8:59:57 AM	MSSQL$SQLEXPRESS	9689	Server	Service Broker manager has shut down.
Information	5/15/2018 8:59:56 AM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	5/15/2018 8:59:09 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:59:09 AM	MsiInstaller	11728	None	Product: SQL Server Browser for SQL Server 2014 -- Configuration completed successfully.
Information	5/15/2018 8:59:09 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for Microsoft SQL Server Browser (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:59:09 AM	MsiInstaller	1022	None	Product: SQL Server Browser for SQL Server 2014 - Update 'GDR 5214 for Microsoft SQL Server Browser (KB4057120)' installed successfully.
Information	5/15/2018 8:59:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:59:06 AM	MsiInstaller	11728	None	Product: Microsoft VSS Writer for SQL Server 2014 -- Configuration completed successfully.
Information	5/15/2018 8:59:06 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for Microsoft SQL Server VSS Writer (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:59:06 AM	MsiInstaller	1022	None	Product: Microsoft VSS Writer for SQL Server 2014 - Update 'GDR 5214 for Microsoft SQL Server VSS Writer (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 8:59:05 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:59:05 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	5/15/2018 8:59:05 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Database Services 2008 Common Core (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:59:05 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'GDR 5214 for SQL Server Database Services 2008 Common Core (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 8:59:01 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:59:01 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	5/15/2018 8:59:01 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server 2014 sql_ssms (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:59:01 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'GDR 5214 for SQL Server 2014 sql_ssms (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 8:58:38 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:58:38 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	5/15/2018 8:58:38 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:58:38 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'GDR 5214 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 8:58:02 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	5/15/2018 8:58:02 AM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	5/15/2018 8:58:02 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5214 for SQL Server Database Services 2008 Core Shared (64-bit) (KB4057120). Installation success or error status: 0.
Information	5/15/2018 8:58:02 AM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'GDR 5214 for SQL Server Database Services 2008 Core Shared (64-bit) (KB4057120)' installed successfully.
Information	5/15/2018 8:57:52 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1642.
Information	5/15/2018 8:57:52 AM	MsiInstaller	11708	None	Product: SQL Server 2014 Database Engine Services -- Installation failed.
Information	5/15/2018 8:57:52 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: {90A409EB-AD1F-45BF-935E-4D34980B20B2}. Installation success or error status: 1642.
Error	5/15/2018 8:57:52 AM	MsiInstaller	1024	None	Product: SQL Server 2014 Database Engine Services - Update '{90A409EB-AD1F-45BF-935E-4D34980B20B2}' could not be installed. Error code 1642. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
Information	5/15/2018 8:55:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 8:55:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:52Z. Reason: GVLK.
Information	5/15/2018 8:49:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/15/2018 8:49:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 8:49:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 8:49:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 8:48:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/15/2018 8:48:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:26Z. Reason: GVLK.
Information	5/15/2018 8:43:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/15/2018 8:43:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/15/2018 8:43:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/15/2018 8:43:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/15/2018 8:42:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d1915b15-57ed-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/15/2018 8:35:25 AM	MTAService.OnSessionChange	0	None	8:35:25 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/15/2018 8:35:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/15/2018 8:32:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/14/2018 9:12:12 PM	MTAService.OnSessionChange	0	None	9:12:12 PM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 7:38:06 PM	MTAService.OnSessionChange	0	None	7:38:06 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/14/2018 7:36:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 7:36:26 PM	MTAService.OnSessionChange	0	None	7:36:26 PM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 7:17:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5afe22ec-577d-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/14/2018 7:14:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/14/2018 6:21:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 6:16:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 6:16:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24458)(?)])(1 )(2 )]

"
Information	5/14/2018 6:16:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 6:16:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 6:16:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 6:16:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 6:10:05 PM	MTAService.OnSessionChange	0	None	6:10:05 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/14/2018 6:00:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 4:46:23 PM	MTAService.OnSessionChange	0	None	4:46:23 PM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 4:44:32 PM	MTAService.OnSessionChange	0	None	4:44:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/14/2018 4:23:35 PM	MTAService.OnSessionChange	0	None	4:23:35 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/14/2018 4:16:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 3:46:53 PM	MTAService.OnSessionChange	0	None	3:46:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/14/2018 3:43:59 PM	MTAService.OnSessionChange	0	None	3:43:59 PM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 3:20:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 3:15:56 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 49, Deleted: 0, Modified: 2, Compared: 22561, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/14/2018 3:15:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 3:15:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24639)(?)])(1 )(2 )]

"
Information	5/14/2018 3:15:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24639)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 3:14:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/14/2018 3:14:16 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/14/2018 3:14:13 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 110

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 250

Information	5/14/2018 3:14:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/14/2018 3:13:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 3:13:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24641)(?)])(1 )(2 )]

"
Information	5/14/2018 3:13:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24641)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 3:13:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 3:13:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 3:13:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 3:11:40 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/14/2018 3:11:40 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/14/2018 3:11:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎14T09:38:36.907796400Z.
Information	5/14/2018 3:11:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{514A7FDE-7028-4CA8-BB0C-F19D3DFDE99C}\4Sight™ 2.msi. Client Process Id: 12328.
Information	5/14/2018 3:08:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎14T09:38:36.907796400Z.
Information	5/14/2018 3:08:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{514A7FDE-7028-4CA8-BB0C-F19D3DFDE99C}\4Sight™ 2.msi. Client Process Id: 12328.
Information	5/14/2018 3:05:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎14T09:34:37.037811800Z.
Information	5/14/2018 3:05:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/14/2018 3:05:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/14/2018 3:05:50 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/14/2018 3:04:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎14T09:34:37.037811800Z.
Information	5/14/2018 3:04:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/14/2018 2:56:58 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/14/2018 2:56:58 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/14/2018 2:56:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎14T09:24:16.813795600Z.
Information	5/14/2018 2:56:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{50748CA5-B8E5-4B73-AA1F-2E0B9D867835}\4Sight™ 2.msi. Client Process Id: 12080.
Information	5/14/2018 2:54:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎14T09:24:16.813795600Z.
Information	5/14/2018 2:54:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{50748CA5-B8E5-4B73-AA1F-2E0B9D867835}\4Sight™ 2.msi. Client Process Id: 12080.
Information	5/14/2018 2:50:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎14T09:19:39.379054900Z.
Information	5/14/2018 2:50:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/14/2018 2:50:56 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/14/2018 2:50:56 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/14/2018 2:49:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎14T09:19:39.379054900Z.
Information	5/14/2018 2:49:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8340.
Information	5/14/2018 2:30:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/14/2018 2:29:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24689)(?)])(1 )(2 )]

"
Information	5/14/2018 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24689)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 2:25:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 2:25:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 2:25:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 2:17:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 711ab03e-5753-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/14/2018 2:15:41 PM	MTAService.OnSessionChange	0	None	2:15:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/14/2018 1:22:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 1:20:21 PM	MTAService.OnSessionChange	0	None	1:20:21 PM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 1:17:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 1:17:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24757)(?)])(1 )(2 )]

"
Information	5/14/2018 1:17:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24757)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 1:17:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 1:17:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 1:17:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24787)(?)])(1 )(2 )]

"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24787)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/14/2018 12:44:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 11:59:33 AM	MTAService.OnSessionChange	0	None	11:59:33 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/14/2018 11:59:29 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/14/2018 11:31:57 AM	MTAService.OnSessionChange	0	None	11:31:57 AM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 11:18:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 11:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 11:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24881)(?)])(1 )(2 )]

"
Information	5/14/2018 11:13:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24881)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 11:13:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 11:13:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 11:13:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 11:10:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24889)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24889)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24889)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24889)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 11:04:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24890)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24890)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 11:04:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 11:04:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 11:04:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/14/2018 10:58:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/14/2018 10:47:27 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:27.008493800Z.
Information	5/14/2018 10:47:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:27.008493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:26.832493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:26.832493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:26.609493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:26.609493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:26.449493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:26.449493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:26.289493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:26.289493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:26.112493800Z.
Information	5/14/2018 10:47:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:26.112493800Z.
Information	5/14/2018 10:47:25 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:25.897493800Z.
Information	5/14/2018 10:47:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:25.897493800Z.
Information	5/14/2018 10:47:23 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T05:17:23.723493800Z.
Information	5/14/2018 10:47:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T05:17:23.723493800Z.
Information	5/14/2018 10:41:50 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8892.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/14/2018 10:34:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 10:33:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 10:33:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:54Z. Reason: GVLK.
Information	5/14/2018 10:29:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 10:29:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24925)(?)])(1 )(2 )]

"
Information	5/14/2018 10:29:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24925)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 10:29:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 10:29:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 10:29:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 10:28:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/14/2018 10:28:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 10:28:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 10:28:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:52.654498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:52.654498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:52.501498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:52.501498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:52.423498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:52.423498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:52.270498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:52.270498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:52.127498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:52.127498900Z.
Information	5/14/2018 10:23:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.974498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.974498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.846498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.846498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.719498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.719498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.567498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.567498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.390498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.390498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:51.023498900Z.
Information	5/14/2018 10:23:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:51.023498900Z.
Information	5/14/2018 10:23:50 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:50.822498900Z.
Information	5/14/2018 10:23:50 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:50.822498900Z.
Information	5/14/2018 10:23:47 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:47.025498900Z.
Information	5/14/2018 10:23:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:47.025498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:11.641498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:11.641498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:11.320498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:11.320498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:11.152498900Z.
Information	5/14/2018 10:23:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:11.152498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:10.856498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:10.856498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:10.704498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:10.704498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:10.544498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:10.544498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:10.256498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:10.256498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:10.104498900Z.
Information	5/14/2018 10:23:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:10.104498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:09.824498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:09.824498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:09.664498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:09.664498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:09.512498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:09.512498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:09.311498900Z.
Information	5/14/2018 10:23:09 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:09.311498900Z.
Information	5/14/2018 10:23:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:08.745498900Z.
Information	5/14/2018 10:23:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:08.745498900Z.
Information	5/14/2018 10:23:07 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:53:07.087498900Z.
Information	5/14/2018 10:23:07 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:53:07.087498900Z.
Information	5/14/2018 10:22:56 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:52:56.641498900Z.
Information	5/14/2018 10:22:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:52:56.641498900Z.
Information	5/14/2018 10:22:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎14T04:52:51.182498900Z.
Information	5/14/2018 10:22:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎14T04:52:51.182498900Z.
Information	5/14/2018 10:22:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 10:16:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 10:16:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24937)(?)])(1 )(2 )]

"
Information	5/14/2018 10:16:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 10:16:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 10:16:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 10:16:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 10:03:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 10:03:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:53Z. Reason: GVLK.
Information	5/14/2018 9:58:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/14/2018 9:58:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 9:58:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 9:58:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/14/2018 9:55:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/14/2018 9:47:35 AM	MTAService.OnSessionChange	0	None	9:47:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/14/2018 9:35:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 9:35:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:31Z. Reason: GVLK.
Error	5/14/2018 9:28:44 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/14/2018 9:28:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 9:23:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/14/2018 9:23:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 9:23:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 9:23:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 9:23:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 9:23:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24991)(?)])(1 )(2 )]

"
Information	5/14/2018 9:23:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24991)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 9:23:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 9:23:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 9:23:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 9:22:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 9:22:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:15Z. Reason: GVLK.
Information	5/14/2018 9:20:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/14/2018 9:18:20 AM	MTAService.OnSessionChange	0	None	9:18:20 AM - Session change notice received: SessionLock Session ID: 1
Information	5/14/2018 9:17:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 87745d31-5729-11e8-8b6b-204747d02364
Report Status: 0"
Information	5/14/2018 9:16:28 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/14/2018 9:15:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/14/2018 9:15:32 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7980F42D-B4CF-44F3-9C92-923823E688F6}
Error	5/14/2018 9:15:32 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7980F42D-B4CF-44F3-9C92-923823E688F6}
Information	5/14/2018 9:15:32 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/14/2018 9:15:28 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/14/2018 9:15:27 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/14/2018 9:15:22 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/14/2018 9:15:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/14/2018 9:15:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24999)(?)])(1 )(2 )]

"
Information	5/14/2018 9:15:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/14/2018 9:15:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24999)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 9:15:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/14/2018 9:15:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 9:15:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/14/2018 9:15:11 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/14/2018 9:15:00 AM	ESENT	302	Logging/Recovery	Windows (8872) Windows: The database engine has successfully completed recovery steps.
Information	5/14/2018 9:14:58 AM	ESENT	301	Logging/Recovery	Windows (8872) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/14/2018 9:14:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/14/2018 9:14:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/14/2018 9:14:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/14/2018 9:14:32 AM	ESENT	301	Logging/Recovery	Windows (8872) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS007BE.log.
Information	5/14/2018 9:14:32 AM	ESENT	300	Logging/Recovery	Windows (8872) Windows: The database engine is initiating recovery steps.
Information	5/14/2018 9:14:31 AM	ESENT	102	General	Windows (8872) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/14/2018 9:14:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/14/2018 9:14:24 AM	Service1	0	None	Service started successfully.
Error	5/14/2018 9:14:01 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/14/2018 9:14:01 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/14/2018 9:13:34 AM	MTAService.OnSessionChange	0	None	9:13:34 AM - Logon : 212558710
Information	5/14/2018 9:13:34 AM	MTAService.OnSessionChange	0	None	9:13:33 AM - Session change notice received: SessionLogon Session ID: 1
Information	5/14/2018 9:13:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8890.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/14/2018 9:13:11 AM	PostgreSQL	0	None	Server started and accepting connections

Information	5/14/2018 9:13:10 AM	PostgreSQL	0	None	"2018-05-14 09:13:10 IST LOG:  redirecting log output to logging collector process
2018-05-14 09:13:10 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/14/2018 9:13:09 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/14/2018 9:13:07 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/14/2018 9:13:05 AM	MTAService	0	None	Service started successfully.
Information	5/14/2018 9:13:05 AM	MTAService.OnStart	0	None	9:13:03 AM - Waiting for user to Logon
Information	5/14/2018 9:13:04 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/14/2018 9:13:04 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/14/2018 9:13:04 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/14/2018 9:13:04 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/14/2018 9:13:04 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/14/2018 9:13:04 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/14/2018 9:12:54 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 460 at 5/13/2018 11:19:28 AM (local) 5/13/2018 5:49:28 AM (UTC). This is an informational message only; no user action is required.
Information	5/14/2018 9:12:52 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/14/2018 9:12:51 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/14/2018 9:12:51 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/14/2018 9:12:51 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/14/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/14/2018 9:12:51 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3836.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/14/2018 9:12:50 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/14/2018 9:12:47 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/14/2018 9:12:37 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/14/2018 9:12:32 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/14/2018 9:12:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/14/2018 9:12:32 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/13/2018 11:19:40 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	5/13/2018 11:19:32 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	5/13/2018 11:19:28 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	5/13/2018 11:19:15 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 932 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4128 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4128 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4128 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4128 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	5/13/2018 11:19:15 AM	MTAService.OnSessionChange	0	None	11:19:15 AM - Logoff
Information	5/13/2018 11:19:15 AM	MTAService.OnSessionChange	0	None	11:19:15 AM - Session change notice received: SessionLogoff Session ID: 1
Information	5/13/2018 11:19:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	5/13/2018 11:19:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	5/13/2018 11:19:14 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	5/13/2018 11:19:07 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	5/13/2018 11:19:06 AM	RasClient	20226	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	5/13/2018 11:13:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/13/2018 10:44:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/13/2018 10:44:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:36Z. Reason: GVLK.
Information	5/13/2018 10:39:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/13/2018 10:39:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 10:39:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 10:39:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 10:27:04 AM	MTAService.OnSessionChange	0	None	10:27:04 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/13/2018 10:21:22 AM	MTAService.OnSessionChange	0	None	10:21:22 AM - Session change notice received: SessionLock Session ID: 1
Information	5/13/2018 10:14:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/13/2018 10:14:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:36Z. Reason: GVLK.
Information	5/13/2018 10:09:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/13/2018 10:09:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 10:09:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 10:09:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 9:47:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/13/2018 9:47:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:54Z. Reason: GVLK.
Error	5/13/2018 9:41:22 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/13/2018 9:40:27 AM	RasClient	20225	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.230.188
TunnelIpv6Address = None
Dial-in User = .
Information	5/13/2018 9:40:21 AM	RasClient	20224	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/13/2018 9:40:21 AM	RasClient	20223	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 9:40:21 AM	RasClient	20222	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 9:40:21 AM	RasClient	20221	None	CoId={02F091A3-AA86-413B-9D6D-0DA3213F6E3D}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	5/13/2018 9:39:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/13/2018 9:39:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 9:39:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 9:39:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 9:37:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/13/2018 9:37:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:26Z. Reason: GVLK.
Information	5/13/2018 9:32:27 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	5/13/2018 9:28:02 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/13/2018 9:28:00 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/13/2018 9:26:47 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/13/2018 9:26:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/13/2018 9:26:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 9:26:44 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/13/2018 9:26:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 9:26:38 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/13/2018 9:26:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 9:26:30 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/13/2018 9:26:27 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Warning	5/13/2018 9:26:24 AM	Microsoft-Windows-EventSystem	4627	Firing Agent	"The COM+ Event System timed out attempting to fire the PostShell method on event class {D5978650-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is ""SENS Logon2 Subscription"". The HRESULT was 80010002."
Information	5/13/2018 9:26:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/13/2018 9:26:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26428)(?)])(1 )(2 )]

"
Information	5/13/2018 9:26:11 AM	ESENT	302	Logging/Recovery	Windows (9408) Windows: The database engine has successfully completed recovery steps.
Information	5/13/2018 9:26:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26428)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 9:26:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/13/2018 9:26:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 9:26:05 AM	ESENT	301	Logging/Recovery	Windows (9408) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/13/2018 9:26:03 AM	ESENT	301	Logging/Recovery	Windows (9408) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS007BD.log.
Information	5/13/2018 9:25:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 9:25:59 AM	ESENT	301	Logging/Recovery	Windows (9408) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS007BC.log.
Information	5/13/2018 9:25:58 AM	ESENT	300	Logging/Recovery	Windows (9408) Windows: The database engine is initiating recovery steps.
Information	5/13/2018 9:25:58 AM	ESENT	102	General	Windows (9408) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/13/2018 9:25:51 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8890.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	5/13/2018 9:25:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/13/2018 9:24:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/13/2018 9:24:26 AM	Service1	0	None	Service started successfully.
Error	5/13/2018 9:24:07 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/13/2018 9:24:07 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/13/2018 9:23:53 AM	MTAService	0	None	Service started successfully.
Information	5/13/2018 9:23:50 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/13/2018 9:23:50 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/13/2018 9:23:47 AM	PostgreSQL	0	None	Server started and accepting connections

Information	5/13/2018 9:23:32 AM	PostgreSQL	0	None	"2018-05-13 09:23:32 IST LOG:  redirecting log output to logging collector process
2018-05-13 09:23:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/13/2018 9:23:28 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/13/2018 9:23:28 AM	MTAService.OnStart	0	None	9:23:27 AM - User is already logged in : 212558710
Information	5/13/2018 9:23:25 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/13/2018 9:23:24 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/13/2018 9:23:24 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/13/2018 9:23:24 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/13/2018 9:23:24 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/13/2018 9:23:24 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/13/2018 9:23:15 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:15 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/13/2018 9:23:14 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/13/2018 9:23:14 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/13/2018 9:23:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/13/2018 9:23:14 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:13 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/13/2018 9:23:12 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/13/2018 9:23:12 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/13/2018 9:23:12 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3768 at 5/2/2018 8:53:27 AM (local) 5/2/2018 3:23:27 AM (UTC). This is an informational message only; no user action is required.
Information	5/13/2018 9:23:08 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/13/2018 9:23:06 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/13/2018 9:23:06 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/13/2018 9:23:06 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/13/2018 9:23:06 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/13/2018 9:23:06 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 460.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/13/2018 9:23:05 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/13/2018 9:22:34 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/13/2018 9:22:26 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/13/2018 9:22:12 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/13/2018 9:22:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/13/2018 9:22:12 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/13/2018 8:40:47 AM	MTAService.OnSessionChange	0	None	8:40:47 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/13/2018 8:07:05 AM	MTAService.OnSessionChange	0	None	8:07:05 AM - Session change notice received: SessionLock Session ID: 1
Information	5/13/2018 7:40:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/13/2018 7:40:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:22Z. Reason: GVLK.
Information	5/13/2018 7:35:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/13/2018 7:35:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/13/2018 7:35:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/13/2018 7:35:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/13/2018 7:34:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0251d9b2-5652-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/13/2018 7:29:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/13/2018 7:25:49 AM	RasClient	20225	None	CoId={31F9BC0E-0C1D-4C5D-9690-1E1593DC06B0}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.231.173
TunnelIpv6Address = None
Dial-in User = .
Information	5/13/2018 7:25:44 AM	RasClient	20224	None	CoId={31F9BC0E-0C1D-4C5D-9690-1E1593DC06B0}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/13/2018 7:25:44 AM	RasClient	20223	None	CoId={31F9BC0E-0C1D-4C5D-9690-1E1593DC06B0}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 7:25:44 AM	RasClient	20222	None	CoId={31F9BC0E-0C1D-4C5D-9690-1E1593DC06B0}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 7:25:44 AM	RasClient	20221	None	CoId={31F9BC0E-0C1D-4C5D-9690-1E1593DC06B0}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	5/13/2018 7:24:44 AM	MTAService.OnSessionChange	0	None	7:24:44 AM - Session change notice received: SessionUnlock Session ID: 1
Error	5/13/2018 7:24:40 AM	RasClient	20227	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 628.
Information	5/13/2018 7:24:40 AM	RasClient	20226	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	5/13/2018 7:24:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/13/2018 7:24:31 AM	RasClient	20224	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/13/2018 7:24:31 AM	RasClient	20223	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 7:24:31 AM	RasClient	20222	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/13/2018 7:24:31 AM	RasClient	20221	None	CoId={18540B4C-1CB6-4327-9FD5-CD0C9E653178}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	5/13/2018 12:00:04 AM	MTAService.OnSessionChange	0	None	12:00:04 AM - Session change notice received: SessionLock Session ID: 1
Information	5/12/2018 11:59:58 PM	RasClient	20226	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	5/12/2018 11:29:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/12/2018 11:28:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/12/2018 11:05:05 PM	MTAService.OnSessionChange	0	None	11:05:05 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/12/2018 10:41:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/12/2018 9:32:06 PM	MTAService.OnSessionChange	0	None	9:32:06 PM - Session change notice received: SessionLock Session ID: 1
Information	5/12/2018 9:31:18 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/12/2018 9:29:29 PM	MTAService.OnSessionChange	0	None	9:29:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/12/2018 9:20:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/12/2018 9:20:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:01Z. Reason: GVLK.
Information	5/12/2018 9:15:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/12/2018 9:15:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/12/2018 9:15:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/12/2018 9:15:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/12/2018 8:41:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/12/2018 8:39:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 816180c6-55f6-11e8-a79e-204747d02364
Report Status: 0"
Information	5/12/2018 8:38:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/12/2018 8:38:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:35Z. Reason: GVLK.
Information	5/12/2018 8:33:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/12/2018 8:33:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/12/2018 8:33:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/12/2018 8:33:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/12/2018 8:21:32 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/12/2018 7:47:37 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/12/2018 7:47:37 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/12/2018 7:47:37 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/12/2018 7:47:13 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/12/2018 7:47:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/12/2018 7:47:10 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/12/2018 7:42:01 PM	MTAService.OnSessionChange	0	None	7:42:01 PM - Session change notice received: SessionLock Session ID: 1
Information	5/12/2018 7:29:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/12/2018 7:29:14 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/12/2018 7:28:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/12/2018 6:57:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8890.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/12/2018 6:50:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/12/2018 6:47:21 PM	RasClient	20225	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.249.67
TunnelIpv6Address = None
Dial-in User = .
Information	5/12/2018 6:47:18 PM	RasClient	20224	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/12/2018 6:47:18 PM	RasClient	20223	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:47:18 PM	RasClient	20222	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:47:18 PM	RasClient	20221	None	CoId={839673A4-5A70-456C-AD91-29340F1A87D8}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	5/12/2018 6:45:24 PM	RasClient	20227	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 628.
Information	5/12/2018 6:45:24 PM	RasClient	20226	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	5/12/2018 6:45:23 PM	RasClient	20224	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/12/2018 6:45:23 PM	RasClient	20223	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:45:23 PM	RasClient	20222	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:45:23 PM	RasClient	20221	None	CoId={AE0587CF-B646-499F-988C-9668B96C28FB}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	5/12/2018 6:45:22 PM	RasClient	20227	None	CoId={BF5A33BF-CC5B-442D-8209-25A5F7933C2F}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 628.
Information	5/12/2018 6:44:45 PM	RasClient	20224	None	CoId={BF5A33BF-CC5B-442D-8209-25A5F7933C2F}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/12/2018 6:44:45 PM	RasClient	20223	None	CoId={BF5A33BF-CC5B-442D-8209-25A5F7933C2F}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:44:45 PM	RasClient	20222	None	CoId={BF5A33BF-CC5B-442D-8209-25A5F7933C2F}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:44:45 PM	RasClient	20221	None	CoId={BF5A33BF-CC5B-442D-8209-25A5F7933C2F}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	5/12/2018 6:44:43 PM	RasClient	20226	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	5/12/2018 6:44:43 PM	RasClient	20225	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.236.49
TunnelIpv6Address = None
Dial-in User = .
Information	5/12/2018 6:44:41 PM	MTAService.OnSessionChange	0	None	6:44:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/12/2018 6:44:38 PM	RasClient	20224	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/12/2018 6:44:38 PM	RasClient	20223	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:44:38 PM	RasClient	20222	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 6:44:38 PM	RasClient	20221	None	CoId={A458492C-C9AA-4EC3-AD15-FFD47B3A2F0E}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	5/12/2018 4:13:22 PM	MTAService.OnSessionChange	0	None	4:13:22 PM - Session change notice received: SessionLock Session ID: 1
Information	5/12/2018 4:13:17 PM	RasClient	20226	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Error	5/12/2018 4:13:13 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/12/2018 4:13:13 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/12/2018 3:48:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/12/2018 3:47:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/12/2018 3:45:19 PM	RasClient	20225	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.236.49
TunnelIpv6Address = None
Dial-in User = .
Information	5/12/2018 3:45:13 PM	RasClient	20224	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	5/12/2018 3:45:13 PM	RasClient	20223	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 3:45:13 PM	RasClient	20222	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	5/12/2018 3:45:13 PM	RasClient	20221	None	CoId={4D0CDE09-8731-4953-A77B-DBC7D17488A8}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	5/12/2018 3:42:32 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	5/12/2018 3:42:32 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {61165D76-E2B7-4B04-9A2B-7643FF70C99C}
Information	5/12/2018 3:40:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/12/2018 3:40:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27494)(?)])(1 )(2 )]

"
Information	5/12/2018 3:40:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27494)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/12/2018 3:40:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/12/2018 3:40:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/12/2018 3:40:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/12/2018 3:39:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 90bb12d0-55cc-11e8-a79e-204747d02364
Report Status: 0"
Information	5/12/2018 3:29:08 PM	MTAService.OnSessionChange	0	None	3:29:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/12/2018 3:28:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/11/2018 9:18:45 PM	MTAService.OnSessionChange	0	None	9:18:44 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/11/2018 9:10:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 8:48:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 8:48:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 8:23:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9382. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/11/2018 8:23:11 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	5/11/2018 8:23:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎11T14:50:11.783934300Z.
Information	5/11/2018 8:23:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FE955BAA-3D50-4DF5-8C6A-572DF8EAF2B1}\4Sight™ 2.msi. Client Process Id: 15956.
Information	5/11/2018 8:20:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎11T14:50:11.783934300Z.
Information	5/11/2018 8:20:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FE955BAA-3D50-4DF5-8C6A-572DF8EAF2B1}\4Sight™ 2.msi. Client Process Id: 15956.
Warning	5/11/2018 7:14:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 6:57:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bdfa720-551f-11e8-a79e-204747d02364
Report Status: 0"
Error	5/11/2018 5:53:57 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/11/2018 5:43:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 5:39:01 PM	MTAService.OnSessionChange	0	None	5:39:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 5:30:25 PM	MTAService.OnSessionChange	0	None	5:30:25 PM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 5:29:16 PM	MTAService.OnSessionChange	0	None	5:29:16 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 5:17:27 PM	MTAService.OnSessionChange	0	None	5:17:26 PM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 4:48:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 4:48:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 4:48:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/11/2018 3:44:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 3:29:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎11T09:58:40.397282900Z.
Information	5/11/2018 3:29:03 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10024.
Information	5/11/2018 3:29:03 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9341. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	5/11/2018 3:29:03 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	5/11/2018 3:28:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎11T09:58:40.397282900Z.
Information	5/11/2018 3:12:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10024.
Information	5/11/2018 2:12:11 PM	MTAService.OnSessionChange	0	None	2:12:11 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/11/2018 2:00:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 1:57:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3205930e-54f5-11e8-a79e-204747d02364
Report Status: 0"
Information	5/11/2018 1:56:53 PM	MTAService.OnSessionChange	0	None	1:56:53 PM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 1:52:53 PM	MTAService.OnSessionChange	0	None	1:52:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 1:51:47 PM	MTAService.OnSessionChange	0	None	1:51:47 PM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 1:48:37 PM	MTAService.OnSessionChange	0	None	1:48:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 1:17:00 PM	MTAService.OnSessionChange	0	None	1:17:00 PM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/11/2018 12:48:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/11/2018 12:48:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/11/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29107)(?)])(1 )(2 )]

"
Information	5/11/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/11/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/11/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/11/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/11/2018 12:33:51 PM	MTAService.OnSessionChange	0	None	12:33:51 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 12:14:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8889.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/11/2018 12:02:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 11:39:46 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 22654, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/11/2018 11:38:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	5/11/2018 11:33:05 AM	MTAService.OnSessionChange	0	None	11:33:05 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/11/2018 10:29:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 10:03:32 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/11/2018 10:03:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/11/2018 10:01:17 AM	MTAService.OnSessionChange	0	None	10:01:17 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 9:44:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	5/11/2018 9:43:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/11/2018 9:26:49 AM	MTAService.OnSessionChange	0	None	9:26:49 AM - Session change notice received: SessionLock Session ID: 1
Information	5/11/2018 9:03:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/11/2018 9:03:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:29Z. Reason: GVLK.
Information	5/11/2018 8:58:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/11/2018 8:58:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/11/2018 8:58:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/11/2018 8:58:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/11/2018 8:57:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 481de0c2-54cb-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/11/2018 8:49:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/11/2018 8:48:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/11/2018 8:48:20 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/11/2018 8:48:01 AM	MTAService.OnSessionChange	0	None	8:48:01 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/11/2018 8:47:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/10/2018 8:39:03 PM	MTAService.OnSessionChange	0	None	8:39:03 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/10/2018 8:12:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 7:31:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97726b76-545a-11e8-a79e-204747d02364
Report Status: 0"
Information	5/10/2018 6:49:54 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9341. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	5/10/2018 6:49:54 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Warning	5/10/2018 6:42:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 6:41:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎05‎-‎10T13:07:40.305292000Z.
Information	5/10/2018 6:41:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B62D39F6-C5BB-40FC-9F0D-49DAA23FEFD3}\4Sight™ 2.msi. Client Process Id: 18528.
Information	5/10/2018 6:37:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎05‎-‎10T13:07:40.305292000Z.
Information	5/10/2018 6:37:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B62D39F6-C5BB-40FC-9F0D-49DAA23FEFD3}\4Sight™ 2.msi. Client Process Id: 18528.
Information	5/10/2018 6:37:03 PM	PostgreSQL	0	None	Server started and accepting connections

Information	5/10/2018 6:37:03 PM	PostgreSQL	0	None	"2018-05-10 18:37:03 IST LOG:  redirecting log output to logging collector process
2018-05-10 18:37:03 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/10/2018 6:37:02 PM	PostgreSQL	0	None	Waiting for server startup...

Information	5/10/2018 5:43:31 PM	MTAService.OnSessionChange	0	None	5:43:31 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 5:23:41 PM	MTAService.OnSessionChange	0	None	5:23:41 PM - Session change notice received: SessionLock Session ID: 1
Information	5/10/2018 5:21:30 PM	MTAService.OnSessionChange	0	None	5:21:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 5:21:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/10/2018 5:01:31 PM	MTAService.OnSessionChange	0	None	5:01:31 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/10/2018 4:47:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 4:06:14 PM	MTAService.OnSessionChange	0	None	4:06:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 4:00:26 PM	MTAService.OnSessionChange	0	None	4:00:26 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/10/2018 3:07:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 3:02:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/10/2018 3:02:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:36Z. Reason: GVLK.
Information	5/10/2018 2:57:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/10/2018 2:57:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/10/2018 2:57:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/10/2018 2:57:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/10/2018 2:31:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad9dcb18-5430-11e8-a79e-204747d02364
Report Status: 0"
Information	5/10/2018 2:21:29 PM	MTAService.OnSessionChange	0	None	2:21:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 2:12:14 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/10/2018 2:06:01 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/10/2018 2:01:06 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/10/2018 1:33:34 PM	MTAService.OnSessionChange	0	None	1:33:34 PM - Session change notice received: SessionLock Session ID: 1
Information	5/10/2018 1:21:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/10/2018 1:21:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/10/2018 1:09:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/10/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/10/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30547)(?)])(1 )(2 )]

"
Information	5/10/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30547)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/10/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/10/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/10/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/10/2018 12:43:41 PM	MTAService.OnSessionChange	0	None	12:43:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 12:39:47 PM	MTAService.OnSessionChange	0	None	12:39:47 PM - Session change notice received: SessionLock Session ID: 1
Information	5/10/2018 12:09:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8888.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/10/2018 12:09:20 PM	MTAService.OnSessionChange	0	None	12:09:20 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 11:36:40 AM	MTAService.OnSessionChange	0	None	11:36:40 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/10/2018 11:22:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 10:32:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/10/2018 10:32:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/10/2018 10:32:25 AM	MTAService.OnSessionChange	0	None	10:32:25 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 9:57:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	5/10/2018 9:43:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/10/2018 9:40:41 AM	MTAService.OnSessionChange	0	None	9:40:41 AM - Session change notice received: SessionLock Session ID: 1
Information	5/10/2018 9:36:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/10/2018 9:36:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:41Z. Reason: GVLK.
Information	5/10/2018 9:31:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/10/2018 9:31:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/10/2018 9:31:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/10/2018 9:31:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/10/2018 9:31:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3ee2805-5406-11e8-a79e-204747d02364
Report Status: 0"
Information	5/10/2018 9:29:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/10/2018 9:29:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:47Z. Reason: GVLK.
Error	5/10/2018 9:29:29 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	5/10/2018 9:24:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/10/2018 9:24:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/10/2018 9:24:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/10/2018 9:24:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/10/2018 9:24:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/10/2018 9:23:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/10/2018 9:21:21 AM	MTAService.OnSessionChange	0	None	9:21:21 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/10/2018 9:21:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 8:17:07 PM	MTAService.OnSessionChange	0	None	8:17:07 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/9/2018 8:09:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 7:52:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 73f9dbb5-5394-11e8-a79e-204747d02364
Report Status: 0"
Information	5/9/2018 7:49:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 7:49:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:29Z. Reason: GVLK.
Information	5/9/2018 7:44:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 7:44:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 7:44:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 7:44:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 6:55:27 PM	MTAService.OnSessionChange	0	None	6:55:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 6:52:05 PM	MTAService.OnSessionChange	0	None	6:52:05 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/9/2018 6:27:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 6:12:01 PM	MTAService.OnSessionChange	0	None	6:12:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 5:45:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 5:45:52 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/9/2018 5:45:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 5:45:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 5:20:55 PM	MTAService.OnSessionChange	0	None	5:20:55 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/9/2018 4:55:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 4:55:14 PM	MTAService.OnSessionChange	0	None	4:55:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 3:35:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 3:35:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:06Z. Reason: GVLK.
Information	5/9/2018 3:30:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 3:30:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 3:30:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 3:30:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/9/2018 3:27:16 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/9/2018 3:21:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 3:21:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:42Z. Reason: GVLK.
Warning	5/9/2018 3:20:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/9/2018 3:15:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/9/2018 3:14:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 3:14:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 3:14:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 3:14:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 2:52:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8a08db06-536a-11e8-a79e-204747d02364
Report Status: 0"
Information	5/9/2018 2:35:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 2:35:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:05:05Z. Reason: GVLK.
Information	5/9/2018 2:30:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 2:30:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 2:30:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 2:30:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 2:11:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 2:08:27 PM	MTAService.OnSessionChange	0	None	2:08:27 PM - Session change notice received: SessionLock Session ID: 1
Information	5/9/2018 2:06:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/9/2018 2:06:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31908)(?)])(1 )(2 )]

"
Information	5/9/2018 2:06:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31908)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 2:06:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/9/2018 2:06:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 2:06:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 2:05:40 PM	MTAService.OnSessionChange	0	None	2:05:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 1:53:06 PM	MTAService.OnSessionChange	0	None	1:53:06 PM - Session change notice received: SessionLock Session ID: 1
Information	5/9/2018 1:51:34 PM	MTAService.OnSessionChange	0	None	1:51:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 1:45:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 1:45:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 1:40:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 1:40:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-16T08:04:45Z. Reason: GVLK.
Information	5/9/2018 1:35:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 1:35:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 1:35:44 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/05/09 08:05"
Information	5/9/2018 1:35:40 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/05/09 08:05, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	5/9/2018 1:30:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 1:30:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 1:30:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 1:30:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 1:30:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 1:14:49 PM	MTAService.OnSessionChange	0	None	1:14:49 PM - Session change notice received: SessionLock Session ID: 1
Information	5/9/2018 12:52:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 12:47:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/9/2018 12:47:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31987)(?)])(1 )(2 )]

"
Information	5/9/2018 12:47:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31987)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 12:47:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/9/2018 12:47:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 12:47:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/9/2018 12:42:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8887.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/9/2018 11:42:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 10:30:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/9/2018 10:30:21 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	5/9/2018 9:58:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 9:52:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a02385fc-5340-11e8-a79e-204747d02364
Report Status: 0"
Information	5/9/2018 9:45:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 9:45:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 9:45:14 AM	MTAService.OnSessionChange	0	None	9:45:14 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/9/2018 9:43:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	5/9/2018 9:42:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/9/2018 9:32:11 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/9/2018 9:32:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/9/2018 9:31:47 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/9/2018 9:31:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/9/2018 9:26:42 AM	MTAService.OnSessionChange	0	None	9:26:42 AM - Session change notice received: SessionLock Session ID: 1
Information	5/9/2018 8:49:39 AM	MTAService.OnSessionChange	0	None	8:49:39 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/9/2018 8:15:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/9/2018 6:31:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 5:45:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 5:45:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 4:54:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 4:54:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:22Z. Reason: GVLK.
Information	5/9/2018 4:52:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6714937-5316-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/9/2018 4:50:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 4:49:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 4:49:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 4:49:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 4:49:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/9/2018 4:47:37 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/9/2018 4:45:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/9/2018 4:45:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T07:59:59Z. Reason: GVLK.
Error	5/9/2018 4:40:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/9/2018 4:39:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/9/2018 4:39:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/9/2018 4:39:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/9/2018 4:39:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/9/2018 2:58:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 2:05:37 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/9/2018 1:58:35 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/9/2018 1:45:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/9/2018 1:45:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/9/2018 12:58:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/9/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/8/2018 11:52:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccc27274-52ec-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/8/2018 11:14:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 9:45:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 9:45:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/8/2018 9:28:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 9:11:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 9:11:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:13Z. Reason: GVLK.
Information	5/8/2018 9:06:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 9:06:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 9:06:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 9:06:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/8/2018 8:44:10 PM	MTAService.OnSessionChange	0	None	8:44:10 PM - Session change notice received: SessionLock Session ID: 1
Information	5/8/2018 7:53:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 7:53:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:14Z. Reason: GVLK.
Information	5/8/2018 7:48:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 7:48:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 7:48:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 7:48:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/8/2018 7:45:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 6:52:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e3023184-52c2-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/8/2018 6:05:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 6:03:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎08T12:33:34.263496400Z.
Information	5/8/2018 6:03:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎08T12:33:34.263496400Z.
Information	5/8/2018 6:03:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎05‎-‎08T12:33:25.308496400Z.
Information	5/8/2018 6:03:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎05‎-‎08T12:33:25.308496400Z.
Information	5/8/2018 6:02:50 PM	MTAService.OnSessionChange	0	None	6:02:50 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/8/2018 5:45:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 5:45:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 5:43:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 5:43:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:32Z. Reason: GVLK.
Information	5/8/2018 5:38:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 5:38:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 5:38:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 5:38:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/8/2018 5:10:18 PM	MTAService.OnSessionChange	0	None	5:10:18 PM - Session change notice received: SessionLock Session ID: 1
Information	5/8/2018 4:21:10 PM	MTAService.OnSessionChange	0	None	4:21:10 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/8/2018 4:10:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 3:59:15 PM	MTAService.OnSessionChange	0	None	3:59:14 PM - Session change notice received: SessionLock Session ID: 1
Information	5/8/2018 2:21:26 PM	MTAService.OnSessionChange	0	None	2:21:26 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/8/2018 2:13:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 1:52:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f925f561-5298-11e8-a79e-204747d02364
Report Status: 0"
Information	5/8/2018 1:45:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 1:45:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 1:18:20 PM	MTAService.OnSessionChange	0	None	1:18:20 PM - Session change notice received: SessionLock Session ID: 1
Information	5/8/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/8/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33427)(?)])(1 )(2 )]

"
Information	5/8/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33427)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/8/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/8/2018 12:17:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 12:01:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8886.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/8/2018 12:01:12 PM	MTAService.OnSessionChange	0	None	12:01:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/8/2018 11:38:27 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 22395, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/8/2018 11:37:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	5/8/2018 11:31:41 AM	MTAService.OnSessionChange	0	None	11:31:41 AM - Session change notice received: SessionLock Session ID: 1
Information	5/8/2018 11:14:41 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	5/8/2018 11:14:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	5/8/2018 10:42:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 10:04:33 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/8/2018 10:04:07 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/8/2018 9:59:32 AM	MTAService.OnSessionChange	0	None	9:59:32 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/8/2018 9:45:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 9:44:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 9:43:15 AM	MTAService.OnSessionChange	0	None	9:43:15 AM - Session change notice received: SessionLock Session ID: 1
Error	5/8/2018 9:42:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/8/2018 9:42:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/8/2018 9:42:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/8/2018 9:36:22 AM	MTAService.OnSessionChange	0	None	9:36:22 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/8/2018 9:10:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 8:52:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f66f819-526f-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/8/2018 7:27:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 5:45:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 5:45:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 5:44:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/8/2018 5:30:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 4:35:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 4:35:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:12Z. Reason: GVLK.
Information	5/8/2018 4:30:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 4:30:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 4:30:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 4:30:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/8/2018 4:04:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 4:04:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:32Z. Reason: GVLK.
Information	5/8/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/8/2018 3:57:57 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/8/2018 3:55:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/8/2018 3:55:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:40Z. Reason: GVLK.
Information	5/8/2018 3:52:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25c08415-5245-11e8-a79e-204747d02364
Report Status: 0"
Error	5/8/2018 3:50:52 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/8/2018 3:47:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/8/2018 3:47:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/8/2018 3:47:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/8/2018 3:47:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/8/2018 3:46:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/8/2018 1:52:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/8/2018 1:45:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 1:44:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 1:44:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/8/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/7/2018 11:56:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 10:52:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3c0dd5be-521b-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/7/2018 9:56:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 9:45:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 9:44:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 9:44:54 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/7/2018 9:44:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 9:30:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 9:30:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:24Z. Reason: GVLK.
Information	5/7/2018 9:25:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/7/2018 9:25:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 9:25:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 9:25:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/7/2018 8:28:40 PM	MTAService.OnSessionChange	0	None	8:28:40 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/7/2018 8:01:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 7:58:15 PM	MTAService.OnSessionChange	0	None	7:58:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 7:03:07 PM	MTAService.OnSessionChange	0	None	7:03:07 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/7/2018 6:15:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 6:05:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 6:00:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/7/2018 6:00:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34554)(?)])(1 )(2 )]

"
Information	5/7/2018 6:00:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34554)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 6:00:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/7/2018 6:00:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 6:00:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/7/2018 5:54:10 PM	MTAService.OnSessionChange	0	None	5:54:10 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 5:52:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 52684a76-51f1-11e8-a79e-204747d02364
Report Status: 0"
Information	5/7/2018 5:45:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 5:44:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 5:13:24 PM	MTAService.OnSessionChange	0	None	5:13:24 PM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 4:28:33 PM	MTAService.OnSessionChange	0	None	4:28:33 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/7/2018 4:20:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 4:07:05 PM	MTAService.OnSessionChange	0	None	4:07:05 PM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 3:47:59 PM	MTAService.OnSessionChange	0	None	3:47:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 3:35:29 PM	MTAService.OnSessionChange	0	None	3:35:29 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/7/2018 2:40:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 2:17:37 PM	MTAService.OnSessionChange	0	None	2:17:37 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 1:45:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 1:44:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 1:44:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 1:15:57 PM	MTAService.OnSessionChange	0	None	1:15:57 PM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 1:10:48 PM	MTAService.OnSessionChange	0	None	1:10:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 1:10:36 PM	MTAService.OnSessionChange	0	None	1:10:36 PM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 12:52:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 68b54c64-51c7-11e8-a79e-204747d02364
Report Status: 0"
Information	5/7/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/7/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34867)(?)])(1 )(2 )]

"
Information	5/7/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34867)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/7/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/7/2018 12:44:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 12:15:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 12:15:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:19Z. Reason: GVLK.
Information	5/7/2018 12:10:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/7/2018 12:10:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 12:10:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 12:10:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/7/2018 12:02:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8885.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/7/2018 12:01:23 PM	MTAService.OnSessionChange	0	None	12:01:23 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 11:33:05 AM	MTAService.OnSessionChange	0	None	11:33:05 AM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 11:19:13 AM	MTAService.OnSessionChange	0	None	11:19:13 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/7/2018 11:09:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 11:08:41 AM	MTAService.OnSessionChange	0	None	11:08:41 AM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 10:13:27 AM	MTAService.OnSessionChange	0	None	10:13:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 9:46:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/7/2018 9:44:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 9:44:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 9:42:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	5/7/2018 9:42:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/7/2018 9:42:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/7/2018 9:40:06 AM	MTAService.OnSessionChange	0	None	9:40:06 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/7/2018 9:36:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/7/2018 9:17:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/7/2018 9:17:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/7/2018 9:00:49 AM	MTAService.OnSessionChange	0	None	9:00:49 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/7/2018 8:57:59 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/7/2018 8:57:45 AM	MTAService.OnSessionChange	0	None	8:57:45 AM - Session change notice received: SessionLock Session ID: 1
Information	5/7/2018 8:57:38 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/7/2018 8:57:16 AM	MTAService.OnSessionChange	0	None	8:57:16 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	5/7/2018 7:56:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 7:52:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7ef298f6-519d-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/7/2018 6:06:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 5:44:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 5:44:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/7/2018 4:25:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 3:30:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 3:30:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:52Z. Reason: GVLK.
Information	5/7/2018 3:25:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/7/2018 3:25:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 3:25:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 3:25:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/7/2018 3:23:26 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/7/2018 3:20:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 3:20:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:48Z. Reason: GVLK.
Error	5/7/2018 3:16:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 3:15:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 3:15:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/7/2018 2:52:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 954b5e46-5173-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/7/2018 2:39:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 1:44:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/7/2018 1:44:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/7/2018 1:05:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/7/2018 12:31:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/7/2018 12:31:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:16Z. Reason: GVLK.
Information	5/7/2018 12:26:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/7/2018 12:26:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/7/2018 12:26:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/7/2018 12:26:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/6/2018 11:20:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 9:52:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aba3bdd3-5149-11e8-a79e-204747d02364
Report Status: 0"
Information	5/6/2018 9:44:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 9:44:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/6/2018 9:28:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/6/2018 7:51:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 7:18:48 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	5/6/2018 6:09:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 5:44:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 5:44:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/6/2018 5:43:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 4:52:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1fe328b-511f-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/6/2018 4:19:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 4:09:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 4:09:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:39Z. Reason: GVLK.
Information	5/6/2018 4:04:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/6/2018 4:04:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 4:04:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 4:04:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/6/2018 2:30:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 1:43:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/6/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36307)(?)])(1 )(2 )]

"
Information	5/6/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36307)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/6/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/6/2018 12:40:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 12:10:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8884.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/6/2018 11:52:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d847e0f1-50f5-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/6/2018 10:52:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 9:43:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 9:43:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	5/6/2018 9:42:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/6/2018 9:30:29 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/6/2018 9:30:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/6/2018 9:30:27 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/6/2018 9:30:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/6/2018 9:30:03 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/6/2018 9:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	5/6/2018 8:57:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/6/2018 7:00:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 6:52:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee9c0629-50cb-11e8-a79e-204747d02364
Report Status: 0"
Information	5/6/2018 5:43:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 5:43:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 5:43:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 5:37:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 5:37:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:44Z. Reason: GVLK.
Information	5/6/2018 5:32:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/6/2018 5:32:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 5:32:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 5:32:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/6/2018 5:15:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 5:15:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:37Z. Reason: GVLK.
Information	5/6/2018 5:10:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/6/2018 5:10:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 5:10:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 5:10:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/6/2018 5:07:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/6/2018 3:30:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 3:30:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 3:30:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:16Z. Reason: GVLK.
Information	5/6/2018 3:25:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/6/2018 3:25:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 3:25:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 3:25:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/6/2018 3:23:38 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/6/2018 3:21:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/6/2018 3:21:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:14Z. Reason: GVLK.
Error	5/6/2018 3:16:30 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/6/2018 3:16:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/6/2018 3:16:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/6/2018 3:16:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/6/2018 3:16:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/6/2018 1:52:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 04f44e85-50a2-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/6/2018 1:50:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 1:43:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 1:43:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/6/2018 1:43:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/6/2018 12:14:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/6/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	5/5/2018 10:42:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 9:43:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 9:43:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 8:52:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b4d04fb-5078-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/5/2018 8:47:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 7:34:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/5/2018 7:34:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:07Z. Reason: GVLK.
Information	5/5/2018 7:29:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/5/2018 7:29:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/5/2018 7:29:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/5/2018 7:29:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/5/2018 7:10:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 5:43:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 5:43:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 5:42:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/5/2018 5:25:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 3:52:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31b0fc6e-504e-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/5/2018 3:32:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/5/2018 1:48:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 1:43:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 1:43:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 1:42:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37747)(?)])(1 )(2 )]

"
Information	5/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37747)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/5/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/5/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/5/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/5/2018 12:01:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8883.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	5/5/2018 11:51:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 11:31:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 14, Compared: 22342, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/5/2018 11:30:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	5/5/2018 10:52:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47e66a6d-5024-11e8-a79e-204747d02364
Report Status: 0"
Information	5/5/2018 10:28:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/5/2018 10:28:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T07:59:59Z. Reason: GVLK.
Information	5/5/2018 10:22:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/5/2018 10:22:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/5/2018 10:22:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/5/2018 10:22:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/5/2018 10:14:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 9:44:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/5/2018 9:43:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 9:42:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	5/5/2018 9:42:31 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/5/2018 8:35:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/5/2018 6:36:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 5:52:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5e48da01-4ffa-11e8-a79e-204747d02364
Report Status: 0"
Information	5/5/2018 5:43:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 5:42:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/5/2018 4:45:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/5/2018 2:51:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 1:43:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 1:42:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/5/2018 1:42:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/5/2018 12:52:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/5/2018 12:52:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74d259e4-4fd0-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/4/2018 11:06:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 9:43:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/4/2018 9:43:00 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/4/2018 9:42:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/4/2018 9:24:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 8:49:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/4/2018 8:49:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T07:59:59Z. Reason: GVLK.
Information	5/4/2018 8:44:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/4/2018 8:44:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/4/2018 8:44:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/4/2018 8:44:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/4/2018 7:52:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b29e50b-4fa6-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/4/2018 7:47:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 6:52:40 PM	MTAService.OnSessionChange	0	None	6:52:40 PM - Session change notice received: SessionLock Session ID: 1
Error	5/4/2018 6:50:01 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/4/2018 6:50:01 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/4/2018 6:16:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 5:42:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/4/2018 5:17:44 PM	MTAService.OnSessionChange	0	None	5:17:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/4/2018 4:56:04 PM	MTAService.OnSessionChange	0	None	4:56:04 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/4/2018 4:17:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 2:52:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a15f0c75-4f7c-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/4/2018 2:33:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 2:14:14 PM	MTAService.OnSessionChange	0	None	2:14:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/4/2018 1:42:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/4/2018 1:11:16 PM	MTAService.OnSessionChange	0	None	1:11:16 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/4/2018 1:00:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/4/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/4/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39187)(?)])(1 )(2 )]

"
Information	5/4/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39187)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/4/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/4/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/4/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/4/2018 12:13:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8882.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	5/4/2018 12:02:01 PM	MTAService.OnSessionChange	0	None	12:02:01 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/4/2018 11:49:22 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/4/2018 11:24:56 AM	MTAService.OnSessionChange	0	None	11:24:56 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/4/2018 11:21:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 10:14:39 AM	MTAService.OnSessionChange	0	None	10:14:39 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/4/2018 10:07:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/4/2018 10:07:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:04Z. Reason: GVLK.
Information	5/4/2018 10:02:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/4/2018 10:02:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/4/2018 10:02:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/4/2018 10:02:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/4/2018 10:00:06 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/4/2018 9:58:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/4/2018 9:58:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:30Z. Reason: GVLK.
Information	5/4/2018 9:53:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/4/2018 9:53:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/4/2018 9:53:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/4/2018 9:53:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/4/2018 9:52:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b70010c4-4f52-11e8-a79e-204747d02364
Report Status: 0"
Information	5/4/2018 9:51:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/4/2018 9:51:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:37Z. Reason: GVLK.
Error	5/4/2018 9:47:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/4/2018 9:46:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/4/2018 9:46:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/4/2018 9:46:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/4/2018 9:46:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	5/4/2018 9:44:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/4/2018 9:44:07 AM	MTAService.OnSessionChange	0	None	9:44:07 AM - Session change notice received: SessionLock Session ID: 1
Error	5/4/2018 9:42:30 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/4/2018 9:42:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/4/2018 9:42:18 AM	MTAService.OnSessionChange	0	None	9:42:18 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/4/2018 9:42:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/4/2018 9:42:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/4/2018 9:42:10 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	5/3/2018 8:35:09 PM	MTAService.OnSessionChange	0	None	8:35:09 PM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 8:17:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 8:15:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 8:15:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 7:57:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a3ab15e-4ede-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/3/2018 7:43:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/3/2018 6:26:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/3/2018 5:57:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 5:31:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/3/2018 5:26:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/3/2018 5:26:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40348)(?)])(1 )(2 )]

"
Information	5/3/2018 5:26:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40348)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/3/2018 5:26:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/3/2018 5:26:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/3/2018 5:26:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/3/2018 5:21:38 PM	MTAService.OnSessionChange	0	None	5:21:38 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 4:40:17 PM	MTAService.OnSessionChange	0	None	4:40:17 PM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 4:17:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	5/3/2018 4:17:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 4:15:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 4:15:29 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/3/2018 4:15:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 4:11:02 PM	MTAService.OnSessionChange	0	None	4:11:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 4:09:50 PM	MTAService.OnSessionChange	0	None	4:09:50 PM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 2:57:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30743b7b-4eb4-11e8-a79e-204747d02364
Report Status: 0"
Information	5/3/2018 2:33:41 PM	McLogEvent	257	None	Would be blocked by access protection rule  (rule is in warn-only mode) (Anti-virus Standard Protection:Prevent remote creation/modification of executable and configuration files).
Warning	5/3/2018 2:31:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 2:08:54 PM	MTAService.OnSessionChange	0	None	2:08:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 1:47:49 PM	MTAService.OnSessionChange	0	None	1:47:49 PM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 1:45:22 PM	MTAService.OnSessionChange	0	None	1:45:22 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 1:16:29 PM	MTAService.OnSessionChange	0	None	1:16:29 PM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 12:52:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	5/3/2018 12:50:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/3/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40627)(?)])(1 )(2 )]

"
Information	5/3/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40627)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/3/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/3/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/3/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/3/2018 12:26:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8881.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	5/3/2018 12:17:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 12:14:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 11:54:52 AM	MTAService.OnSessionChange	0	None	11:54:52 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 11:31:47 AM	MTAService.OnSessionChange	0	None	11:31:47 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/3/2018 11:10:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 10:36:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/3/2018 10:36:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:24Z. Reason: GVLK.
Information	5/3/2018 10:31:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/3/2018 10:31:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/3/2018 10:31:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/3/2018 10:31:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/3/2018 10:21:28 AM	PostgreSQL	0	None	Server started and accepting connections

Information	5/3/2018 10:21:09 AM	PostgreSQL	0	None	"2018-05-03 10:21:09 IST LOG:  redirecting log output to logging collector process
2018-05-03 10:21:09 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	5/3/2018 10:21:09 AM	PostgreSQL	0	None	Waiting for server startup...

Information	5/3/2018 10:13:55 AM	MTAService.OnSessionChange	0	None	10:13:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 9:57:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 469495ec-4e8a-11e8-a79e-204747d02364
Report Status: 0"
Information	5/3/2018 9:54:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/3/2018 9:54:21 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	5/3/2018 9:53:49 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/3/2018 9:53:47 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	5/3/2018 9:48:40 AM	MTAService.OnSessionChange	0	None	9:48:40 AM - Session change notice received: SessionLock Session ID: 1
Information	5/3/2018 9:27:38 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	5/3/2018 9:27:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	5/3/2018 9:26:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/3/2018 9:24:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	5/3/2018 9:21:10 AM	MTAService.OnSessionChange	0	None	9:21:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/3/2018 8:16:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/3/2018 8:14:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/3/2018 5:13:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/3/2018 5:13:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:36Z. Reason: GVLK.
Information	5/3/2018 5:08:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/3/2018 5:08:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/3/2018 5:08:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/3/2018 5:08:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/3/2018 5:07:03 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/3/2018 5:05:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/3/2018 5:05:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:35Z. Reason: GVLK.
Error	5/3/2018 5:00:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/3/2018 5:00:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/3/2018 5:00:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/3/2018 5:00:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/3/2018 5:00:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/3/2018 4:16:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/3/2018 4:14:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	5/3/2018 12:16:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 12:14:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/3/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/2/2018 11:57:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 740eeb9b-4e36-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/2/2018 11:52:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/2/2018 10:15:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/2/2018 8:17:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/2/2018 8:16:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 8:14:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 8:09:04 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	5/2/2018 8:06:13 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	5/2/2018 7:54:07 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	5/2/2018 7:24:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 7:24:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T08:00:32Z. Reason: GVLK.
Information	5/2/2018 7:19:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 7:19:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 7:19:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 7:19:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 7:02:36 PM	MTAService.OnSessionChange	0	None	7:02:36 PM - Session change notice received: SessionLock Session ID: 1
Information	5/2/2018 6:57:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8a5f1640-4e0c-11e8-a79e-204747d02364
Report Status: 0"
Warning	5/2/2018 6:18:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	5/2/2018 4:20:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/2/2018 4:16:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 4:14:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 3:45:49 PM	MTAService.OnSessionChange	0	None	3:45:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/2/2018 3:32:58 PM	MTAService.OnSessionChange	0	None	3:32:58 PM - Session change notice received: SessionLock Session ID: 1
Warning	5/2/2018 2:27:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/2/2018 2:05:04 PM	MTAService.OnSessionChange	0	None	2:05:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/2/2018 1:57:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e9ffcd2-4de2-11e8-a79e-204747d02364
Report Status: 0"
Information	5/2/2018 1:42:00 PM	MTAService.OnSessionChange	0	None	1:42:00 PM - Session change notice received: SessionLock Session ID: 1
Information	5/2/2018 1:38:47 PM	MTAService.OnSessionChange	0	None	1:38:47 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/2/2018 1:35:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 1:35:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-09T07:59:57Z. Reason: GVLK.
Information	5/2/2018 1:30:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 1:30:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 1:30:56 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/05/02 08:00"
Information	5/2/2018 1:30:56 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/05/02 08:00, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	5/2/2018 1:25:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 1:25:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 1:25:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 1:25:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 1:19:00 PM	MTAService.OnSessionChange	0	None	1:19:00 PM - Session change notice received: SessionLock Session ID: 1
Information	5/2/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/2/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42067)(?)])(1 )(2 )]

"
Information	5/2/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42067)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/2/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 12:47:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	5/2/2018 12:45:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/2/2018 12:19:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 12:18:05 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 36, Deleted: 0, Modified: 43, Compared: 22183, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	5/2/2018 12:16:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 12:16:22 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	5/2/2018 12:14:22 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 109

Information	5/2/2018 12:14:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	5/2/2018 12:13:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/2/2018 12:13:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42101)(?)])(1 )(2 )]

"
Information	5/2/2018 12:13:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42101)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 12:13:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/2/2018 12:13:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 12:13:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 12:12:19 PM	MTAService.OnSessionChange	0	None	12:12:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/2/2018 11:38:13 AM	MTAService.OnSessionChange	0	None	11:38:13 AM - Session change notice received: SessionLock Session ID: 1
Warning	5/2/2018 10:47:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	5/2/2018 10:13:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 10:13:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:50Z. Reason: GVLK.
Information	5/2/2018 10:08:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 10:08:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 10:08:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 10:08:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 9:49:53 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8880.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	5/2/2018 9:48:55 AM	MTAService.OnSessionChange	0	None	9:48:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	5/2/2018 9:43:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 9:43:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:48Z. Reason: GVLK.
Information	5/2/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 9:38:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 9:24:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 9:24:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:51Z. Reason: GVLK.
Information	5/2/2018 9:21:18 AM	MTAService.OnSessionChange	0	None	9:21:18 AM - Session change notice received: SessionLock Session ID: 1
Information	5/2/2018 9:19:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 9:19:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 9:19:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 9:19:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	5/2/2018 9:18:23 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	5/2/2018 9:13:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 9:13:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:47Z. Reason: GVLK.
Error	5/2/2018 9:03:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	5/2/2018 9:02:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	5/2/2018 9:01:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/2/2018 9:00:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/2/2018 8:56:21 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	5/2/2018 8:55:23 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8879.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	5/2/2018 8:55:23 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/2/2018 8:55:22 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/2/2018 8:55:21 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/2/2018 8:55:16 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	5/2/2018 8:55:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {36D514C5-E4EA-4A67-A066-E2EA281BC7C5}
Error	5/2/2018 8:55:15 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {36D514C5-E4EA-4A67-A066-E2EA281BC7C5}
Information	5/2/2018 8:55:01 AM	ESENT	302	Logging/Recovery	Windows (8272) Windows: The database engine has successfully completed recovery steps.
Information	5/2/2018 8:54:54 AM	ESENT	301	Logging/Recovery	Windows (8272) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/2/2018 8:54:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/2/2018 8:54:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 8:54:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 8:54:43 AM	ESENT	301	Logging/Recovery	Windows (8272) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0067A.log.
Information	5/2/2018 8:54:43 AM	ESENT	300	Logging/Recovery	Windows (8272) Windows: The database engine is initiating recovery steps.
Information	5/2/2018 8:54:42 AM	ESENT	102	General	Windows (8272) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/2/2018 8:54:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/2/2018 8:54:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/2/2018 8:54:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42300)(?)])(1 )(2 )]

"
Information	5/2/2018 8:54:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/2/2018 8:54:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/2/2018 8:54:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/2/2018 8:54:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	5/2/2018 8:54:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	5/2/2018 8:54:18 AM	Service1	0	None	Service started successfully.
Error	5/2/2018 8:54:10 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/2/2018 8:54:07 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/2/2018 8:53:31 AM	MTAService.OnSessionChange	0	None	8:53:31 AM - Logon : 212558710
Information	5/2/2018 8:53:31 AM	MTAService.OnSessionChange	0	None	8:53:31 AM - Session change notice received: SessionLogon Session ID: 1
Information	5/2/2018 8:53:30 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/2/2018 8:53:30 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/2/2018 8:53:30 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:30 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/2/2018 8:53:29 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/2/2018 8:53:28 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4060 at 5/1/2018 3:34:13 PM (local) 5/1/2018 10:04:13 AM (UTC). This is an informational message only; no user action is required.
Information	5/2/2018 8:53:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/2/2018 8:53:26 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/2/2018 8:53:26 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/2/2018 8:53:26 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/2/2018 8:53:26 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/2/2018 8:53:23 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/2/2018 8:53:22 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/2/2018 8:53:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/2/2018 8:53:22 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	5/2/2018 8:53:22 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/2/2018 8:53:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/2/2018 8:53:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/2/2018 8:53:13 AM	MTAService	0	None	Service started successfully.
Information	5/2/2018 8:53:13 AM	MTAService.OnStart	0	None	8:53:12 AM - Waiting for user to Logon
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3768.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/2/2018 8:53:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/2/2018 8:52:59 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/2/2018 8:52:58 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/2/2018 8:52:45 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/2/2018 8:52:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/2/2018 8:52:45 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	5/1/2018 3:34:19 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	5/1/2018 3:34:13 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	5/1/2018 3:34:11 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 15 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 3920 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 3920 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	5/1/2018 3:34:11 PM	MTAService.OnSessionChange	0	None	3:34:11 PM - Logoff
Information	5/1/2018 3:34:11 PM	MTAService.OnSessionChange	0	None	3:34:11 PM - Session change notice received: SessionLogoff Session ID: 1
Information	5/1/2018 3:34:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	5/1/2018 3:34:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	5/1/2018 3:34:10 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	5/1/2018 3:34:04 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	5/1/2018 3:33:53 PM	MTAService.OnSessionChange	0	None	3:33:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/1/2018 3:33:42 PM	MTAService.OnSessionChange	0	None	3:33:42 PM - Session change notice received: SessionLock Session ID: 1
Information	5/1/2018 3:26:45 PM	MTAService.OnSessionChange	0	None	3:26:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/1/2018 3:19:50 PM	MTAService.OnSessionChange	0	None	3:19:50 PM - Session change notice received: SessionLock Session ID: 1
Information	5/1/2018 3:00:49 PM	MTAService.OnSessionChange	0	None	3:00:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/1/2018 2:26:19 PM	MTAService.OnSessionChange	0	None	2:26:19 PM - Session change notice received: SessionLock Session ID: 1
Information	5/1/2018 1:48:42 PM	MTAService.OnSessionChange	0	None	1:48:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/1/2018 1:24:27 PM	MTAService.OnSessionChange	0	None	1:24:27 PM - Session change notice received: SessionLock Session ID: 1
Information	5/1/2018 12:52:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/1/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43507)(?)])(1 )(2 )]

"
Information	5/1/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43507)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/1/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 12:47:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 12:28:19 PM	MTAService.OnSessionChange	0	None	12:28:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	5/1/2018 12:21:38 PM	MTAService.OnSessionChange	0	None	12:21:38 PM - Session change notice received: SessionLock Session ID: 1
Information	5/1/2018 12:04:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 12:04:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:39Z. Reason: GVLK.
Information	5/1/2018 11:59:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/1/2018 11:59:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 11:59:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 11:59:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 11:49:01 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8879.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	5/1/2018 11:34:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 11:34:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:38Z. Reason: GVLK.
Information	5/1/2018 11:29:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/1/2018 11:29:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 11:29:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 11:29:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 11:04:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 11:04:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:38Z. Reason: GVLK.
Information	5/1/2018 10:59:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/1/2018 10:59:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 10:59:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 10:59:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 10:58:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 10:58:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:55Z. Reason: GVLK.
Information	5/1/2018 10:53:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/1/2018 10:53:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 10:53:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 10:53:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 10:51:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 10:51:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:50Z. Reason: GVLK.
Information	5/1/2018 10:50:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	5/1/2018 10:46:05 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	5/1/2018 10:45:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	5/1/2018 10:45:57 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0F45C039-F917-4870-822C-91AADD5ABAB6}
Error	5/1/2018 10:45:57 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0F45C039-F917-4870-822C-91AADD5ABAB6}
Information	5/1/2018 10:45:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	5/1/2018 10:45:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	5/1/2018 10:45:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43629)(?)])(1 )(2 )]

"
Information	5/1/2018 10:45:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43629)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 10:45:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	5/1/2018 10:45:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 10:45:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 10:45:10 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/1/2018 10:45:09 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/1/2018 10:45:08 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/1/2018 10:44:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	5/1/2018 10:44:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	5/1/2018 10:44:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	5/1/2018 10:44:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	5/1/2018 10:44:27 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	5/1/2018 10:44:22 AM	MTAService.OnSessionChange	0	None	10:44:22 AM - Logon : 212558710
Information	5/1/2018 10:44:22 AM	MTAService.OnSessionChange	0	None	10:44:22 AM - Session change notice received: SessionLogon Session ID: 1
Information	5/1/2018 10:44:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	5/1/2018 10:44:21 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	5/1/2018 10:44:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	5/1/2018 10:44:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	5/1/2018 10:44:17 AM	ESENT	302	Logging/Recovery	Windows (6428) Windows: The database engine has successfully completed recovery steps.
Information	5/1/2018 10:44:15 AM	ESENT	301	Logging/Recovery	Windows (6428) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	5/1/2018 10:44:15 AM	ESENT	300	Logging/Recovery	Windows (6428) Windows: The database engine is initiating recovery steps.
Information	5/1/2018 10:44:14 AM	ESENT	102	General	Windows (6428) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	5/1/2018 10:44:02 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8878.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	5/1/2018 10:43:53 AM	Service1	0	None	Service started successfully.
Error	5/1/2018 10:43:49 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	5/1/2018 10:43:49 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	5/1/2018 10:43:47 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	5/1/2018 10:43:45 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	5/1/2018 10:43:41 AM	MTAService	0	None	Service started successfully.
Information	5/1/2018 10:43:41 AM	MTAService.OnStart	0	None	10:43:40 AM - Waiting for user to Logon
Information	5/1/2018 10:43:40 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	5/1/2018 10:43:29 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:28 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	5/1/2018 10:43:27 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	5/1/2018 10:43:27 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	5/1/2018 10:43:27 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4080 at 4/24/2018 8:53:14 AM (local) 4/24/2018 3:23:14 AM (UTC). This is an informational message only; no user action is required.
Information	5/1/2018 10:43:23 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	5/1/2018 10:43:21 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	5/1/2018 10:43:21 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	5/1/2018 10:43:21 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	5/1/2018 10:43:21 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	5/1/2018 10:43:21 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4060.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	5/1/2018 10:43:20 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	5/1/2018 10:42:46 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	5/1/2018 10:42:40 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	5/1/2018 10:42:26 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	5/1/2018 10:42:26 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	5/1/2018 10:42:26 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	4/30/2018 10:48:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/30/2018 10:13:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/30/2018 10:13:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/30/2018 10:10:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/30/2018 10:10:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:42Z. Reason: GVLK.
Information	4/30/2018 10:07:46 PM	MTAService.OnSessionChange	0	None	10:07:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 10:05:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/30/2018 10:05:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/30/2018 10:05:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/30/2018 10:05:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/30/2018 9:52:44 PM	MTAService.OnSessionChange	0	None	9:52:44 PM - Session change notice received: SessionLock Session ID: 1
Information	4/30/2018 9:37:44 PM	MTAService.OnSessionChange	0	None	9:37:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 9:27:48 PM	MTAService.OnSessionChange	0	None	9:27:48 PM - Session change notice received: SessionLock Session ID: 1
Information	4/30/2018 9:06:43 PM	RasClient	20225	None	CoId={4B94AA16-9B4C-4440-90AA-11C37400703C}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.234.66
TunnelIpv6Address = None
Dial-in User = .
Information	4/30/2018 9:06:38 PM	RasClient	20224	None	CoId={4B94AA16-9B4C-4440-90AA-11C37400703C}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/30/2018 9:06:38 PM	RasClient	20223	None	CoId={4B94AA16-9B4C-4440-90AA-11C37400703C}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 9:06:38 PM	RasClient	20222	None	CoId={4B94AA16-9B4C-4440-90AA-11C37400703C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 9:06:38 PM	RasClient	20221	None	CoId={4B94AA16-9B4C-4440-90AA-11C37400703C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/30/2018 9:05:19 PM	Group Policy Registry	8194	(2)	The client-side extension could not apply computer policy settings for 'Logon_Disable_IPv6_ALL {FCA4FE78-369E-42C2-9BE4-4AB7AA05E07E}' because it failed with error code '0x80070035 The network path was not found.' See trace file for more details.
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{31b2f340-016d-11d2-945f-00c04fb984f9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\SysVol\logon.ds.ge.com\Policies\{6D2A5CDB-AF09-4F1C-8632-37CAA44C207E}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{05eb30ed-da8b-4d49-ad9a-591b1ba3f8c0}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{2c2a6b24-042d-4cdb-8d2e-ffc6ac1c75da}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{863fb769-0f91-41e7-83b8-4ac4cc1185a4}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{f1cbf5c9-4c6e-415a-a8d6-9bee23ad3775}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Error	4/30/2018 9:04:58 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{944fee05-2d40-4de0-8377-9b52ddd1a65f}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Information	4/30/2018 9:04:08 PM	RasClient	20226	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	4/30/2018 9:03:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/30/2018 8:58:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/30/2018 8:58:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44456)(?)])(1 )(2 )]

"
Information	4/30/2018 8:58:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44456)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/30/2018 8:58:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/30/2018 8:58:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/30/2018 8:58:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/30/2018 8:55:52 PM	MTAService.OnSessionChange	0	None	8:55:52 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 8:38:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 8:37:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 8:37:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 8:37:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 7:54:59 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/30/2018 7:15:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 7:07:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ead5975-4c7b-11e8-8799-204747d02364
Report Status: 0"
Information	4/30/2018 7:03:27 PM	MTAService.OnSessionChange	0	None	7:03:27 PM - Session change notice received: SessionLock Session ID: 1
Information	4/30/2018 6:58:42 PM	RasClient	20225	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.234.91
TunnelIpv6Address = None
Dial-in User = .
Information	4/30/2018 6:58:37 PM	RasClient	20224	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/30/2018 6:58:37 PM	RasClient	20223	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 6:58:37 PM	RasClient	20222	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 6:58:37 PM	RasClient	20221	None	CoId={90ECEF8B-F5B2-4CDA-AA4E-D08C951E2F15}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/30/2018 6:57:17 PM	MTAService.OnSessionChange	0	None	6:57:17 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 6:10:44 PM	MTAService.OnSessionChange	0	None	6:10:44 PM - Session change notice received: SessionLock Session ID: 1
Information	4/30/2018 6:10:43 PM	RasClient	20226	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	4/30/2018 5:58:02 PM	RasClient	20225	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.253.67
TunnelIpv6Address = None
Dial-in User = .
Information	4/30/2018 5:57:57 PM	RasClient	20224	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/30/2018 5:57:57 PM	RasClient	20223	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 5:57:57 PM	RasClient	20222	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 5:57:57 PM	RasClient	20221	None	CoId={60892966-53E8-4E01-84EB-ACC25E8F7B8D}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/30/2018 5:56:36 PM	RasClient	20226	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	4/30/2018 5:36:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 4:59:40 PM	MTAService.OnSessionChange	0	None	4:59:40 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 4:57:01 PM	MTAService.OnSessionChange	0	None	4:57:01 PM - Session change notice received: SessionLock Session ID: 1
Error	4/30/2018 4:47:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/30/2018 4:38:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 4:37:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 4:37:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 4:33:08 PM	MTAService.OnSessionChange	0	None	4:33:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 4:21:27 PM	MTAService.OnSessionChange	0	None	4:21:27 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/30/2018 3:43:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 2:27:18 PM	MTAService.OnSessionChange	0	None	2:27:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 2:15:01 PM	MTAService.OnSessionChange	0	None	2:15:01 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/30/2018 1:52:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 1:47:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f9e5d52c-4c4e-11e8-8799-204747d02364
Report Status: 0"
Information	4/30/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/30/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/30/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44947)(?)])(1 )(2 )]

"
Information	4/30/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44947)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/30/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/30/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/30/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/30/2018 12:37:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 12:37:47 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/30/2018 12:37:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/30/2018 12:19:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/30/2018 12:14:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/30/2018 12:14:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44980)(?)])(1 )(2 )]

"
Information	4/30/2018 12:14:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44980)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/30/2018 12:13:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/30/2018 12:13:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44981)(?)])(1 )(2 )]

"
Information	4/30/2018 12:13:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44981)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/30/2018 12:13:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/30/2018 12:13:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/30/2018 12:13:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/30/2018 12:13:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8878.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/30/2018 12:11:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 12:07:12 PM	MTAService.OnSessionChange	0	None	12:07:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 11:52:29 AM	MTAService.OnSessionChange	0	None	11:52:29 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/30/2018 10:34:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 10:08:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/30/2018 10:08:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/30/2018 10:08:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/30/2018 10:07:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 22041, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/30/2018 10:07:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/30/2018 10:07:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/30/2018 8:47:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f3f0adc-4c25-11e8-8799-204747d02364
Report Status: 0"
Warning	4/30/2018 8:43:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/30/2018 8:40:36 AM	RasClient	20225	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.247.213
TunnelIpv6Address = None
Dial-in User = .
Information	4/30/2018 8:40:30 AM	RasClient	20224	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/30/2018 8:40:30 AM	RasClient	20223	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 8:40:30 AM	RasClient	20222	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/30/2018 8:40:30 AM	RasClient	20221	None	CoId={D503F060-E302-4540-9474-E29B6A4E4E44}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/30/2018 8:37:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/30/2018 8:37:24 AM	MTAService.OnSessionChange	0	None	8:37:24 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/30/2018 8:37:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/30/2018 8:37:23 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	4/30/2018 8:37:23 AM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x2d34302d
Faulting process id: 0x3c34
Faulting application start time: 0x01d3dfabc0fd1061
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: 99ea285f-4c23-11e8-8799-204747d02364"
Information	4/30/2018 8:37:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	4/29/2018 6:33:40 PM	RasClient	20227	None	CoId={26480C01-C911-4E32-B52A-BA797A83BD28}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/29/2018 6:33:40 PM	RasClient	20221	None	CoId={26480C01-C911-4E32-B52A-BA797A83BD28}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/29/2018 6:33:40 PM	RasClient	20227	None	CoId={27E27505-BEA5-4308-8EF6-4F761B5C61F9}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/29/2018 6:33:40 PM	RasClient	20221	None	CoId={27E27505-BEA5-4308-8EF6-4F761B5C61F9}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/29/2018 6:33:30 PM	MTAService.OnSessionChange	0	None	6:33:30 PM - Session change notice received: SessionLock Session ID: 1
Information	4/29/2018 6:33:20 PM	RasClient	20226	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	4/29/2018 6:06:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/29/2018 6:06:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:20Z. Reason: GVLK.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, April 27, 2018 11:59:35 PM.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UCA Global Root, O=UniTrust, C=CN> Sha1 thumbprint: <0B972C9EA6E7CC58D93B20BF71EC412E7209FABF>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Staat der Nederlanden Root CA, O=Staat der Nederlanden, C=NL> Sha1 thumbprint: <101DFA3FD50BCBBB9BB5600C1955A41AF4733A04>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=CA DATEV STD 01, O=DATEV eG, C=DE> Sha1 thumbprint: <150332A58DC591FC42D4C873FF9F1F0F81D597C9>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3, OU=Kamu Sertifikasyon Merkezi, OU=Ulusal Elektronik ve Kriptoloji Araştırma Enstitüsü - UEKAE, O=Türkiye Bilimsel ve Teknolojik Araştırma Kurumu - TÜBİTAK, L=Gebze - Kocaeli, C=TR> Sha1 thumbprint: <1B4B396126276B6491A2686DD70243212D1F1D96>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Microsec e-Szigno Root CA, OU=e-Szigno CA, O=Microsec Ltd., L=Budapest, C=HU> Sha1 thumbprint: <2388C9D371CC9E963DFF7D3CA7CEFCD625EC190D>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=VeriSign Commercial Software Publishers CA, O=""VeriSign, Inc."", L=Internet> Sha1 thumbprint: <24A40A1F573643A67F0A4B0749F6A22BF28ABB6B>."
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=CA Disig, O=Disig a.s., L=Bratislava, C=SK> Sha1 thumbprint: <2AC8D58B57CEBF2F49AFF2FC768F511462907A41>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=DST ACES CA X6, OU=DST ACES, O=Digital Signature Trust, C=US> Sha1 thumbprint: <4054DA6F1C3F4074ACED0FECCDDB79D153FB901D>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <E=Info@izenpe.com, CN=Izenpe.com, L=Avda del Mediterraneo Etorbidea 3 - 01010 Vitoria-Gasteiz, O=IZENPE S.A. - CIF A-01337260-RMerc.Vitoria-Gasteiz T1055 F62 S8, C=ES> Sha1 thumbprint: <4A3F8D6BDC0E1ECFCD72E377DEF2D7FF92C19BC7>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=CA DATEV INT 01, O=DATEV eG, C=DE> Sha1 thumbprint: <52412BD67B5A6C695282386026F0B053DD400EFC>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=Cybertrust Global Root, O=""Cybertrust, Inc""> Sha1 thumbprint: <5F43E5B1BFF8788CAC1CC7CA4A9AC6222BCC34C6>."
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <O=""První certifikační autorita, a.s."", CN=I.CA - Qualified root certificate, C=CZ> Sha1 thumbprint: <64902AD7277AF3E32CD8CC1DC79DE1FD7F8069EA>."
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=UCA Root, O=UniTrust, C=CN> Sha1 thumbprint: <8250BED5A214433A66377CBC10EF83F669DA3A67>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <C=TR, O=EBG Bilişim Teknolojileri ve Hizmetleri A.Ş., CN=EBG Elektronik Sertifika Hizmet Sağlayıcısı> Sha1 thumbprint: <8C96BAEBDD2B070748EE303266A0F3986E7CAE58>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <OU=Application CA G2, O=LGPKI, C=JP> Sha1 thumbprint: <968338F113E36A7BABDD08F7776391A68736582E>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=Buypass Class 2 CA 1, O=Buypass AS-983163327, C=NO> Sha1 thumbprint: <A0A1AB90C9FC847B3B1261E8977D5FD32261D3CC>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <O=Prvni certifikacni autorita a.s., CN=I.CA - Standard root certificate, C=CZ> Sha1 thumbprint: <AB16DD144ECDC0FC4BAAB62ECF0408896FDE52B7>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=CA DATEV BT 01, O=DATEV eG, C=DE> Sha1 thumbprint: <DA8B6567EF3F6E1EA26AB146E36CCB5728041846>.
Information	4/29/2018 6:05:46 PM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <O=TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş. (c) Aralık 2007, L=Ankara, C=TR, CN=TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı> Sha1 thumbprint: <F17F6FB631DC99E3A3C87FFE1CF1811088D96033>.
Information	4/29/2018 6:01:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/29/2018 6:01:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/29/2018 6:01:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/29/2018 6:01:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/29/2018 5:03:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/29/2018 5:03:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:51Z. Reason: GVLK.
Information	4/29/2018 5:03:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/29/2018 4:58:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/29/2018 4:58:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/29/2018 4:58:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/29/2018 4:58:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/29/2018 4:58:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/29/2018 4:58:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46136)(?)])(1 )(2 )]

"
Information	4/29/2018 4:58:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46136)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/29/2018 4:58:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/29/2018 4:58:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/29/2018 4:58:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/29/2018 4:57:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3e94bb0c-4ba0-11e8-8799-204747d02364
Report Status: 0"
Warning	4/29/2018 4:56:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/29/2018 4:56:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8877.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/29/2018 4:55:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/29/2018 4:55:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:28Z. Reason: GVLK.
Information	4/29/2018 4:52:34 PM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Saturday, April 28, 2018 12:59:48 AM.
Information	4/29/2018 4:52:07 PM	RasClient	20225	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.227.106
TunnelIpv6Address = None
Dial-in User = .
Information	4/29/2018 4:52:01 PM	RasClient	20224	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/29/2018 4:52:01 PM	RasClient	20223	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/29/2018 4:52:00 PM	RasClient	20222	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/29/2018 4:51:59 PM	RasClient	20221	None	CoId={082241C4-497C-4B32-BDDD-6E32C83A9C0F}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/29/2018 4:50:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/29/2018 4:50:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/29/2018 4:50:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/29/2018 4:50:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/29/2018 4:46:48 PM	MTAService.OnSessionChange	0	None	4:46:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/29/2018 4:46:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/27/2018 5:01:04 PM	MTAService.OnSessionChange	0	None	5:01:04 PM - Session change notice received: SessionLock Session ID: 1
Information	4/27/2018 4:57:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/27/2018 4:57:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/27/2018 4:57:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/27/2018 4:44:41 PM	MTAService.OnSessionChange	0	None	4:44:41 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/27/2018 4:37:26 PM	MTAService.OnSessionChange	0	None	4:37:26 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/27/2018 4:21:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/27/2018 2:56:11 PM	MTAService.OnSessionChange	0	None	2:56:11 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/27/2018 2:38:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/27/2018 2:07:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 411890ed-49f6-11e8-8799-204747d02364
Report Status: 0"
Information	4/27/2018 1:23:12 PM	MTAService.OnSessionChange	0	None	1:23:12 PM - Session change notice received: SessionLock Session ID: 1
Information	4/27/2018 12:57:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/27/2018 12:57:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/27/2018 12:57:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/27/2018 12:52:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/27/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/27/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49267)(?)])(1 )(2 )]

"
Information	4/27/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/27/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/27/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/27/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/27/2018 12:36:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8875.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/27/2018 11:47:00 AM	MTAService.OnSessionChange	0	None	11:47:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/27/2018 11:33:54 AM	MTAService.OnSessionChange	0	None	11:33:54 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/27/2018 10:59:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/27/2018 10:53:25 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/27/2018 10:52:58 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/27/2018 10:03:35 AM	MTAService.OnSessionChange	0	None	10:03:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/27/2018 9:35:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 22013, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/27/2018 9:34:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/27/2018 9:34:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/27/2018 9:29:20 AM	MTAService.OnSessionChange	0	None	9:29:20 AM - Session change notice received: SessionLock Session ID: 1
Information	4/27/2018 9:20:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/27/2018 9:20:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:40Z. Reason: GVLK.
Error	4/27/2018 9:10:58 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/27/2018 9:10:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/27/2018 9:10:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/27/2018 9:10:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/27/2018 9:10:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/27/2018 9:07:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 571a0a1d-49cc-11e8-8799-204747d02364
Report Status: 0"
Information	4/27/2018 9:07:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/27/2018 9:07:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:26Z. Reason: GVLK.
Error	4/27/2018 9:01:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/27/2018 9:01:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/27/2018 9:01:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/27/2018 9:01:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/27/2018 9:01:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/27/2018 9:00:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	4/27/2018 8:59:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/27/2018 8:58:00 AM	MTAService.OnSessionChange	0	None	8:58:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/27/2018 8:57:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/27/2018 8:57:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/27/2018 8:57:42 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/27/2018 8:57:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/27/2018 8:57:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/26/2018 8:20:54 PM	MTAService.OnSessionChange	0	None	8:20:54 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 6:48:59 PM	MTAService.OnSessionChange	0	None	6:48:59 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/26/2018 6:43:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 6:19:43 PM	MTAService.OnSessionChange	0	None	6:19:43 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 6:04:11 PM	MTAService.OnSessionChange	0	None	6:04:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/26/2018 5:49:26 PM	MTAService.OnSessionChange	0	None	5:49:26 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 5:22:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 5:22:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:59Z. Reason: GVLK.
Information	4/26/2018 5:17:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/26/2018 5:17:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 5:17:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 5:17:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/26/2018 5:16:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 5:16:38 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/26/2018 5:16:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 5:10:14 PM	MTAService.OnSessionChange	0	None	5:10:14 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/26/2018 5:07:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 4:38:02 PM	MTAService.OnSessionChange	0	None	4:38:02 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 4:37:58 PM	MTAService.OnSessionChange	0	None	4:37:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/26/2018 4:13:39 PM	MTAService.OnSessionChange	0	None	4:13:39 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 4:09:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 4:09:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:56:11Z. Reason: GVLK.
Information	4/26/2018 4:04:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/26/2018 4:04:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 4:04:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 4:04:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/26/2018 3:57:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 615a6603-493c-11e8-8799-204747d02364
Report Status: 0"
Information	4/26/2018 3:55:58 PM	MTAService.OnSessionChange	0	None	3:55:58 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/26/2018 3:30:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 3:23:06 PM	MTAService.OnSessionChange	0	None	3:23:06 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 2:18:33 PM	MTAService.OnSessionChange	0	None	2:18:33 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/26/2018 1:44:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 1:16:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 1:16:07 PM	MTAService.OnSessionChange	0	None	1:16:07 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 1:16:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 1:15:49 PM	MTAService.OnSessionChange	0	None	1:15:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/26/2018 1:13:38 PM	MTAService.OnSessionChange	0	None	1:13:38 PM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 12:52:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50707)(?)])(1 )(2 )]

"
Information	4/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50707)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/26/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 12:47:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/26/2018 12:16:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8874.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/26/2018 12:08:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 11:49:21 AM	MTAService.OnSessionChange	0	None	11:49:21 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/26/2018 11:32:51 AM	MTAService.OnSessionChange	0	None	11:32:51 AM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 10:57:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7794a7b8-4912-11e8-8799-204747d02364
Report Status: 0"
Warning	4/26/2018 10:30:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 10:01:53 AM	MTAService.OnSessionChange	0	None	10:01:53 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/26/2018 9:21:34 AM	MTAService.OnSessionChange	0	None	9:21:34 AM - Session change notice received: SessionLock Session ID: 1
Information	4/26/2018 9:21:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 9:17:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/26/2018 9:16:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 9:16:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/26/2018 9:16:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/26/2018 9:16:11 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 905

Information	4/26/2018 9:16:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/26/2018 9:16:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/26/2018 9:15:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/26/2018 9:15:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50919)(?)])(1 )(2 )]

"
Information	4/26/2018 9:15:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50919)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 9:15:38 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/26/2018 9:15:38 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 9:15:37 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/26/2018 9:00:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	4/26/2018 8:48:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 8:44:43 AM	MTAService.OnSessionChange	0	None	8:44:43 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/26/2018 4:24:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 3:28:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 3:28:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:23Z. Reason: GVLK.
Information	4/26/2018 3:23:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/26/2018 3:23:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 3:23:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 3:23:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/26/2018 3:22:06 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/26/2018 3:22:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/26/2018 3:22:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:56:05Z. Reason: GVLK.
Error	4/26/2018 3:17:11 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/26/2018 3:17:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/26/2018 3:17:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/26/2018 3:17:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/26/2018 3:17:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/26/2018 2:36:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 2:26:31 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/26/2018 2:25:50 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/26/2018 12:57:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4943578-48be-11e8-8799-204747d02364
Report Status: 0"
Warning	4/26/2018 12:54:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/26/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/25/2018 11:03:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/25/2018 9:19:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 8:39:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 8:39:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:56:08Z. Reason: GVLK.
Information	4/25/2018 8:34:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 8:34:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 8:34:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 8:34:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 7:57:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bad6d215-4894-11e8-8799-204747d02364
Report Status: 0"
Information	4/25/2018 7:49:03 PM	MTAService.OnSessionChange	0	None	7:49:03 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/25/2018 7:30:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 7:27:29 PM	MTAService.OnSessionChange	0	None	7:27:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 7:09:08 PM	MTAService.OnSessionChange	0	None	7:09:08 PM - Session change notice received: SessionLock Session ID: 1
Information	4/25/2018 6:51:55 PM	MTAService.OnSessionChange	0	None	6:51:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 6:37:58 PM	MTAService.OnSessionChange	0	None	6:37:58 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/25/2018 5:55:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 5:41:04 PM	MTAService.OnSessionChange	0	None	5:41:04 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 5:24:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/25/2018 4:56:45 PM	MTAService.OnSessionChange	0	None	4:56:45 PM - Session change notice received: SessionLock Session ID: 1
Information	4/25/2018 4:10:25 PM	MTAService.OnSessionChange	0	None	4:10:25 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/25/2018 4:05:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 3:59:51 PM	MTAService.OnSessionChange	0	None	3:59:51 PM - Session change notice received: SessionLock Session ID: 1
Information	4/25/2018 3:47:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 3:42:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 3:42:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51972)(?)])(1 )(2 )]

"
Information	4/25/2018 3:42:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51972)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 3:42:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/25/2018 3:42:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 3:42:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 3:32:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 3:32:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:56:02Z. Reason: GVLK.
Information	4/25/2018 3:27:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 3:27:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 3:27:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 3:27:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/25/2018 3:23:48 PM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/25/2018 3:20:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 3:20:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:57Z. Reason: GVLK.
Error	4/25/2018 3:15:28 PM	SideBySide	59	None	"Activation context generation failed for ""c:\users\212558710\documents\visual studio 2015\projects\webapi_sut\webapi_sut\bin\roslyn\vbcscompiler.exe"".Error in manifest or policy file ""c:\users\212558710\documents\visual studio 2015\projects\webapi_sut\webapi_sut\bin\roslyn\vbcscompiler.exe.Config"" on line 0. Invalid Xml syntax."
Error	4/25/2018 3:14:07 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/25/2018 3:13:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 3:13:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 3:13:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 3:13:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 2:57:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d0c4aa1d-486a-11e8-8799-204747d02364
Report Status: 0"
Information	4/25/2018 2:50:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/25/2018 2:47:37 PM	Microsoft-Windows-IIS-W3SVC-PerfCounters	2001	None	It has taken too long to refresh the W3SVC counters, the stale counters are being used instead.
Information	4/25/2018 2:45:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 2:45:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52029)(?)])(1 )(2 )]

"
Information	4/25/2018 2:45:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52029)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 2:44:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 2:44:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52030)(?)])(1 )(2 )]

"
Information	4/25/2018 2:44:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52030)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 2:43:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 2:43:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52030)(?)])(1 )(2 )]

"
Information	4/25/2018 2:43:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52031)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 2:43:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/25/2018 2:43:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 2:43:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/25/2018 2:34:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 2:25:33 PM	MTAService.OnSessionChange	0	None	2:25:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 2:00:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 2:00:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:35Z. Reason: GVLK.
Information	4/25/2018 1:55:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 1:55:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 1:55:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 1:55:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 1:31:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 1:31:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T07:55:13Z. Reason: GVLK.
Information	4/25/2018 1:26:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 1:26:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 1:26:12 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/04/25 07:56"
Information	4/25/2018 1:26:10 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/04/25 07:56, 0, 1, 249000, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/25/2018 1:25:15 PM	MTAService.OnSessionChange	0	None	1:25:15 PM - Session change notice received: SessionLock Session ID: 1
Information	4/25/2018 1:24:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/25/2018 1:21:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 1:21:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 1:21:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 1:21:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/25/2018 12:52:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 12:48:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8873.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/25/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52147)(?)])(1 )(2 )]

"
Information	4/25/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52147)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/25/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 12:40:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 12:34:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/25/2018 12:34:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52160)(?)])(1 )(2 )]

"
Information	4/25/2018 12:34:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52160)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 12:34:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/25/2018 12:34:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 12:34:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 12:26:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎25T06:55:11.919063100Z.
Information	4/25/2018 12:26:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	4/25/2018 12:26:33 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9146. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	4/25/2018 12:26:33 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	4/25/2018 12:25:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎25T06:55:11.919063100Z.
Information	4/25/2018 12:24:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 15848.
Information	4/25/2018 11:57:30 AM	MTAService.OnSessionChange	0	None	11:57:30 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 11:49:47 AM	MTAService.OnSessionChange	0	None	11:49:47 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/25/2018 11:04:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 11:02:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 11:02:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-05-02T05:26:28Z. Reason: GVLK.
Information	4/25/2018 10:59:10 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9146. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	4/25/2018 10:59:10 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	4/25/2018 10:59:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎25T05:23:25.528479100Z.
Information	4/25/2018 10:59:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F30DADF6-F218-49A3-8501-07CB39BF6255}\4Sight™ 2.msi. Client Process Id: 16724.
Information	4/25/2018 10:57:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 10:57:27 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	4/25/2018 10:57:27 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/04/25 05:27, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/25/2018 10:53:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎25T05:23:25.528479100Z.
Information	4/25/2018 10:53:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F30DADF6-F218-49A3-8501-07CB39BF6255}\4Sight™ 2.msi. Client Process Id: 16724.
Information	4/25/2018 10:52:46 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/25/2018 10:52:46 AM	PostgreSQL	0	None	"2018-04-25 10:52:46 IST LOG:  redirecting log output to logging collector process
2018-04-25 10:52:46 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/25/2018 10:52:45 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/25/2018 10:52:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 10:52:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 10:52:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 10:51:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 10:48:14 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎04‎-‎25T05:18:14.438882900Z.
Information	4/25/2018 10:48:14 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎04‎-‎25T05:18:14.438882900Z.
Information	4/25/2018 10:38:35 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.3.0.9146. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	4/25/2018 10:38:35 AM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	4/25/2018 10:21:48 AM	MTAService.OnSessionChange	0	None	10:21:48 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/25/2018 9:57:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e6f47b08-4840-11e8-8799-204747d02364
Report Status: 0"
Information	4/25/2018 9:39:47 AM	MTAService.OnSessionChange	0	None	9:39:47 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/25/2018 9:26:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 9:24:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/25/2018 9:17:01 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/25/2018 9:16:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/25/2018 9:16:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/25/2018 9:16:27 AM	MTAService.OnSessionChange	0	None	9:16:27 AM - Session change notice received: SessionUnlock Session ID: 1
Error	4/25/2018 9:00:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/25/2018 9:00:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	4/25/2018 7:43:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/25/2018 6:09:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 5:24:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/25/2018 4:57:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fd1526b5-4816-11e8-8799-204747d02364
Report Status: 0"
Information	4/25/2018 4:41:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 4:41:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:53Z. Reason: GVLK.
Information	4/25/2018 4:36:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 4:36:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 4:36:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 4:36:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/25/2018 4:35:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/25/2018 4:35:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:47Z. Reason: GVLK.
Error	4/25/2018 4:35:36 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	4/25/2018 4:30:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/25/2018 4:30:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/25/2018 4:30:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/25/2018 4:30:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/25/2018 4:30:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/25/2018 4:25:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/25/2018 2:33:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 1:59:04 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/25/2018 1:58:30 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/25/2018 1:24:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/25/2018 12:51:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/25/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/24/2018 11:57:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 134f6f1a-47ed-11e8-8799-204747d02364
Report Status: 0"
Warning	4/24/2018 10:58:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 10:29:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 10:29:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:35Z. Reason: GVLK.
Information	4/24/2018 10:24:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/24/2018 10:24:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 10:24:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 10:24:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 9:23:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/24/2018 9:22:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 8:47:25 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/24/2018 8:46:41 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/24/2018 8:13:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/24/2018 7:41:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 7:33:30 PM	MTAService.OnSessionChange	0	None	7:33:30 PM - Session change notice received: SessionLock Session ID: 1
Information	4/24/2018 7:18:49 PM	MTAService.OnSessionChange	0	None	7:18:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 7:17:11 PM	MTAService.OnSessionChange	0	None	7:17:11 PM - Session change notice received: SessionLock Session ID: 1
Information	4/24/2018 6:56:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2971922b-47c3-11e8-8799-204747d02364
Report Status: 0"
Information	4/24/2018 6:21:45 PM	MTAService.OnSessionChange	0	None	6:21:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 6:08:15 PM	MTAService.OnSessionChange	0	None	6:08:15 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/24/2018 5:53:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 5:49:15 PM	MTAService.OnSessionChange	0	None	5:49:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 5:23:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/24/2018 5:17:16 PM	MTAService.OnSessionChange	0	None	5:17:16 PM - Session change notice received: SessionLock Session ID: 1
Information	4/24/2018 5:13:42 PM	MTAService.OnSessionChange	0	None	5:13:42 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 5:03:55 PM	MTAService.OnSessionChange	0	None	5:03:55 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/24/2018 4:22:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/24/2018 2:48:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 2:22:55 PM	MTAService.OnSessionChange	0	None	2:22:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 1:56:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3f9b55b5-4799-11e8-8799-204747d02364
Report Status: 0"
Information	4/24/2018 1:23:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/24/2018 1:12:11 PM	MTAService.OnSessionChange	0	None	1:12:11 PM - Session change notice received: SessionLock Session ID: 1
Information	4/24/2018 12:52:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/24/2018 12:50:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/24/2018 12:47:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53587)(?)])(1 )(2 )]

"
Information	4/24/2018 12:47:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53587)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 12:47:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/24/2018 12:47:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 12:47:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 11:56:44 AM	MTAService.OnSessionChange	0	None	11:56:44 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 11:32:39 AM	MTAService.OnSessionChange	0	None	11:32:39 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/24/2018 11:03:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 10:46:30 AM	MTAService.OnSessionChange	0	None	10:46:30 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/24/2018 10:10:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 10:10:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:04Z. Reason: GVLK.
Information	4/24/2018 10:05:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/24/2018 10:05:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 10:05:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 10:05:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/24/2018 10:02:56 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	4/24/2018 9:54:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 9:53:13 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8872.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/24/2018 9:37:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:07:51.191415300Z.
Information	4/24/2018 9:37:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}. Client Process Id: 12412.
Information	4/24/2018 9:37:53 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:37:53 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005 -- Removal completed successfully.
Information	4/24/2018 9:37:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:07:51.191415300Z.
Information	4/24/2018 9:37:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:07:48.021098300Z.
Information	4/24/2018 9:37:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}. Client Process Id: 12412.
Information	4/24/2018 9:37:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C596D608-3E74-3232-8CA5-DF1DCB9F10DE}. Client Process Id: 12412.
Information	4/24/2018 9:37:51 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:37:51 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005 -- Removal completed successfully.
Information	4/24/2018 9:37:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:07:48.021098300Z.
Information	4/24/2018 9:37:47 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:07:31.029399300Z.
Information	4/24/2018 9:37:47 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C596D608-3E74-3232-8CA5-DF1DCB9F10DE}. Client Process Id: 12412.
Information	4/24/2018 9:37:47 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B255880F-8C5E-4FAF-8F9C-7DBA635B2615}. Client Process Id: 12412.
Information	4/24/2018 9:37:47 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Build Tools - x86. Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:37:47 AM	MsiInstaller	11724	None	Product: Build Tools - x86 -- Removal completed successfully.
Information	4/24/2018 9:37:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:07:31.029399300Z.
Information	4/24/2018 9:37:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:07:20.759372400Z.
Information	4/24/2018 9:37:30 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B255880F-8C5E-4FAF-8F9C-7DBA635B2615}. Client Process Id: 12412.
Information	4/24/2018 9:37:30 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CC1F74DF-058F-406C-BC7D-F14D6E5F7CBD}. Client Process Id: 12412.
Information	4/24/2018 9:37:30 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Build Tools - amd64. Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:37:30 AM	MsiInstaller	11724	None	Product: Build Tools - amd64 -- Removal completed successfully.
Information	4/24/2018 9:37:20 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:07:20.759372400Z.
Information	4/24/2018 9:37:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:06:20.469344000Z.
Information	4/24/2018 9:37:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CC1F74DF-058F-406C-BC7D-F14D6E5F7CBD}. Client Process Id: 12412.
Information	4/24/2018 9:37:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D37FDF2F-8766-4BDF-A0E3-A60BDBB630ED}. Client Process Id: 12412.
Information	4/24/2018 9:37:20 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Build Tools Language Resources - x86. Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:37:20 AM	MsiInstaller	11724	None	Product: Build Tools Language Resources - x86 -- Removal completed successfully.
Information	4/24/2018 9:37:01 AM	MTAService.OnSessionChange	0	None	9:37:01 AM - Session change notice received: SessionLock Session ID: 1
Information	4/24/2018 9:36:20 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:06:20.469344000Z.
Information	4/24/2018 9:36:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:50.089306300Z.
Information	4/24/2018 9:36:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D37FDF2F-8766-4BDF-A0E3-A60BDBB630ED}. Client Process Id: 12412.
Information	4/24/2018 9:36:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E43BBAEB-4914-44C6-88C0-E7A1DBD20A91}. Client Process Id: 12412.
Information	4/24/2018 9:36:20 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Build Tools Language Resources - amd64. Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:36:20 AM	MsiInstaller	11724	None	Product: Build Tools Language Resources - amd64 -- Removal completed successfully.
Information	4/24/2018 9:35:50 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:50.089306300Z.
Information	4/24/2018 9:35:50 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:46.758973300Z.
Information	4/24/2018 9:35:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E43BBAEB-4914-44C6-88C0-E7A1DBD20A91}. Client Process Id: 12412.
Information	4/24/2018 9:35:50 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {0B6BDD27-3097-4FE1-BDE6-1D5EC7399563}. Client Process Id: 12412.
Information	4/24/2018 9:35:50 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual Studio 2013 Prerequisites. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:50 AM	MsiInstaller	11724	None	Product: Visual Studio 2013 Prerequisites -- Removal completed successfully.
Information	4/24/2018 9:35:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:46.758973300Z.
Information	4/24/2018 9:35:46 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:43.033600800Z.
Information	4/24/2018 9:35:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {0B6BDD27-3097-4FE1-BDE6-1D5EC7399563}. Client Process Id: 12412.
Information	4/24/2018 9:35:46 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {16222DF7-8513-491E-91F0-F489AB2D3CB0}. Client Process Id: 12412.
Information	4/24/2018 9:35:46 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual Studio 2013 Prerequisites - ENU Language Pack. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:46 AM	MsiInstaller	11724	None	Product: Visual Studio 2013 Prerequisites - ENU Language Pack -- Removal completed successfully.
Information	4/24/2018 9:35:43 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:43.033600800Z.
Information	4/24/2018 9:35:42 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:33.589656500Z.
Information	4/24/2018 9:35:42 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {16222DF7-8513-491E-91F0-F489AB2D3CB0}. Client Process Id: 12412.
Information	4/24/2018 9:35:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {678800C0-D94E-4513-89CB-478F2B781A0B}. Client Process Id: 12412.
Information	4/24/2018 9:35:42 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 x86-x64 Compilers. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:42 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 x86-x64 Compilers -- Removal completed successfully.
Information	4/24/2018 9:35:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:33.589656500Z.
Information	4/24/2018 9:35:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:30.037338800Z.
Information	4/24/2018 9:35:33 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {678800C0-D94E-4513-89CB-478F2B781A0B}. Client Process Id: 12412.
Information	4/24/2018 9:35:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6C06FEE9-C64E-453F-B8A5-D9E9B79ED040}. Client Process Id: 12412.
Information	4/24/2018 9:35:33 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 32bit Compilers - ENU Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:33 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 32bit Compilers - ENU Resources -- Removal completed successfully.
Information	4/24/2018 9:35:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:30.037338800Z.
Information	4/24/2018 9:35:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:27.032338800Z.
Information	4/24/2018 9:35:29 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6C06FEE9-C64E-453F-B8A5-D9E9B79ED040}. Client Process Id: 12412.
Information	4/24/2018 9:35:29 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DB5600F1-DE83-46DE-B162-5FC4400EAF5B}. Client Process Id: 12412.
Information	4/24/2018 9:35:29 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 Compilers. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:29 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 Compilers -- Removal completed successfully.
Information	4/24/2018 9:35:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:27.032338800Z.
Information	4/24/2018 9:35:26 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:25.613338800Z.
Information	4/24/2018 9:35:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:25.613338800Z.
Information	4/24/2018 9:35:25 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:22.974338800Z.
Information	4/24/2018 9:35:26 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DB5600F1-DE83-46DE-B162-5FC4400EAF5B}. Client Process Id: 12412.
Information	4/24/2018 9:35:26 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E6F3851E-CEEB-4ECB-A6FA-337C8F662E3D}. Client Process Id: 12412.
Information	4/24/2018 9:35:26 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 Compilers - ENU Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:26 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 Compilers - ENU Resources -- Removal completed successfully.
Information	4/24/2018 9:35:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E6F3851E-CEEB-4ECB-A6FA-337C8F662E3D}. Client Process Id: 12412.
Information	4/24/2018 9:35:25 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DE0E8FAF-9758-4BFD-A16E-009DB4B8C912}. Client Process Id: 12412.
Information	4/24/2018 9:35:25 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64 Native Compilers. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:25 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64 Native Compilers -- Removal completed successfully.
Information	4/24/2018 9:35:22 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:22.974338800Z.
Information	4/24/2018 9:35:22 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:20.402338800Z.
Information	4/24/2018 9:35:22 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DE0E8FAF-9758-4BFD-A16E-009DB4B8C912}. Client Process Id: 12412.
Information	4/24/2018 9:35:22 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BB0D9EE5-F7B1-4986-AF62-DB3BED9A83BC}. Client Process Id: 12412.
Information	4/24/2018 9:35:22 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64 Native Compilers - ENU Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:22 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64 Native Compilers - ENU Resources -- Removal completed successfully.
Information	4/24/2018 9:35:20 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:20.402338800Z.
Information	4/24/2018 9:35:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:18.029338800Z.
Information	4/24/2018 9:35:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BB0D9EE5-F7B1-4986-AF62-DB3BED9A83BC}. Client Process Id: 12412.
Information	4/24/2018 9:35:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C1D0E508-ECAF-45AA-A549-1E26B9ECE0FB}. Client Process Id: 12412.
Information	4/24/2018 9:35:20 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64-x86 Cross Compilers. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:20 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64-x86 Cross Compilers -- Removal completed successfully.
Information	4/24/2018 9:35:18 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:18.029338800Z.
Information	4/24/2018 9:35:17 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:15.471338800Z.
Information	4/24/2018 9:35:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C1D0E508-ECAF-45AA-A549-1E26B9ECE0FB}. Client Process Id: 12412.
Information	4/24/2018 9:35:17 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {96563105-F726-4865-8C32-416753ECA5F1}. Client Process Id: 12412.
Information	4/24/2018 9:35:17 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64-x86 Cross Compilers - ENU Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:17 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64-x86 Cross Compilers - ENU Resources -- Removal completed successfully.
Information	4/24/2018 9:35:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:15.471338800Z.
Information	4/24/2018 9:35:15 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:12.533338800Z.
Information	4/24/2018 9:35:15 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {96563105-F726-4865-8C32-416753ECA5F1}. Client Process Id: 12412.
Information	4/24/2018 9:35:15 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {30F2491C-9410-4DB1-BE66-77B360B1F484}. Client Process Id: 12412.
Information	4/24/2018 9:35:15 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64-arm Cross Compilers. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:15 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64-arm Cross Compilers -- Removal completed successfully.
Information	4/24/2018 9:35:12 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:12.533338800Z.
Information	4/24/2018 9:35:12 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:05:10.740338800Z.
Information	4/24/2018 9:35:12 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {30F2491C-9410-4DB1-BE66-77B360B1F484}. Client Process Id: 12412.
Information	4/24/2018 9:35:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B3C98C29-A2BE-455F-9285-13B745282271}. Client Process Id: 12412.
Information	4/24/2018 9:35:12 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64-arm Cross Compilers - ENU Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:12 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64-arm Cross Compilers - ENU Resources -- Removal completed successfully.
Information	4/24/2018 9:35:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:05:10.740338800Z.
Information	4/24/2018 9:35:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:45.316338800Z.
Information	4/24/2018 9:35:10 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B3C98C29-A2BE-455F-9285-13B745282271}. Client Process Id: 12412.
Information	4/24/2018 9:35:10 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {84D88F57-4130-30FE-A0B6-1E04428FE1F6}. Client Process Id: 12412.
Information	4/24/2018 9:35:10 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 Core Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:35:10 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 Core Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:45.316338800Z.
Information	4/24/2018 9:34:45 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:40.846338800Z.
Information	4/24/2018 9:34:45 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {84D88F57-4130-30FE-A0B6-1E04428FE1F6}. Client Process Id: 12412.
Information	4/24/2018 9:34:45 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D42681AA-BC16-3C84-949E-45F05D2AA997}. Client Process Id: 12412.
Information	4/24/2018 9:34:45 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 Core Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:45 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 Core Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:40 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:40.846338800Z.
Information	4/24/2018 9:34:40 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:38.085338800Z.
Information	4/24/2018 9:34:40 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D42681AA-BC16-3C84-949E-45F05D2AA997}. Client Process Id: 12412.
Information	4/24/2018 9:34:40 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4781443E-204D-4D98-8899-18A123C13B1E}. Client Process Id: 12412.
Information	4/24/2018 9:34:40 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft C++ REST SDK for Visual Studio 2013. Product Version: 1.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:40 AM	MsiInstaller	11724	None	Product: Microsoft C++ REST SDK for Visual Studio 2013 -- Removal completed successfully.
Information	4/24/2018 9:34:38 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:38.085338800Z.
Information	4/24/2018 9:34:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:35.900338800Z.
Information	4/24/2018 9:34:38 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4781443E-204D-4D98-8899-18A123C13B1E}. Client Process Id: 12412.
Information	4/24/2018 9:34:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A3B8D9FB-CA7D-4487-8CA2-A6A2C8AD1077}. Client Process Id: 12412.
Information	4/24/2018 9:34:37 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x86 Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:37 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x86 Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:35 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:35.900338800Z.
Information	4/24/2018 9:34:35 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:33.977338800Z.
Information	4/24/2018 9:34:35 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A3B8D9FB-CA7D-4487-8CA2-A6A2C8AD1077}. Client Process Id: 12412.
Information	4/24/2018 9:34:35 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {0B698858-DAB0-4F9E-A10A-125B274EDA06}. Client Process Id: 12412.
Information	4/24/2018 9:34:35 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  x64 Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:35 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  x64 Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:33.977338800Z.
Information	4/24/2018 9:34:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:31.380338800Z.
Information	4/24/2018 9:34:33 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {0B698858-DAB0-4F9E-A10A-125B274EDA06}. Client Process Id: 12412.
Information	4/24/2018 9:34:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A8229A09-E570-412B-8D18-E78985673E34}. Client Process Id: 12412.
Information	4/24/2018 9:34:33 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++  ARM Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:33 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++  ARM Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:31.380338800Z.
Information	4/24/2018 9:34:31 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:04:28.144338800Z.
Information	4/24/2018 9:34:31 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A8229A09-E570-412B-8D18-E78985673E34}. Client Process Id: 12412.
Information	4/24/2018 9:34:31 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A1D06677-1103-32DE-AA74-6EE44DCF7F81}. Client Process Id: 12412.
Information	4/24/2018 9:34:31 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual C++ 2013 Extended Libraries. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:31 AM	MsiInstaller	11724	None	Product: Microsoft Visual C++ 2013 Extended Libraries -- Removal completed successfully.
Information	4/24/2018 9:34:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:04:28.144338800Z.
Information	4/24/2018 9:34:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:01:34.074338800Z.
Information	4/24/2018 9:34:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A1D06677-1103-32DE-AA74-6EE44DCF7F81}. Client Process Id: 12412.
Information	4/24/2018 9:34:28 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {F361FE04-789E-42F3-BBAB-E7B380AA5E06}. Client Process Id: 12412.
Information	4/24/2018 9:34:28 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows XP Targeting with C++. Product Version: 11.0.51106. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:34:28 AM	MsiInstaller	11724	None	Product: Windows XP Targeting with C++ -- Removal completed successfully.
Information	4/24/2018 9:33:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 5, Deleted: 0, Modified: 3, Compared: 21131, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/24/2018 9:31:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:01:34.074338800Z.
Information	4/24/2018 9:31:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:01:28.671338800Z.
Information	4/24/2018 9:31:33 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {F361FE04-789E-42F3-BBAB-E7B380AA5E06}. Client Process Id: 12412.
Information	4/24/2018 9:31:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {993F6DDC-63F8-4BCD-9B28-D941971A9CAC}. Client Process Id: 12412.
Information	4/24/2018 9:31:33 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows XP Targeting with C++. Product Version: 11.0.51106. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:31:33 AM	MsiInstaller	11724	None	Product: Windows XP Targeting with C++ -- Removal completed successfully.
Information	4/24/2018 9:31:28 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:01:28.671338800Z.
Information	4/24/2018 9:31:28 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:00:19.935338800Z.
Information	4/24/2018 9:31:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {993F6DDC-63F8-4BCD-9B28-D941971A9CAC}. Client Process Id: 12412.
Information	4/24/2018 9:31:28 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C0DE47ED-AFAF-3B17-8268-D5BFDEC404A8}. Client Process Id: 12412.
Information	4/24/2018 9:31:28 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Team Foundation Server 2013 Update 4 Object Model (x64). Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:31:28 AM	MsiInstaller	11724	None	Product: Microsoft Team Foundation Server 2013 Update 4 Object Model (x64) -- Removal completed successfully.
Error	4/24/2018 9:30:59 AM	SideBySide	63	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/24/2018 9:30:19 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:00:19.935338800Z.
Information	4/24/2018 9:30:18 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:00:11.946338800Z.
Information	4/24/2018 9:30:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C0DE47ED-AFAF-3B17-8268-D5BFDEC404A8}. Client Process Id: 12412.
Information	4/24/2018 9:30:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {33B4C199-3463-30E8-B3D2-A0793DAC3607}. Client Process Id: 12412.
Information	4/24/2018 9:30:18 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Team Foundation Server 2013 Update 4 Object Model Language Pack (x64) - ENU. Product Version: 12.0.31101. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:30:18 AM	MsiInstaller	11724	None	Product: Microsoft Team Foundation Server 2013 Update 4 Object Model Language Pack (x64) - ENU -- Removal completed successfully.
Information	4/24/2018 9:30:11 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:00:11.946338800Z.
Information	4/24/2018 9:30:11 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:00:05.370338800Z.
Information	4/24/2018 9:30:11 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {33B4C199-3463-30E8-B3D2-A0793DAC3607}. Client Process Id: 12412.
Information	4/24/2018 9:30:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {976C3D92-0DEC-37A6-A870-FF4FC18CD029}. Client Process Id: 12412.
Information	4/24/2018 9:30:11 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps. Product Version: 4.5.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:30:11 AM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps -- Removal completed successfully.
Information	4/24/2018 9:30:05 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:00:05.370338800Z.
Information	4/24/2018 9:30:05 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T04:00:00.701338800Z.
Information	4/24/2018 9:30:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {976C3D92-0DEC-37A6-A870-FF4FC18CD029}. Client Process Id: 12412.
Information	4/24/2018 9:30:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A223B446-EC3D-3031-828D-5188800AB782}. Client Process Id: 12412.
Information	4/24/2018 9:30:05 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps (ENU). Product Version: 4.5.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:30:05 AM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps (ENU) -- Removal completed successfully.
Information	4/24/2018 9:30:00 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T04:00:00.701338800Z.
Information	4/24/2018 9:30:00 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:58:53.741338800Z.
Information	4/24/2018 9:30:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A223B446-EC3D-3031-828D-5188800AB782}. Client Process Id: 12412.
Information	4/24/2018 9:30:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5411060C-8F8C-393D-8D3B-26AF2C92FABB}. Client Process Id: 12412.
Information	4/24/2018 9:30:00 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 Shell (Minimum). Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:30:00 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 Shell (Minimum) -- Removal completed successfully.
Information	4/24/2018 9:29:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 9:28:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:58:53.741338800Z.
Information	4/24/2018 9:28:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:58:34.792338800Z.
Information	4/24/2018 9:28:53 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5411060C-8F8C-393D-8D3B-26AF2C92FABB}. Client Process Id: 12412.
Information	4/24/2018 9:28:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AE937DBA-FEFD-3BFE-9860-0591C0F91D61}. Client Process Id: 12412.
Information	4/24/2018 9:28:53 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 Shell (Minimum) Interop Assemblies. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:28:53 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 Shell (Minimum) Interop Assemblies -- Removal completed successfully.
Information	4/24/2018 9:28:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:58:34.792338800Z.
Information	4/24/2018 9:28:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:58:29.324338800Z.
Information	4/24/2018 9:28:34 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AE937DBA-FEFD-3BFE-9860-0591C0F91D61}. Client Process Id: 12412.
Information	4/24/2018 9:28:34 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B6A0A174-33E0-3D42-92EA-547D318CB149}. Client Process Id: 12412.
Information	4/24/2018 9:28:34 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 Devenv. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:28:34 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 Devenv -- Removal completed successfully.
Information	4/24/2018 9:28:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:58:29.324338800Z.
Information	4/24/2018 9:28:29 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:58:21.407338800Z.
Information	4/24/2018 9:28:29 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B6A0A174-33E0-3D42-92EA-547D318CB149}. Client Process Id: 12412.
Information	4/24/2018 9:28:29 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {985EF141-95DD-3934-8F23-7C2C4C61E5F7}. Client Process Id: 12412.
Information	4/24/2018 9:28:29 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 Shell (Minimum) Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:28:29 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 Shell (Minimum) Resources -- Removal completed successfully.
Information	4/24/2018 9:28:21 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:58:21.407338800Z.
Information	4/24/2018 9:28:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:58:17.172338800Z.
Information	4/24/2018 9:28:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {985EF141-95DD-3934-8F23-7C2C4C61E5F7}. Client Process Id: 12412.
Information	4/24/2018 9:28:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C26C1495-8EBE-3F71-BDA1-7DE2010840D8}. Client Process Id: 12412.
Information	4/24/2018 9:28:20 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 Devenv Resources. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:28:20 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 Devenv Resources -- Removal completed successfully.
Information	4/24/2018 9:28:17 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:58:17.172338800Z.
Information	4/24/2018 9:28:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:57:47.273338800Z.
Information	4/24/2018 9:28:16 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C26C1495-8EBE-3F71-BDA1-7DE2010840D8}. Client Process Id: 12412.
Information	4/24/2018 9:28:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C11CD3FC-F7A0-3A92-8B38-02D5E6C79FAE}. Client Process Id: 12412.
Information	4/24/2018 9:28:16 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Portable Library Multi-Targeting Pack. Product Version: 14.0.23107.00. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:28:16 AM	MsiInstaller	11724	None	Product: Microsoft Portable Library Multi-Targeting Pack -- Removal completed successfully.
Information	4/24/2018 9:27:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:57:47.273338800Z.
Information	4/24/2018 9:27:46 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:57:15.448338800Z.
Information	4/24/2018 9:27:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C11CD3FC-F7A0-3A92-8B38-02D5E6C79FAE}. Client Process Id: 12412.
Information	4/24/2018 9:27:46 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {EC04E080-8898-35F1-90C7-E5965C68A0DC}. Client Process Id: 12412.
Information	4/24/2018 9:27:46 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Portable Library Multi-Targeting Pack Language Pack - enu. Product Version: 14.0.23107.00. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:27:46 AM	MsiInstaller	11724	None	Product: Microsoft Portable Library Multi-Targeting Pack Language Pack - enu -- Removal completed successfully.
Information	4/24/2018 9:27:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:57:15.448338800Z.
Information	4/24/2018 9:27:13 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:56:51.394338800Z.
Information	4/24/2018 9:27:14 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {EC04E080-8898-35F1-90C7-E5965C68A0DC}. Client Process Id: 12412.
Information	4/24/2018 9:27:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6321F2D4-366B-3AE4-877A-8E539EC3331A}. Client Process Id: 12412.
Information	4/24/2018 9:27:13 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual F# 3.1 VS. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:27:13 AM	MsiInstaller	11724	None	Product: Visual F# 3.1 VS -- Removal completed successfully.
Information	4/24/2018 9:26:51 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:56:51.394338800Z.
Information	4/24/2018 9:26:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:56:19.140338800Z.
Information	4/24/2018 9:26:49 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6321F2D4-366B-3AE4-877A-8E539EC3331A}. Client Process Id: 12412.
Information	4/24/2018 9:26:49 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {06EEE072-B561-38E5-85D9-485ABCBE8342}. Client Process Id: 12412.
Information	4/24/2018 9:26:49 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual F# 3.1 SDK. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:26:49 AM	MsiInstaller	11724	None	Product: Visual F# 3.1 SDK -- Removal completed successfully.
Information	4/24/2018 9:26:19 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:56:19.140338800Z.
Information	4/24/2018 9:26:18 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:56:05.477338800Z.
Information	4/24/2018 9:26:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {06EEE072-B561-38E5-85D9-485ABCBE8342}. Client Process Id: 12412.
Information	4/24/2018 9:26:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {F17662A3-4569-4A61-ABD4-E51B632D3C4D}. Client Process Id: 12412.
Information	4/24/2018 9:26:18 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2013 VsGraphics Helper Dependencies. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:26:18 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2013 VsGraphics Helper Dependencies -- Removal completed successfully.
Information	4/24/2018 9:26:05 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:56:05.477338800Z.
Information	4/24/2018 9:26:04 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎04‎-‎24T03:50:19.353042000Z.
Information	4/24/2018 9:26:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {F17662A3-4569-4A61-ABD4-E51B632D3C4D}. Client Process Id: 12412.
Information	4/24/2018 9:26:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9C593464-7F2F-37B3-89F8-7E894E3B09EA}. Client Process Id: 12412.
Information	4/24/2018 9:26:04 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Professional 2013. Product Version: 12.0.21005. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	4/24/2018 9:26:04 AM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Professional 2013 -- Removal completed successfully.
Information	4/24/2018 9:24:38 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/24/2018 9:24:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2242.
Information	4/24/2018 9:24:27 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 218

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 187

Information	4/24/2018 9:23:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/24/2018 9:23:23 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	4/24/2018 9:23:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/24/2018 9:23:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53791)(?)])(1 )(2 )]

"
Information	4/24/2018 9:23:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53791)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 9:23:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/24/2018 9:23:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 9:23:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 9:20:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 9:20:19 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎04‎-‎24T03:50:19.353042000Z.
Information	4/24/2018 9:20:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9C593464-7F2F-37B3-89F8-7E894E3B09EA}. Client Process Id: 12412.
Error	4/24/2018 9:18:55 AM	SideBySide	33	None	"Activation context generation failed for ""c:\program files (x86)\microsoft office\root\office16\odbc drivers\salesforce\lib\libcurl32.dlla\libcurl.dll"". Dependent Assembly OpenSSL.DllA,processorArchitecture=""&#x2a;"",type=""win32"",version=""1.0.0.4"" could not be found. Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 9:15:58 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:58 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8431.2242. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	4/24/2018 9:15:58 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	4/24/2018 9:15:57 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/24/2018 9:15:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53799)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 9:15:54 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	4/24/2018 9:15:54 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/24/2018 9:15:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 9:15:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/24/2018 9:15:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 9:15:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 9:15:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 9:15:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:27 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:27 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2242. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	4/24/2018 9:15:27 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	4/24/2018 9:15:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:25 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:25 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2242. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	4/24/2018 9:15:25 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	4/24/2018 9:15:18 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/24/2018 9:15:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:18 AM	ESENT	102	General	Windows (13052) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/24/2018 9:15:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:18 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2242. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	4/24/2018 9:15:18 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	4/24/2018 9:15:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:02 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	4/24/2018 9:15:02 AM	ESENT	103	General	Windows (9816) Windows: The database engine stopped the instance (0).
Information	4/24/2018 9:15:02 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:15:02 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2242. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	4/24/2018 9:15:02 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	4/24/2018 9:13:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1536.
Information	4/24/2018 9:12:30 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/24/2018 9:12:29 AM	ESENT	102	General	Windows (9816) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/24/2018 9:12:25 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	4/24/2018 9:12:24 AM	ESENT	103	General	Windows (4688) Windows: The database engine stopped the instance (0).
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:22 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:21 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:19 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:19 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	4/24/2018 9:12:19 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:19 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:19 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	4/24/2018 9:12:05 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	4/24/2018 9:11:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 9:11:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/24/2018 9:11:32 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/24/2018 9:11:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53803)(?)])(1 )(2 )]

"
Information	4/24/2018 9:11:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53803)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 9:11:32 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	4/24/2018 9:11:32 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/24/2018 9:11:03 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	4/24/2018 9:11:03 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Skype for Business'.
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	4/24/2018 9:11:02 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	4/24/2018 9:11:01 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	4/24/2018 9:11:00 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	4/24/2018 9:10:59 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	4/24/2018 9:10:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/24/2018 9:10:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 9:10:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/24/2018 9:10:52 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 9:10:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 9:10:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:44Z. Reason: GVLK.
Information	4/24/2018 9:10:06 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Error	4/24/2018 9:09:57 AM	SideBySide	35	None	"Activation context generation failed for ""c:\program files (x86)\microsoft office\root\office16\lync.exe.Manifest"".Error in manifest or policy file ""c:\program files (x86)\microsoft office\root\office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 9:05:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/24/2018 9:05:14 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Information	4/24/2018 9:05:14 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Error	4/24/2018 9:05:12 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	4/24/2018 9:05:12 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	4/24/2018 9:05:12 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	4/24/2018 9:04:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎04‎-‎24T03:34:36.153909300Z.
Warning	4/24/2018 9:03:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/24/2018 9:00:12 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	4/24/2018 9:00:10 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	4/24/2018 8:59:30 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/24/2018 8:59:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/24/2018 8:59:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/24/2018 8:59:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53815)(?)])(1 )(2 )]

"
Information	4/24/2018 8:59:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53815)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 8:59:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/24/2018 8:59:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 8:59:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 8:57:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/24/2018 8:57:20 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/24/2018 8:57:19 AM	MTAService.OnSessionChange	0	None	8:57:19 AM - Logon : 212558710
Information	4/24/2018 8:57:19 AM	MTAService.OnSessionChange	0	None	8:57:19 AM - Session change notice received: SessionLogon Session ID: 1
Information	4/24/2018 8:57:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/24/2018 8:57:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/24/2018 8:57:16 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/24/2018 8:56:53 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/24/2018 8:56:52 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/24/2018 8:56:51 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/24/2018 8:56:44 AM	MTAService.OnSessionChange	0	None	8:56:44 AM - Session change notice received: ConsoleConnect Session ID: 1
Warning	4/24/2018 8:56:42 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 96 second(s) to handle the notification event (CreateSession).
Warning	4/24/2018 8:56:05 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	4/24/2018 8:55:47 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/24/2018 8:55:36 AM	ESENT	302	Logging/Recovery	Windows (4688) Windows: The database engine has successfully completed recovery steps.
Information	4/24/2018 8:55:31 AM	ESENT	301	Logging/Recovery	Windows (4688) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/24/2018 8:55:20 AM	ESENT	301	Logging/Recovery	Windows (4688) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00656.log.
Information	4/24/2018 8:55:20 AM	ESENT	300	Logging/Recovery	Windows (4688) Windows: The database engine is initiating recovery steps.
Information	4/24/2018 8:55:20 AM	ESENT	102	General	Windows (4688) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/24/2018 8:55:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/24/2018 8:55:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/24/2018 8:55:05 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	4/24/2018 8:55:04 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	4/24/2018 8:55:04 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	4/24/2018 8:55:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/24/2018 8:54:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/24/2018 8:54:50 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8871.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/24/2018 8:54:10 AM	Service1	0	None	Service started successfully.
Error	4/24/2018 8:53:58 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/24/2018 8:53:58 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/24/2018 8:53:35 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/24/2018 8:53:30 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/24/2018 8:53:29 AM	PostgreSQL	0	None	"2018-04-24 08:53:29 IST LOG:  redirecting log output to logging collector process
2018-04-24 08:53:29 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/24/2018 8:53:27 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:27 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/24/2018 8:53:27 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/24/2018 8:53:27 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/24/2018 8:53:27 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/24/2018 8:53:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/24/2018 8:53:26 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/24/2018 8:53:26 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:25 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/24/2018 8:53:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/24/2018 8:53:23 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:23 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/24/2018 8:53:23 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/24/2018 8:53:20 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/24/2018 8:53:20 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/24/2018 8:53:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/24/2018 8:53:18 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/24/2018 8:53:16 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:16 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:16 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/24/2018 8:53:15 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/24/2018 8:53:15 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/24/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/24/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/24/2018 8:53:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4288 at 4/23/2018 8:20:14 PM (local) 4/23/2018 2:50:14 PM (UTC). This is an informational message only; no user action is required.
Information	4/24/2018 8:53:12 AM	MTAService	0	None	Service started successfully.
Information	4/24/2018 8:53:12 AM	MTAService.OnStart	0	None	8:53:11 AM - Waiting for user to Logon
Information	4/24/2018 8:53:09 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/24/2018 8:53:07 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/24/2018 8:53:07 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/24/2018 8:53:07 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/24/2018 8:53:07 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4080.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/24/2018 8:52:44 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/24/2018 8:51:50 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/24/2018 8:51:42 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/24/2018 8:48:41 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/24/2018 8:48:41 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/24/2018 8:48:41 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/23/2018 8:20:24 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	4/23/2018 8:20:14 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	4/23/2018 8:18:28 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1012 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1012 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1012 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1012 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1012 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1404 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	4/23/2018 8:18:25 PM	MTAService.OnSessionChange	0	None	8:18:25 PM - Logoff
Information	4/23/2018 8:18:25 PM	MTAService.OnSessionChange	0	None	8:18:25 PM - Session change notice received: SessionLogoff Session ID: 1
Information	4/23/2018 8:18:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	4/23/2018 8:18:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	4/23/2018 8:18:15 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	4/23/2018 7:24:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/23/2018 7:22:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/23/2018 7:19:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 6:54:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b4ce407a-46f9-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 6:26:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 6:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/23/2018 6:21:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54693)(?)])(1 )(2 )]

"
Information	4/23/2018 6:21:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 6:21:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/23/2018 6:21:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 6:21:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 6:10:05 PM	MTAService.OnSessionChange	0	None	6:10:05 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/23/2018 5:22:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 5:19:46 PM	MTAService.OnSessionChange	0	None	5:19:46 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/23/2018 3:48:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 3:32:31 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 163, Deleted: 0, Modified: 42, Compared: 21842, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/23/2018 3:28:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 3:24:13 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/23/2018 3:24:04 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/23/2018 3:23:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/23/2018 3:23:55 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/23/2018 3:23:29 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/23/2018 3:23:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 328

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 530

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 718

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 406

Information	4/23/2018 3:22:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/23/2018 3:21:51 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	4/23/2018 3:21:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/23/2018 3:21:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54873)(?)])(1 )(2 )]

"
Information	4/23/2018 3:21:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54873)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 3:21:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/23/2018 3:21:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 3:21:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:59:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:59:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:46Z. Reason: GVLK.
Information	4/23/2018 2:54:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:54:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:54:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:54:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:52:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 65
P9: {0A493D86-761B-40E9-92C8-BE26B77B4117}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d3082665-46d7-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 2:51:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:51:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:52Z. Reason: GVLK.
Information	4/23/2018 2:46:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:46:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:46:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:46:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:41:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:41:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:57Z. Reason: GVLK.
Information	4/23/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:36:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:34:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 65
P9: {17A4BF72-F966-46D3-83C2-AA864B29802B}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b9e728f-46d5-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 2:31:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:31:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:42Z. Reason: GVLK.
Information	4/23/2018 2:26:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:26:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:26:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:26:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:23:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:23:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:45Z. Reason: GVLK.
Information	4/23/2018 2:18:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:18:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:18:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:18:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:16:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 64
P9: {4051949C-6F79-4CAA-A7BC-564B75988141}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c4326b8b-46d2-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 2:14:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:14:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:24Z. Reason: GVLK.
Warning	4/23/2018 2:13:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 2:09:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:09:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:09:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:09:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 2:05:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 2:05:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:49Z. Reason: GVLK.
Information	4/23/2018 2:00:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 2:00:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 2:00:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 2:00:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:57:56 PM	MTAService.OnSessionChange	0	None	1:57:56 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/23/2018 1:57:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 65
P9: {4016F93E-C1EF-4E69-AF2E-77E95975A5D8}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 380329c2-46d0-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 1:57:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:57:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:33Z. Reason: GVLK.
Information	4/23/2018 1:54:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb07a51a-46cf-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 1:52:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:52:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:52:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:52:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:49:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:49:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:51Z. Reason: GVLK.
Information	4/23/2018 1:44:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:44:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:44:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:44:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:42:55 PM	MTAService.OnSessionChange	0	None	1:42:53 PM - Session change notice received: SessionLock Session ID: 1
Information	4/23/2018 1:42:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 64
P9: {AA383EC1-F038-421F-8429-D51848CCC13F}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0fe2b558-46ce-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 1:40:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:40:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:22Z. Reason: GVLK.
Information	4/23/2018 1:35:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:35:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:35:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:35:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:34:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:34:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:11Z. Reason: GVLK.
Information	4/23/2018 1:29:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:29:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:29:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:29:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:27:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 65
P9: {380EDB6B-C481-4D60-A22C-27BE16566DA4}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e66e8676-46cb-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 1:26:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:26:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:11Z. Reason: GVLK.
Information	4/23/2018 1:21:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:21:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:21:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:21:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:20:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:19:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:56Z. Reason: GVLK.
Information	4/23/2018 1:14:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:14:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:14:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:14:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:12:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 64
P9: {3E7969DE-B720-40CD-B8D3-B107F5641BBD}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e07314f5-46c9-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 1:12:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:12:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:25Z. Reason: GVLK.
Information	4/23/2018 1:07:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:07:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:07:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:07:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 1:06:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 1:06:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:57Z. Reason: GVLK.
Information	4/23/2018 1:00:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 1:00:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 1:00:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 1:00:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 12:58:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 64
P9: {CB7FA457-F9EF-46CE-8B18-D547E1EB10F8}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee7f6a9e-46c7-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 12:57:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 12:57:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:52Z. Reason: GVLK.
Information	4/23/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 12:51:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 12:51:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 12:51:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 12:51:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/23/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]

"
Information	4/23/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/23/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/23/2018 12:39:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 12:19:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 12:19:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:54Z. Reason: GVLK.
Information	4/23/2018 12:14:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 12:14:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 12:14:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 12:14:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 12:12:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 64
P9: {BEFAC61F-D581-40DF-B6A2-6FEB2726172B}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 82deb7a8-46c1-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 12:10:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 12:10:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:38Z. Reason: GVLK.
Information	4/23/2018 12:05:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 12:05:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 12:05:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 12:05:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 11:48:46 AM	MTAService.OnSessionChange	0	None	11:48:46 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/23/2018 11:34:51 AM	MTAService.OnSessionChange	0	None	11:34:51 AM - Session change notice received: SessionLock Session ID: 1
Information	4/23/2018 11:04:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 11:04:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:58Z. Reason: GVLK.
Information	4/23/2018 10:59:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 10:59:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 10:59:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 10:59:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 10:57:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 65
P9: {5471EDD4-7396-4663-933B-34648825DEBD}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 11b8aec4-46b7-11e8-b8e2-204747d02364
Report Status: 0"
Information	4/23/2018 10:57:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 10:57:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:12Z. Reason: GVLK.
Information	4/23/2018 10:52:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 10:52:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 10:52:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 10:52:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 10:44:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 10:44:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:56Z. Reason: GVLK.
Warning	4/23/2018 10:43:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 10:40:57 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/23/2018 10:39:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 10:39:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 10:39:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 10:39:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 10:31:33 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/23/2018 10:22:51 AM	GE Software	0	(1)	++Installation complete
Information	4/23/2018 10:22:51 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	4/23/2018 10:22:07 AM	GE Software	0	(1)	++This is a Windows 7 machine. KB2952664 will now install.
Information	4/23/2018 10:22:03 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++Started the installation of Microsoft UpgradeReadiness 01122018 V01 with the following commandline: /Q
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	4/23/2018 10:22:02 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	4/23/2018 10:21:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 10:21:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:11Z. Reason: GVLK.
Information	4/23/2018 10:19:22 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8871.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/23/2018 10:16:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 10:16:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 10:16:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 10:16:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 10:12:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 10:12:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:08Z. Reason: GVLK.
Information	4/23/2018 10:07:14 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎04‎-‎23T04:37:14.769175200Z.
Information	4/23/2018 10:07:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 10:07:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 10:07:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 10:07:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 10:04:00 AM	MTAService.OnSessionChange	0	None	10:04:00 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/23/2018 9:54:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 9:54:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:06Z. Reason: GVLK.
Information	4/23/2018 9:49:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 9:49:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 9:49:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 9:49:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 9:42:24 AM	MTAService.OnSessionChange	0	None	9:42:24 AM - Session change notice received: SessionLock Session ID: 1
Information	4/23/2018 9:42:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 9:42:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:14Z. Reason: GVLK.
Information	4/23/2018 9:37:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎04‎-‎23T04:07:27.768793200Z.
Information	4/23/2018 9:37:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 9:37:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 9:37:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 9:37:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/23/2018 9:34:32 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/23/2018 9:23:38 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎04‎-‎23T03:53:38.228793200Z.
Information	4/23/2018 9:12:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 9:12:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:22:06Z. Reason: GVLK.
Information	4/23/2018 9:08:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 9:05:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 9:05:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 9:03:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/23/2018 9:03:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55251)(?)])(1 )(2 )]

"
Information	4/23/2018 9:03:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55251)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 9:03:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/23/2018 9:03:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 9:03:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/23/2018 9:03:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/23/2018 9:00:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 8:59:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/23/2018 8:59:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:26Z. Reason: GVLK.
Error	4/23/2018 8:55:02 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/23/2018 8:54:57 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {F4CBD446-D3E8-4F13-B9BE-BFE85B32F41C}
Error	4/23/2018 8:54:57 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {F4CBD446-D3E8-4F13-B9BE-BFE85B32F41C}
Error	4/23/2018 8:54:53 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/23/2018 8:54:35 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/23/2018 8:54:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/23/2018 8:54:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55260)(?)])(1 )(2 )]

"
Information	4/23/2018 8:54:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55260)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 8:54:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/23/2018 8:54:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 8:54:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 8:53:34 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/23/2018 8:53:21 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/23/2018 8:53:18 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/23/2018 8:53:13 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/23/2018 8:52:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/23/2018 8:52:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/23/2018 8:52:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/23/2018 8:52:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/23/2018 8:51:50 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/23/2018 8:51:50 AM	MTAService.OnSessionChange	0	None	8:51:50 AM - Logon : 212558710
Information	4/23/2018 8:51:50 AM	MTAService.OnSessionChange	0	None	8:51:50 AM - Session change notice received: SessionLogon Session ID: 1
Information	4/23/2018 8:51:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/23/2018 8:51:35 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/23/2018 8:51:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/23/2018 8:51:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/23/2018 8:51:32 AM	ESENT	302	Logging/Recovery	Windows (6584) Windows: The database engine has successfully completed recovery steps.
Information	4/23/2018 8:51:22 AM	ESENT	301	Logging/Recovery	Windows (6584) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/23/2018 8:51:22 AM	ESENT	300	Logging/Recovery	Windows (6584) Windows: The database engine is initiating recovery steps.
Information	4/23/2018 8:51:21 AM	ESENT	102	General	Windows (6584) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/23/2018 8:51:01 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8866.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/23/2018 8:50:46 AM	Service1	0	None	Service started successfully.
Error	4/23/2018 8:50:43 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/23/2018 8:50:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/23/2018 8:50:31 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/23/2018 8:50:30 AM	PostgreSQL	0	None	"2018-04-23 08:50:30 IST LOG:  redirecting log output to logging collector process
2018-04-23 08:50:30 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/23/2018 8:50:25 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/23/2018 8:50:23 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/23/2018 8:50:20 AM	MTAService	0	None	Service started successfully.
Information	4/23/2018 8:50:20 AM	MTAService.OnStart	0	None	8:50:19 AM - Waiting for user to Logon
Information	4/23/2018 8:50:13 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/23/2018 8:50:11 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:11 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/23/2018 8:50:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/23/2018 8:50:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/23/2018 8:50:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/23/2018 8:50:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/23/2018 8:50:09 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/23/2018 8:50:09 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/23/2018 8:50:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/23/2018 8:50:08 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:08 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/23/2018 8:50:07 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/23/2018 8:50:07 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/23/2018 8:50:07 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3720 at 4/18/2018 12:25:55 PM (local) 4/18/2018 6:55:55 AM (UTC). This is an informational message only; no user action is required.
Information	4/23/2018 8:50:05 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/23/2018 8:50:03 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/23/2018 8:50:02 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/23/2018 8:50:02 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/23/2018 8:50:02 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/23/2018 8:50:02 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4288.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/23/2018 8:50:01 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/23/2018 8:48:57 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/23/2018 8:48:48 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/23/2018 8:48:32 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/23/2018 8:48:31 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/23/2018 8:48:31 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/18/2018 12:26:10 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	4/18/2018 12:25:54 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	4/18/2018 12:24:52 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 22 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
"
Information	4/18/2018 12:24:41 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	4/18/2018 12:24:41 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	4/18/2018 12:24:40 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	4/18/2018 12:17:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/18/2018 12:05:25 PM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8866.0000.
Information	4/18/2018 12:03:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8866.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/18/2018 10:57:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/18/2018 10:57:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-25T05:21:26Z. Reason: GVLK.
Information	4/18/2018 10:52:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 10:52:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 10:52:25 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/04/18 05:22"
Information	4/18/2018 10:52:21 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/04/18 05:22, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/18/2018 10:47:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/18/2018 10:47:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 10:47:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/18/2018 10:47:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/18/2018 10:24:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/18/2018 10:18:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/18/2018 10:12:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/18/2018 10:12:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62382)(?)])(1 )(2 )]

"
Information	4/18/2018 10:12:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62382)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 10:12:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/18/2018 10:12:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/18/2018 10:12:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/18/2018 10:00:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/18/2018 10:00:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:15Z. Reason: GVLK.
Information	4/18/2018 9:55:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/18/2018 9:55:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 9:55:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/18/2018 9:55:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/18/2018 9:41:34 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/18/2018 8:55:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17308120-42b8-11e8-a2be-204747d02364
Report Status: 0"
Information	4/18/2018 8:54:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/18/2018 8:54:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:19Z. Reason: GVLK.
Error	4/18/2018 8:50:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/18/2018 8:49:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/18/2018 8:49:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/18/2018 8:49:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/18/2018 8:49:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/18/2018 8:47:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/18/2018 8:45:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/17/2018 7:33:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/17/2018 7:28:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/17/2018 7:28:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63266)(?)])(1 )(2 )]

"
Information	4/17/2018 7:28:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63266)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/17/2018 7:28:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/17/2018 7:28:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/17/2018 7:28:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/17/2018 7:09:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b31b4e39-4244-11e8-a2be-204747d02364
Report Status: 0"
Warning	4/17/2018 7:04:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/17/2018 7:00:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/17/2018 7:00:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/17/2018 6:00:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/17/2018 5:59:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/17/2018 5:59:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/17/2018 5:10:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/17/2018 4:26:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/17/2018 4:00:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/17/2018 4:00:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/17/2018 4:00:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/17/2018 3:32:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/17/2018 2:56:03 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/17/2018 2:15:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/17/2018 2:15:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/17/2018 2:15:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:31Z. Reason: GVLK.
Information	4/17/2018 2:10:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/17/2018 2:10:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63584)(?)])(1 )(2 )]

"
Information	4/17/2018 2:10:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63584)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/17/2018 2:10:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/17/2018 2:10:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/17/2018 2:10:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/17/2018 2:10:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/17/2018 2:10:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/17/2018 2:10:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/17/2018 2:10:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/17/2018 2:09:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c97ecdd3-421a-11e8-a2be-204747d02364
Report Status: 0"
Information	4/17/2018 2:08:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8865.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/17/2018 2:01:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/17/2018 2:00:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/17/2018 2:00:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Error	4/17/2018 1:59:25 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/17/2018 1:59:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/17/2018 1:59:07 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/17/2018 1:59:03 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	4/16/2018 7:00:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/16/2018 6:51:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 6:51:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:00Z. Reason: GVLK.
Information	4/16/2018 6:46:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/16/2018 6:46:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 6:46:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 6:45:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 6:38:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4ef2c20c-4177-11e8-a2be-204747d02364
Report Status: 0"
Information	4/16/2018 6:29:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 6:24:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/16/2018 6:24:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64770)(?)])(1 )(2 )]

"
Information	4/16/2018 6:24:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64770)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 6:24:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/16/2018 6:24:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 6:24:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 5:33:48 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/16/2018 5:16:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/16/2018 4:55:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/16/2018 3:35:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/16/2018 1:51:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/16/2018 1:38:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 65272133-414d-11e8-a2be-204747d02364
Report Status: 0"
Information	4/16/2018 12:55:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/16/2018 12:54:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/16/2018 12:52:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]

"
Information	4/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/16/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 12:26:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8864.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/16/2018 12:06:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/16/2018 11:17:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 11:12:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/16/2018 11:12:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65202)(?)])(1 )(2 )]

"
Information	4/16/2018 11:12:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65202)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 11:12:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/16/2018 11:12:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 11:12:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/16/2018 10:34:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/16/2018 9:37:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/16/2018 9:37:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/16/2018 9:28:26 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/16/2018 9:07:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 9:02:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/16/2018 9:02:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65332)(?)])(1 )(2 )]

"
Information	4/16/2018 9:02:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65332)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 9:02:40 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/16/2018 9:02:40 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 9:02:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 8:59:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 8:56:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 52, Deleted: 0, Modified: 42, Compared: 21447, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/16/2018 8:54:59 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/16/2018 8:54:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/16/2018 8:54:58 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/16/2018 8:54:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/16/2018 8:54:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/16/2018 8:54:50 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 110

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	4/16/2018 8:54:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/16/2018 8:54:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/16/2018 8:54:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65340)(?)])(1 )(2 )]

"
Information	4/16/2018 8:54:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65340)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 8:54:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/16/2018 8:54:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 8:54:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 8:43:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/16/2018 8:43:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:55Z. Reason: GVLK.
Information	4/16/2018 8:38:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/16/2018 8:38:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/16/2018 8:38:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/16/2018 8:38:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/16/2018 8:38:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7b5dea00-4123-11e8-a2be-204747d02364
Report Status: 0"
Warning	4/16/2018 8:36:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/15/2018 9:48:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/15/2018 8:35:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 8:35:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:16Z. Reason: GVLK.
Information	4/15/2018 8:30:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 8:30:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 8:30:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 8:30:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 8:30:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad1a0fb6-40bd-11e8-a2be-204747d02364
Report Status: 0"
Information	4/15/2018 8:20:16 PM	RasClient	20226	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	4/15/2018 8:19:43 PM	RasClient	20225	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.250.146
TunnelIpv6Address = None
Dial-in User = .
Information	4/15/2018 8:19:19 PM	RasClient	20224	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/15/2018 8:19:19 PM	RasClient	20223	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 8:19:19 PM	RasClient	20222	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 8:19:19 PM	RasClient	20221	None	CoId={B92C1E94-9FA5-48B4-9F78-544654992BB1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Warning	4/15/2018 8:19:18 PM	ESENT	508	Performance	"taskhost (5080) WebCacheLocal: A request to write to the file ""C:\Users\212558710\AppData\Local\Microsoft\Windows\WebCache\V01.log"" at offset 139264 (0x0000000000022000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (17941 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Error	4/15/2018 8:19:17 PM	RasClient	20227	None	CoId={DDDE68E0-3930-4174-AC6F-A0EA410628AA}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 8:19:17 PM	RasClient	20221	None	CoId={DDDE68E0-3930-4174-AC6F-A0EA410628AA}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 8:19:17 PM	RasClient	20227	None	CoId={71DC4250-9CC3-48EE-BF51-21F9B26809E5}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 8:19:17 PM	RasClient	20221	None	CoId={71DC4250-9CC3-48EE-BF51-21F9B26809E5}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 3:20:16 PM	RasClient	20227	None	CoId={71FA4FCA-165E-4CF0-AC21-D6824C029874}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 3:20:16 PM	RasClient	20221	None	CoId={71FA4FCA-165E-4CF0-AC21-D6824C029874}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 3:20:15 PM	RasClient	20227	None	CoId={82471713-9AF4-487D-A99A-E52F82C276B4}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 3:20:15 PM	RasClient	20221	None	CoId={82471713-9AF4-487D-A99A-E52F82C276B4}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 3:20:14 PM	RasClient	20227	None	CoId={23552F29-32B0-4900-9B7F-670593514E24}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 3:20:14 PM	RasClient	20221	None	CoId={23552F29-32B0-4900-9B7F-670593514E24}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 3:20:14 PM	RasClient	20227	None	CoId={A3BD23C3-F6B5-4E4F-B5F8-2F0A0A31E5FF}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 3:20:14 PM	RasClient	20221	None	CoId={A3BD23C3-F6B5-4E4F-B5F8-2F0A0A31E5FF}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/15/2018 3:20:12 PM	RasClient	20226	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	4/15/2018 3:20:12 PM	RasClient	20225	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.250.146
TunnelIpv6Address = None
Dial-in User = .
Information	4/15/2018 3:20:08 PM	RasClient	20224	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/15/2018 3:20:08 PM	RasClient	20223	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 3:20:08 PM	RasClient	20222	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 3:20:08 PM	RasClient	20221	None	CoId={350C2FA3-839D-4BC2-B8E8-2333B83ACE7C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/15/2018 3:20:05 PM	RasClient	20226	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	4/15/2018 3:05:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/15/2018 3:03:08 PM	RasClient	20225	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.250.146
TunnelIpv6Address = None
Dial-in User = .
Information	4/15/2018 3:03:02 PM	RasClient	20224	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/15/2018 3:03:02 PM	RasClient	20223	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 3:03:02 PM	RasClient	20222	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 3:03:02 PM	RasClient	20221	None	CoId={6F2B1DA3-3547-4F79-90C2-45994786D5AB}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/15/2018 2:40:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8863.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/15/2018 2:16:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 2:11:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b8ac1502-4088-11e8-a2be-204747d02364
Report Status: 0"
Information	4/15/2018 2:10:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66463)(?)])(1 )(2 )]

"
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66463)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109663  Grace type=8.
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=9564a5ab-08a1-4ca6-b2b4-91e5a28b6324"
Information	4/15/2018 2:10:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=c37ed116-efa9-4d1f-8e02-ace86fc3b8f7"
Information	4/15/2018 2:10:57 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/15/2018 2:10:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/15/2018 2:10:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20384)(?)])(1 )(2 )]

"
Information	4/15/2018 2:10:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20384)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 2:10:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/15/2018 2:10:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 2:10:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/15/2018 12:02:29 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0aff3b4c
Faulting process id: 0x2910
Faulting application start time: 0x01d3d45e138bfc48
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: c49c32b1-4076-11e8-a2be-204747d02364"
Error	4/15/2018 10:28:29 AM	RasClient	20227	None	CoId={0C84DBD3-4EB3-42C1-9E7F-C7769BA304EB}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 10:28:29 AM	RasClient	20221	None	CoId={0C84DBD3-4EB3-42C1-9E7F-C7769BA304EB}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	4/15/2018 10:28:29 AM	RasClient	20227	None	CoId={75B355E2-BF99-4F42-BAB1-A32FC1E44C13}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	4/15/2018 10:28:29 AM	RasClient	20221	None	CoId={75B355E2-BF99-4F42-BAB1-A32FC1E44C13}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/15/2018 10:28:22 AM	RasClient	20226	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	4/15/2018 9:11:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/15/2018 8:46:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	4/15/2018 8:43:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 8:43:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:00Z. Reason: GVLK.
Information	4/15/2018 8:38:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 8:38:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 8:38:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 8:37:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 8:12:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 8:12:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:59Z. Reason: GVLK.
Information	4/15/2018 8:07:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 8:07:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 8:07:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 8:07:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 8:06:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 8:06:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:47Z. Reason: GVLK.
Information	4/15/2018 8:01:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 8:01:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 8:01:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 8:01:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 7:42:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 7:42:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:58Z. Reason: GVLK.
Information	4/15/2018 7:35:44 AM	RasClient	20225	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.224.254
TunnelIpv6Address = None
Dial-in User = .
Information	4/15/2018 7:35:39 AM	RasClient	20224	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/15/2018 7:35:39 AM	RasClient	20223	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 7:35:39 AM	RasClient	20222	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/15/2018 7:35:39 AM	RasClient	20221	None	CoId={A661868B-5DE9-4298-AD91-2177240BA2B1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/15/2018 7:33:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 7:33:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 7:33:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 7:33:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 7:30:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 7:30:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:50Z. Reason: GVLK.
Information	4/15/2018 7:28:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/15/2018 7:27:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 631db79b-4050-11e8-a2be-204747d02364
Report Status: 0"
Information	4/15/2018 7:25:04 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/15/2018 7:24:08 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8862.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/15/2018 7:24:01 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	4/15/2018 7:23:59 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {C9132A7C-44F3-428F-BA5E-46A21397D02D}
Information	4/15/2018 7:23:49 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/15/2018 7:23:47 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/15/2018 7:23:45 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/15/2018 7:23:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/15/2018 7:23:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20791)(?)])(1 )(2 )]

"
Information	4/15/2018 7:23:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20791)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 7:23:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/15/2018 7:23:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 7:23:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 7:23:16 AM	ESENT	302	Logging/Recovery	Windows (8124) Windows: The database engine has successfully completed recovery steps.
Error	4/15/2018 7:23:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/15/2018 7:23:16 AM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/15/2018 7:23:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/15/2018 7:23:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/15/2018 7:23:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/15/2018 7:23:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/15/2018 7:23:05 AM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00638.log.
Information	4/15/2018 7:23:05 AM	ESENT	300	Logging/Recovery	Windows (8124) Windows: The database engine is initiating recovery steps.
Information	4/15/2018 7:23:04 AM	ESENT	102	General	Windows (8124) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/15/2018 7:23:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/15/2018 7:23:00 AM	MTAService	0	None	Service started successfully.
Information	4/15/2018 7:22:49 AM	Service1	0	None	Service started successfully.
Error	4/15/2018 7:22:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/15/2018 7:22:42 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/15/2018 7:22:17 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/15/2018 7:22:10 AM	MTAService.OnStart	0	None	7:22:09 AM - User is already logged in : 212558710
Information	4/15/2018 7:22:07 AM	PostgreSQL	0	None	"2018-04-15 07:22:07 IST LOG:  redirecting log output to logging collector process
2018-04-15 07:22:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/15/2018 7:22:07 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/15/2018 7:22:03 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/15/2018 7:21:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/15/2018 7:21:57 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	4/15/2018 7:21:57 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/15/2018 7:21:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/15/2018 7:21:57 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/15/2018 7:21:56 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/15/2018 7:21:52 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:52 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/15/2018 7:21:52 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/15/2018 7:21:52 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/15/2018 7:21:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/15/2018 7:21:51 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/15/2018 7:21:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/15/2018 7:21:49 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:49 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/15/2018 7:21:49 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/15/2018 7:21:49 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/15/2018 7:21:48 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/15/2018 7:21:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/15/2018 7:21:46 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/15/2018 7:21:46 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:46 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/15/2018 7:21:46 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/15/2018 7:21:45 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/15/2018 7:21:45 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3456 at 4/14/2018 11:26:11 PM (local) 4/14/2018 5:56:11 PM (UTC). This is an informational message only; no user action is required.
Information	4/15/2018 7:21:44 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/15/2018 7:21:44 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/15/2018 7:21:44 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/15/2018 7:21:44 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/15/2018 7:21:44 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3720.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/15/2018 7:21:36 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/15/2018 7:21:21 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/15/2018 7:21:14 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/15/2018 7:21:05 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/15/2018 7:21:06 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/15/2018 7:21:05 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/14/2018 11:26:17 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	4/14/2018 11:26:11 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	4/14/2018 11:26:09 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\SysVol\logon.ds.ge.com\Policies\{6D2A5CDB-AF09-4F1C-8632-37CAA44C207E}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Warning	4/14/2018 11:25:58 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 4304 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4304 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 928 (\Device\HarddiskVolume1\Windows\System32\services.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4304 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4304 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1960 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	4/14/2018 11:25:58 PM	MTAService.OnSessionChange	0	None	11:25:58 PM - Logoff
Information	4/14/2018 11:25:58 PM	MTAService.OnSessionChange	0	None	11:25:58 PM - Session change notice received: SessionLogoff Session ID: 1
Information	4/14/2018 11:25:57 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	4/14/2018 11:25:57 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	4/14/2018 11:25:57 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	4/14/2018 11:25:51 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	4/14/2018 11:25:49 PM	RasClient	20226	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	4/14/2018 10:47:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 10:47:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:04Z. Reason: GVLK.
Information	4/14/2018 10:42:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/14/2018 10:42:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 10:42:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 10:42:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/14/2018 10:17:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 10:17:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:02Z. Reason: GVLK.
Information	4/14/2018 10:15:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8862.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/14/2018 10:12:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/14/2018 10:12:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 10:12:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 10:12:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/14/2018 10:10:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 10:05:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/14/2018 10:05:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21349)(?)])(1 )(2 )]

"
Information	4/14/2018 10:05:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21349)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 10:05:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/14/2018 10:05:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 10:05:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/14/2018 9:48:03 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/14/2018 9:47:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 9:47:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:02Z. Reason: GVLK.
Information	4/14/2018 9:46:41 PM	RasClient	20225	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.230.81
TunnelIpv6Address = None
Dial-in User = .
Information	4/14/2018 9:46:35 PM	RasClient	20224	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/14/2018 9:46:35 PM	RasClient	20223	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/14/2018 9:46:35 PM	RasClient	20222	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/14/2018 9:46:35 PM	RasClient	20221	None	CoId={B370D26E-2119-402B-9E3E-81CC63DA896B}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/14/2018 9:44:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 9:42:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/14/2018 9:42:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 9:42:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 9:42:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/14/2018 9:39:46 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	4/14/2018 9:39:46 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {3892FF98-9664-42CE-BA94-2EE50A9C438A}
Information	4/14/2018 9:38:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/14/2018 9:38:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21376)(?)])(1 )(2 )]

"
Information	4/14/2018 9:38:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21376)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 9:38:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/14/2018 9:38:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 9:38:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/14/2018 9:36:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 9:36:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:28Z. Reason: GVLK.
Information	4/14/2018 9:36:02 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/14/2018 9:34:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 754309f0-3ffd-11e8-8d30-204747d02364
Report Status: 0"
Information	4/14/2018 9:33:29 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	4/14/2018 9:33:28 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	4/14/2018 9:30:56 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {3F6DFE49-86F6-47AD-BA58-50CBFABE4FEA}
Information	4/14/2018 9:30:42 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/14/2018 9:29:32 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/14/2018 9:29:31 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/14/2018 9:29:16 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/14/2018 9:29:12 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/14/2018 9:29:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/14/2018 9:29:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21385)(?)])(1 )(2 )]

"
Information	4/14/2018 9:29:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 9:29:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/14/2018 9:29:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 9:29:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/14/2018 9:28:54 PM	ESENT	302	Logging/Recovery	Windows (9068) Windows: The database engine has successfully completed recovery steps.
Information	4/14/2018 9:28:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/14/2018 9:28:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/14/2018 9:28:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/14/2018 9:28:44 PM	ESENT	301	Logging/Recovery	Windows (9068) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/14/2018 9:28:44 PM	ESENT	300	Logging/Recovery	Windows (9068) Windows: The database engine is initiating recovery steps.
Information	4/14/2018 9:28:44 PM	ESENT	102	General	Windows (9068) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/14/2018 9:28:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/14/2018 9:28:39 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8861.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Error	4/14/2018 9:28:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/14/2018 9:27:52 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/14/2018 9:27:44 PM	Service1	0	None	Service started successfully.
Error	4/14/2018 9:27:36 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/14/2018 9:27:36 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/14/2018 9:27:21 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/14/2018 9:27:08 PM	MTAService	0	None	Service started successfully.
Information	4/14/2018 9:26:55 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:55 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/14/2018 9:26:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/14/2018 9:26:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/14/2018 9:26:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/14/2018 9:26:53 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/14/2018 9:26:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/14/2018 9:26:53 PM	PostgreSQL	0	None	Server started and accepting connections

Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/14/2018 9:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/14/2018 9:26:51 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:51 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/14/2018 9:26:51 PM	PostgreSQL	0	None	"2018-04-14 21:26:51 IST LOG:  redirecting log output to logging collector process
2018-04-14 21:26:51 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/14/2018 9:26:49 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/14/2018 9:26:49 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/14/2018 9:26:49 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/14/2018 9:26:49 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/14/2018 9:26:47 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:47 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:47 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/14/2018 9:26:46 PM	PostgreSQL	0	None	Waiting for server startup...

Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/14/2018 9:26:46 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4376 at 4/13/2018 11:38:12 PM (local) 4/13/2018 6:08:12 PM (UTC). This is an informational message only; no user action is required.
Information	4/14/2018 9:26:40 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/14/2018 9:26:39 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/14/2018 9:26:39 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/14/2018 9:26:39 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/14/2018 9:26:39 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/14/2018 9:26:31 PM	MTAService.OnStart	0	None	9:26:30 PM - User is already logged in : 212558710
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3456.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/14/2018 9:26:13 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	4/14/2018 9:26:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/14/2018 9:26:11 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	4/14/2018 9:26:11 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/14/2018 9:26:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/14/2018 9:26:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	4/14/2018 9:25:33 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/14/2018 9:25:29 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/14/2018 9:25:15 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/14/2018 9:25:15 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	4/14/2018 9:25:15 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/13/2018 11:38:12 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	4/13/2018 11:38:06 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 39 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 4492 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1336 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	4/13/2018 11:38:06 PM	MTAService.OnSessionChange	0	None	11:38:06 PM - Logoff
Information	4/13/2018 11:38:06 PM	MTAService.OnSessionChange	0	None	11:38:06 PM - Session change notice received: SessionLogoff Session ID: 1
Information	4/13/2018 11:38:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	4/13/2018 11:38:04 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	4/13/2018 11:38:04 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	4/13/2018 11:38:02 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	4/13/2018 11:37:56 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	4/13/2018 11:37:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 11:37:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 11:37:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 11:13:49 PM	MTAService.OnSessionChange	0	None	11:13:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 11:00:39 PM	MTAService.OnSessionChange	0	None	11:00:39 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 10:31:32 PM	RasClient	20226	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Warning	4/13/2018 9:44:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 9:42:27 PM	RasClient	20225	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.239.220
TunnelIpv6Address = None
Dial-in User = .
Information	4/13/2018 9:42:21 PM	RasClient	20224	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	4/13/2018 9:42:21 PM	RasClient	20223	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/13/2018 9:42:21 PM	RasClient	20222	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	4/13/2018 9:42:21 PM	RasClient	20221	None	CoId={0803A875-DA1F-4C80-B0C5-BBD5D83CA2E7}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	4/13/2018 9:29:28 PM	MTAService.OnSessionChange	0	None	9:29:28 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 9:29:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/13/2018 9:28:58 PM	Desktop Window Manager	9007	None	The Desktop Window Manager was unable to start because WDDM is not in use
Information	4/13/2018 8:39:48 PM	MTAService.OnSessionChange	0	None	8:39:48 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 7:54:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 7:54:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:32Z. Reason: GVLK.
Information	4/13/2018 7:48:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/13/2018 7:48:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 7:48:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 7:48:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/13/2018 7:38:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 6:55:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 202cd189-3f1e-11e8-ae76-204747d02364
Report Status: 0"
Information	4/13/2018 6:08:37 PM	MTAService.OnSessionChange	0	None	6:08:37 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/13/2018 6:00:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/13/2018 5:39:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/13/2018 5:36:43 PM	MTAService.OnSessionChange	0	None	5:36:43 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 5:32:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 5:27:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 5:27:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23067)(?)])(1 )(2 )]

"
Information	4/13/2018 5:27:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23067)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 5:27:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 5:27:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 5:27:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 5:21:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 5:21:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:47Z. Reason: GVLK.
Information	4/13/2018 5:19:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 5:16:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/13/2018 5:16:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 5:16:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 5:16:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23080)(?)])(1 )(2 )]

"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23080)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 5:14:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 5:00:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 4:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 4:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23099)(?)])(1 )(2 )]

"
Information	4/13/2018 4:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23099)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 4:55:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 4:55:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 4:55:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 4:47:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/13/2018 4:06:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 3:49:34 PM	MTAService.OnSessionChange	0	None	3:49:34 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 3:11:05 PM	MTAService.OnSessionChange	0	None	3:11:05 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 3:00:55 PM	MTAService.OnSessionChange	0	None	3:00:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 2:24:40 PM	MTAService.OnSessionChange	0	None	2:24:40 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 2:12:39 PM	MTAService.OnSessionChange	0	None	2:12:39 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/13/2018 2:09:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 1:55:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3619dddb-3ef4-11e8-ae76-204747d02364
Report Status: 0"
Information	4/13/2018 1:43:28 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/13/2018 1:15:56 PM	MTAService.OnSessionChange	0	None	1:15:56 PM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23347)(?)])(1 )(2 )]

"
Information	4/13/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23347)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 12:47:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/13/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 12:31:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 12:26:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 12:26:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23368)(?)])(1 )(2 )]

"
Information	4/13/2018 12:26:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23368)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 12:26:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 12:26:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 12:26:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/13/2018 12:25:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 12:07:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8861.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/13/2018 11:21:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 11:16:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 11:16:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23438)(?)])(1 )(2 )]

"
Information	4/13/2018 11:16:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23438)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 11:16:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 11:16:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 11:16:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/13/2018 10:35:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 10:19:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/13/2018 10:15:58 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/13/2018 10:15:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/13/2018 9:47:08 AM	MTAService.OnSessionChange	0	None	9:47:08 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 9:28:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 9:28:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:16Z. Reason: GVLK.
Information	4/13/2018 9:25:09 AM	MTAService.OnSessionChange	0	None	9:25:09 AM - Session change notice received: SessionLock Session ID: 1
Information	4/13/2018 9:23:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/13/2018 9:23:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 9:23:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 9:23:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/13/2018 9:17:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/13/2018 9:01:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 9:01:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:38Z. Reason: GVLK.
Information	4/13/2018 8:56:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/13/2018 8:56:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 8:56:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 8:56:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 8:55:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c479331-3eca-11e8-ae76-204747d02364
Report Status: 0"
Information	4/13/2018 8:54:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/13/2018 8:54:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:38Z. Reason: GVLK.
Information	4/13/2018 8:52:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/13/2018 8:51:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/13/2018 8:49:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/13/2018 8:49:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/13/2018 8:49:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 8:49:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/13/2018 8:48:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/13/2018 8:47:50 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 312

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 78

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 327

Information	4/13/2018 8:47:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/13/2018 8:47:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/13/2018 8:47:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23587)(?)])(1 )(2 )]

"
Information	4/13/2018 8:47:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23587)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	4/13/2018 8:47:03 AM	Microsoft Office 16	2001	None	Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Warning	4/13/2018 8:46:55 AM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	4/13/2018 8:46:43 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/13/2018 8:46:43 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/13/2018 8:46:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/13/2018 8:46:27 AM	MTAService.OnSessionChange	0	None	8:46:27 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/13/2018 8:45:52 AM	Microsoft-Windows-CAPI2	4112	None	Successful auto update of disallowed certificate list with effective date: Wednesday, April 11, 2018 11:48:04 PM.
Warning	4/13/2018 8:45:14 AM	ESENT	508	Performance	"wuaueng.dll (1196) SUS20ClientDataStore: A request to write to the file ""C:\Windows\SoftwareDistribution\DataStore\DataStore.edb"" at offset 2606006272 (0x000000009b548000) for 32768 (0x00008000) bytes succeeded, but took an abnormally long time (48177 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Information	4/12/2018 7:22:13 PM	MTAService.OnSessionChange	0	None	7:22:13 PM - Session change notice received: SessionLock Session ID: 1
Information	4/12/2018 7:17:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 7:17:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:31Z. Reason: GVLK.
Information	4/12/2018 7:12:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/12/2018 7:12:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 7:12:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 7:12:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 6:55:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 6:50:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:50:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24424)(?)])(1 )(2 )]

"
Information	4/12/2018 6:50:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24424)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:49:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:49:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24425)(?)])(1 )(2 )]

"
Information	4/12/2018 6:49:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:49:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:49:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24425)(?)])(1 )(2 )]

"
Information	4/12/2018 6:49:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:48:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:48:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24426)(?)])(1 )(2 )]

"
Information	4/12/2018 6:48:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24426)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:48:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 6:48:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 6:48:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 6:44:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 6:44:07 PM	MTAService.OnSessionChange	0	None	6:44:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 6:42:11 PM	MTAService.OnSessionChange	0	None	6:42:11 PM - Session change notice received: SessionLock Session ID: 1
Information	4/12/2018 6:39:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:39:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24435)(?)])(1 )(2 )]

"
Information	4/12/2018 6:39:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24435)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:38:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:38:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24436)(?)])(1 )(2 )]

"
Information	4/12/2018 6:38:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24436)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:38:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 6:38:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 6:38:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/12/2018 6:32:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 6:27:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 6:25:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7efc311-3e50-11e8-ae76-204747d02364
Report Status: 0"
Information	4/12/2018 6:22:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:22:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24452)(?)])(1 )(2 )]

"
Information	4/12/2018 6:22:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24452)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:19:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:19:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24455)(?)])(1 )(2 )]

"
Information	4/12/2018 6:19:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24455)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:17:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:17:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24457)(?)])(1 )(2 )]

"
Information	4/12/2018 6:17:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24457)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:16:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:16:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24458)(?)])(1 )(2 )]

"
Information	4/12/2018 6:16:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:15:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:15:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24459)(?)])(1 )(2 )]

"
Information	4/12/2018 6:15:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24459)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:15:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 6:15:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 6:15:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 6:13:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 6:08:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 6:08:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24466)(?)])(1 )(2 )]

"
Information	4/12/2018 6:08:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24466)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 6:08:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 6:08:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 6:08:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 6:04:44 PM	MTAService.OnSessionChange	0	None	6:04:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 6:02:25 PM	MTAService.OnSessionChange	0	None	6:02:25 PM - Session change notice received: SessionLock Session ID: 1
Error	4/12/2018 5:39:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	4/12/2018 4:52:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/12/2018 4:50:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/12/2018 4:50:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/12/2018 4:46:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 4:41:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:41:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]

"
Information	4/12/2018 4:41:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:38:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:38:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24556)(?)])(1 )(2 )]

"
Information	4/12/2018 4:38:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24556)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:36:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 16

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	4/12/2018 4:36:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 4:36:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:36:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24558)(?)])(1 )(2 )]

"
Information	4/12/2018 4:36:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24558)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:35:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 4:35:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:35:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24559)(?)])(1 )(2 )]

"
Information	4/12/2018 4:35:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24559)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:35:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:35:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24559)(?)])(1 )(2 )]

"
Information	4/12/2018 4:35:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24559)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:32:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 4:32:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24562)(?)])(1 )(2 )]

"
Information	4/12/2018 4:32:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24562)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:32:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 4:32:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 4:32:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 4:23:59 PM	MTAService.OnSessionChange	0	None	4:23:59 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 4:18:22 PM	MTAService.OnSessionChange	0	None	4:18:22 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/12/2018 3:14:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 2:20:58 PM	MTAService.OnSessionChange	0	None	2:20:58 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 2:18:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:17:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:17:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/12/2018 1:38:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 1:25:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee3a9fc3-3e26-11e8-ae76-204747d02364
Report Status: 0"
Information	4/12/2018 1:10:55 PM	MTAService.OnSessionChange	0	None	1:10:55 PM - Session change notice received: SessionLock Session ID: 1
Information	4/12/2018 1:04:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 1:04:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:42Z. Reason: GVLK.
Information	4/12/2018 12:59:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/12/2018 12:59:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 12:59:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 12:59:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/12/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24787)(?)])(1 )(2 )]

"
Information	4/12/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24787)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/12/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 12:42:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8860.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/12/2018 12:02:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 11:52:54 AM	MTAService.OnSessionChange	0	None	11:52:54 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 11:42:25 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/12/2018 11:42:23 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/12/2018 11:37:12 AM	MTAService.OnSessionChange	0	None	11:37:12 AM - Session change notice received: SessionLock Session ID: 1
Information	4/12/2018 10:18:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 10:17:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 10:17:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/12/2018 10:17:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/12/2018 10:17:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 10:17:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/12/2018 10:17:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/12/2018 10:17:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 10:17:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/12/2018 10:14:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 10:03:51 AM	MTAService.OnSessionChange	0	None	10:03:51 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/12/2018 9:40:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/12/2018 9:40:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 12, Compared: 21322, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/12/2018 9:38:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/12/2018 9:38:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/12/2018 9:32:52 AM	MTAService.OnSessionChange	0	None	9:32:52 AM - Session change notice received: SessionLock Session ID: 1
Information	4/12/2018 9:26:44 AM	MTAService.OnSessionChange	0	None	9:26:44 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/12/2018 8:40:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 8:25:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0464a26b-3dfd-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/12/2018 6:42:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 6:18:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 6:17:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 6:17:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 6:17:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/12/2018 4:52:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 4:50:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 4:50:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:14Z. Reason: GVLK.
Information	4/12/2018 4:45:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/12/2018 4:45:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:45:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 4:45:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/12/2018 4:42:37 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/12/2018 4:36:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 4:36:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:43Z. Reason: GVLK.
Error	4/12/2018 4:31:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/12/2018 4:31:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/12/2018 4:31:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 4:31:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 4:31:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 3:25:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1aaa1663-3dd3-11e8-ae76-204747d02364
Report Status: 0"
Information	4/12/2018 3:03:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/12/2018 3:03:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:43Z. Reason: GVLK.
Warning	4/12/2018 3:01:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 2:58:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/12/2018 2:58:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/12/2018 2:58:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/12/2018 2:58:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/12/2018 2:18:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:17:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:17:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:16:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 2:16:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/12/2018 1:44:58 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/12/2018 1:41:45 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	4/12/2018 1:24:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/12/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/11/2018 11:24:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 10:25:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 307c186f-3da9-11e8-ae76-204747d02364
Report Status: 0"
Information	4/11/2018 10:17:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:17:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:17:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:16:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:16:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/11/2018 9:45:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/11/2018 8:12:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 7:38:45 PM	MTAService.OnSessionChange	0	None	7:38:45 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 6:50:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 6:45:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/11/2018 6:45:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25869)(?)])(1 )(2 )]

"
Information	4/11/2018 6:45:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25869)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 6:44:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/11/2018 6:44:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25870)(?)])(1 )(2 )]

"
Information	4/11/2018 6:44:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25870)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 6:44:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/11/2018 6:44:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 6:44:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/11/2018 6:41:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 6:30:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 6:30:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:17:18Z. Reason: GVLK.
Information	4/11/2018 6:30:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 6:25:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/11/2018 6:25:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 6:25:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 6:25:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25889)(?)])(1 )(2 )]

"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25889)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 6:25:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/11/2018 6:21:55 PM	MTAService.OnSessionChange	0	None	6:21:55 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 6:17:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:17:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:17:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:16:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:16:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 5:51:30 PM	MTAService.OnSessionChange	0	None	5:51:30 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 5:44:33 PM	MTAService.OnSessionChange	0	None	5:44:33 PM - Session change notice received: SessionUnlock Session ID: 1
Error	4/11/2018 5:39:01 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/11/2018 5:32:43 PM	MTAService.OnSessionChange	0	None	5:32:43 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 5:25:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46900811-3d7f-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/11/2018 4:51:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/11/2018 2:56:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 2:55:18 PM	MTAService.OnSessionChange	0	None	2:55:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 2:42:51 PM	MTAService.OnSessionChange	0	None	2:42:51 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 2:37:21 PM	MTAService.OnSessionChange	0	None	2:37:21 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 2:17:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:17:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:17:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:16:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:06:12 PM	MTAService.OnSessionChange	0	None	2:06:12 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 1:59:11 PM	MTAService.OnSessionChange	0	None	1:59:11 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 1:24:22 PM	MTAService.OnSessionChange	0	None	1:24:22 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/11/2018 1:02:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 1:00:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8859.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/11/2018 12:52:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 12:47:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/11/2018 12:47:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26226)(?)])(1 )(2 )]

"
Information	4/11/2018 12:47:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26226)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 12:47:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/11/2018 12:47:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 12:47:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/11/2018 12:31:39 PM	MTAService.OnSessionChange	0	None	12:31:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 12:25:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ccfbe73-3d55-11e8-ae76-204747d02364
Report Status: 0"
Information	4/11/2018 12:22:36 PM	MTAService.OnSessionChange	0	None	12:22:36 PM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 12:08:13 PM	MTAService.OnSessionChange	0	None	12:08:13 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/11/2018 11:48:45 AM	MTAService.OnSessionChange	0	None	11:48:45 AM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 11:36:15 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/11/2018 11:35:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	4/11/2018 11:11:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 10:52:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 10:52:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-18T05:16:35Z. Reason: GVLK.
Information	4/11/2018 10:47:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 10:47:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 10:47:35 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/04/11 05:17"
Information	4/11/2018 10:47:34 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/04/11 05:17, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/11/2018 10:42:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/11/2018 10:42:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 10:42:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 10:42:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/11/2018 10:21:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/11/2018 10:17:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:17:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:16:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 10:16:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 9:58:19 AM	MTAService.OnSessionChange	0	None	9:58:19 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/11/2018 9:38:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 9:27:55 AM	MTAService.OnSessionChange	0	None	9:27:55 AM - Session change notice received: SessionLock Session ID: 1
Information	4/11/2018 9:19:57 AM	MTAService.OnSessionChange	0	None	9:19:57 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/11/2018 7:52:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 7:25:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 732a71a4-3d2b-11e8-ae76-204747d02364
Report Status: 0"
Information	4/11/2018 6:17:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:16:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 6:16:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/11/2018 5:52:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/11/2018 4:09:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 4:05:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 4:05:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:30Z. Reason: GVLK.
Information	4/11/2018 4:00:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/11/2018 4:00:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 4:00:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 4:00:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/11/2018 3:57:11 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/11/2018 3:49:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 3:49:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:47Z. Reason: GVLK.
Error	4/11/2018 3:45:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/11/2018 3:44:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/11/2018 3:44:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 3:44:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 3:44:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/11/2018 2:28:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 2:25:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 894a2c6a-3d01-11e8-ae76-204747d02364
Report Status: 0"
Information	4/11/2018 2:23:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/11/2018 2:23:08 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/11/2018 2:17:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:16:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 2:16:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/11/2018 1:10:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/11/2018 1:10:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:23Z. Reason: GVLK.
Information	4/11/2018 1:05:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/11/2018 1:05:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/11/2018 1:05:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/11/2018 1:05:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/11/2018 12:53:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/11/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/10/2018 11:20:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 10:17:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 10:16:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 10:16:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/10/2018 10:16:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/10/2018 9:44:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 9:25:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9f9738e6-3cd7-11e8-ae76-204747d02364
Report Status: 0"
Information	4/10/2018 8:34:32 PM	MTAService.OnSessionChange	0	None	8:34:32 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/10/2018 8:07:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 7:32:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 7:28:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 7:28:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:46Z. Reason: GVLK.
Information	4/10/2018 7:27:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/10/2018 7:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27267)(?)])(1 )(2 )]

"
Information	4/10/2018 7:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 7:27:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/10/2018 7:27:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 7:27:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/10/2018 7:23:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/10/2018 7:23:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 7:23:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 7:23:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/10/2018 6:34:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/10/2018 6:32:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/10/2018 6:22:05 PM	Application Error	1000	(100)	"Faulting application name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x56fa03eb
Faulting module name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x56fa03eb
Exception code: 0xc0000005
Fault offset: 0x00000000001810c6
Faulting process id: 0x378c
Faulting application start time: 0x01d3d0bc29e41617
Faulting application path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Faulting module path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Report Id: f845f1f7-3cbd-11e8-ae76-204747d02364"
Information	4/10/2018 6:17:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:16:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:16:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:15:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 5:57:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/10/2018 5:57:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 5:57:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/10/2018 5:38:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/10/2018 5:37:54 PM	MTAService.OnSessionChange	0	None	5:37:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/10/2018 5:04:14 PM	MTAService.OnSessionChange	0	None	5:04:14 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/10/2018 4:41:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 4:25:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5ce3597-3cad-11e8-ae76-204747d02364
Report Status: 0"
Information	4/10/2018 4:21:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 4:16:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/10/2018 4:16:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27458)(?)])(1 )(2 )]

"
Information	4/10/2018 4:16:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 4:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 4:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 4:14:06 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	4/10/2018 4:14:06 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	4/10/2018 4:14:06 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	4/10/2018 4:14:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/10/2018 4:14:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 4:14:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/10/2018 3:57:29 PM	MTAService.OnSessionChange	0	None	3:57:29 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/10/2018 3:42:56 PM	MTAService.OnSessionChange	0	None	3:42:56 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/10/2018 3:09:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/10/2018 2:46:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/10/2018 2:44:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/10/2018 2:44:32 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/10/2018 2:31:53 PM	MTAService.OnSessionChange	0	None	2:31:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/10/2018 2:17:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:16:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:16:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:15:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:02:09 PM	MTAService.OnSessionChange	0	None	2:02:09 PM - Session change notice received: SessionLock Session ID: 1
Information	4/10/2018 1:54:44 PM	MTAService.OnSessionChange	0	None	1:54:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/10/2018 1:29:56 PM	MTAService.OnSessionChange	0	None	1:29:56 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/10/2018 1:16:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/10/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27667)(?)])(1 )(2 )]

"
Information	4/10/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27667)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/10/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/10/2018 12:32:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8858.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/10/2018 12:01:59 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/10/2018 12:01:42 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/10/2018 11:48:32 AM	MTAService.OnSessionChange	0	None	11:48:32 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/10/2018 11:33:19 AM	MTAService.OnSessionChange	0	None	11:33:19 AM - Session change notice received: SessionLock Session ID: 1
Information	4/10/2018 11:25:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cc277c84-3c83-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/10/2018 11:17:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 10:25:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	4/10/2018 10:19:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/10/2018 10:17:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 10:16:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 10:15:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 10:15:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 9:43:42 AM	MTAService.OnSessionChange	0	None	9:43:42 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/10/2018 9:19:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/10/2018 7:30:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 6:25:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e28493ee-3c59-11e8-ae76-204747d02364
Report Status: 0"
Information	4/10/2018 6:17:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:16:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:15:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 6:15:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/10/2018 5:46:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/10/2018 3:47:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 3:44:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 3:44:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:25Z. Reason: GVLK.
Information	4/10/2018 3:39:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/10/2018 3:39:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 3:39:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 3:39:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/10/2018 2:17:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:16:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:15:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/10/2018 2:15:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/10/2018 1:57:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/10/2018 1:25:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f8e90502-3c2f-11e8-ae76-204747d02364
Report Status: 0"
Information	4/10/2018 12:52:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/10/2018 12:52:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:25Z. Reason: GVLK.
Information	4/10/2018 12:47:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/10/2018 12:47:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/10/2018 12:47:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/10/2018 12:47:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/10/2018 12:10:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/9/2018 10:36:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 10:16:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 10:16:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 10:15:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 10:15:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/9/2018 9:03:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 8:25:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f26f778-3c06-11e8-ae76-204747d02364
Report Status: 0"
Information	4/9/2018 8:24:10 PM	MTAService.OnSessionChange	0	None	8:24:10 PM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 7:30:59 PM	MTAService.OnSessionChange	0	None	7:30:59 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/9/2018 7:10:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 6:57:33 PM	MTAService.OnSessionChange	0	None	6:57:33 PM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 6:18:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 6:16:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 6:15:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 6:15:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 6:15:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 6:13:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 6:13:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28781)(?)])(1 )(2 )]

"
Information	4/9/2018 6:13:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28781)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 6:11:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 6:11:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28783)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 6:11:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 6:01:31 PM	MTAService.OnSessionChange	0	None	6:01:31 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/9/2018 5:17:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 5:00:46 PM	MTAService.OnSessionChange	0	None	5:00:46 PM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 4:06:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 4:01:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 4:01:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28913)(?)])(1 )(2 )]

"
Information	4/9/2018 4:01:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28913)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 4:01:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 4:01:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 4:01:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 3:43:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 3:38:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 3:38:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28936)(?)])(1 )(2 )]

"
Information	4/9/2018 3:38:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28936)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 3:37:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 3:37:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 3:37:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28937)(?)])(1 )(2 )]

"
Information	4/9/2018 3:37:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 3:37:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28937)(?)])(1 )(2 )]

"
Information	4/9/2018 3:37:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 3:36:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 3:36:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28938)(?)])(1 )(2 )]

"
Information	4/9/2018 3:36:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28938)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 3:36:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 3:36:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 3:36:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/9/2018 3:29:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 3:25:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 256e9f3c-3bdc-11e8-ae76-204747d02364
Report Status: 0"
Information	4/9/2018 3:12:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 3:07:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 3:07:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28967)(?)])(1 )(2 )]

"
Information	4/9/2018 3:07:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28967)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 3:07:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 3:07:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 3:07:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 3:04:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 2:59:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 2:59:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28975)(?)])(1 )(2 )]

"
Information	4/9/2018 2:59:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 2:59:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 2:59:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 2:59:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 2:55:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 2:50:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 2:50:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28984)(?)])(1 )(2 )]

"
Information	4/9/2018 2:50:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28984)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 2:50:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 2:50:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 2:50:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 2:21:48 PM	MTAService.OnSessionChange	0	None	2:21:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/9/2018 2:16:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 2:15:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 2:15:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 1:58:01 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/9/2018 1:57:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 1:18:29 PM	MTAService.OnSessionChange	0	None	1:18:29 PM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29107)(?)])(1 )(2 )]

"
Information	4/9/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 12:24:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 12:24:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:12Z. Reason: GVLK.
Information	4/9/2018 12:19:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/9/2018 12:19:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 12:19:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 12:19:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 12:14:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8857.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/9/2018 12:04:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 11:45:41 AM	MTAService.OnSessionChange	0	None	11:45:41 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/9/2018 11:31:27 AM	MTAService.OnSessionChange	0	None	11:31:27 AM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 11:24:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 11:24:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:37Z. Reason: GVLK.
Information	4/9/2018 11:19:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/9/2018 11:19:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 11:19:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 11:19:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/9/2018 11:05:01 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	4/9/2018 10:59:22 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/9/2018 10:59:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/9/2018 10:59:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/9/2018 10:47:37 AM	MTAService.OnSessionChange	0	None	10:47:37 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/9/2018 10:47:13 AM	MTAService.OnSessionChange	0	None	10:47:13 AM - Session change notice received: SessionLock Session ID: 1
Information	4/9/2018 10:37:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/9/2018 10:37:56 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/9/2018 10:32:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 10:32:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:17Z. Reason: GVLK.
Information	4/9/2018 10:31:58 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 10:30:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/9/2018 10:29:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/9/2018 10:28:42 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 9, Compared: 21092, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/9/2018 10:27:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/9/2018 10:27:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 10:27:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 10:27:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 10:26:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/9/2018 10:26:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29248)(?)])(1 )(2 )]

"
Information	4/9/2018 10:26:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29248)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 10:26:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/9/2018 10:26:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 10:26:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/9/2018 10:26:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/9/2018 10:26:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:58Z. Reason: GVLK.
Error	4/9/2018 10:25:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/9/2018 10:25:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3aeb1e1d-3bb2-11e8-ae76-204747d02364
Report Status: 0"
Information	4/9/2018 10:20:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/9/2018 10:20:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/9/2018 10:20:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/9/2018 10:20:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/9/2018 10:19:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	4/9/2018 10:17:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/9/2018 10:16:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 10:16:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/9/2018 10:15:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/9/2018 10:15:35 AM	MTAService.OnSessionChange	0	None	10:15:35 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/9/2018 10:15:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	4/9/2018 10:15:31 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/9/2018 10:15:27 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	4/9/2018 10:15:27 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/6/2018 7:45:47 PM	MTAService.OnSessionChange	0	None	7:45:47 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 7:39:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 7:33:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:33:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33020)(?)])(1 )(2 )]

"
Information	4/6/2018 7:33:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33020)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:33:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:33:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33021)(?)])(1 )(2 )]

"
Information	4/6/2018 7:33:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33021)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:33:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 7:33:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 7:33:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/6/2018 7:31:43 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/6/2018 7:31:31 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/6/2018 7:29:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 7:24:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:24:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33030)(?)])(1 )(2 )]

"
Information	4/6/2018 7:24:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33030)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:23:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:23:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33031)(?)])(1 )(2 )]

"
Information	4/6/2018 7:23:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33031)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:22:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:22:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33032)(?)])(1 )(2 )]

"
Information	4/6/2018 7:22:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33032)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:20:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 7:20:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33034)(?)])(1 )(2 )]

"
Information	4/6/2018 7:20:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33034)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 7:20:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 7:20:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 7:20:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 7:08:11 PM	MTAService.OnSessionChange	0	None	7:08:11 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/6/2018 6:48:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 6:40:06 PM	MTAService.OnSessionChange	0	None	6:40:06 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 6:38:44 PM	MTAService.OnSessionChange	0	None	6:38:44 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 5:51:39 PM	MTAService.OnSessionChange	0	None	5:51:39 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 5:29:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 5:28:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 5:11:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 5:06:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 5:06:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33168)(?)])(1 )(2 )]

"
Information	4/6/2018 5:06:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33168)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 5:06:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 5:06:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 5:06:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 5:03:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 4:58:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 4:58:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33176)(?)])(1 )(2 )]

"
Information	4/6/2018 4:58:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33176)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 4:58:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 4:58:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 4:58:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/6/2018 4:52:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 4:47:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 4:42:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 4:42:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33192)(?)])(1 )(2 )]

"
Information	4/6/2018 4:42:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33192)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 4:39:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 4:39:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33195)(?)])(1 )(2 )]

"
Information	4/6/2018 4:39:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33195)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 4:39:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 4:39:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33195)(?)])(1 )(2 )]

"
Information	4/6/2018 4:39:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33195)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 3:37:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4d399de2-3982-11e8-ae76-204747d02364
Report Status: 0"
Information	4/6/2018 3:30:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 3:30:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 3:30:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 3:28:39 PM	MTAService.OnSessionChange	0	None	3:28:39 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 3:21:00 PM	MTAService.OnSessionChange	0	None	3:21:00 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/6/2018 3:03:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 2:55:07 PM	MTAService.OnSessionChange	0	None	2:55:07 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 2:06:00 PM	MTAService.OnSessionChange	0	None	2:06:00 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 2:04:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 1:59:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 1:59:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33355)(?)])(1 )(2 )]

"
Information	4/6/2018 1:59:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33355)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 1:57:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 1:57:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 1:57:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 1:52:33 PM	MTAService.OnSessionChange	0	None	1:52:33 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 1:35:58 PM	MTAService.OnSessionChange	0	None	1:35:58 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 1:35:03 PM	MTAService.OnSessionChange	0	None	1:35:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 1:29:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 1:28:46 PM	MTAService.OnSessionChange	0	None	1:28:46 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 1:28:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 1:26:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 1:26:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:51Z. Reason: GVLK.
Warning	4/6/2018 1:23:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 1:21:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/6/2018 1:21:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 1:21:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 1:21:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 1:04:46 PM	MTAService.OnSessionChange	0	None	1:04:46 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 12:54:40 PM	MTAService.OnSessionChange	0	None	12:54:40 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 12:52:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 12:50:18 PM	MTAService.OnSessionChange	0	None	12:50:18 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 12:49:42 PM	MTAService.OnSessionChange	0	None	12:49:42 PM - Session change notice received: SessionLock Session ID: 1
Information	4/6/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33427)(?)])(1 )(2 )]

"
Information	4/6/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33427)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 12:46:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8854.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/6/2018 11:37:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 11:31:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 11:26:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 11:26:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33508)(?)])(1 )(2 )]

"
Information	4/6/2018 11:25:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33508)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 11:25:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 11:25:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 11:25:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/6/2018 11:15:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/6/2018 10:43:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 10:38:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 10:38:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33556)(?)])(1 )(2 )]

"
Information	4/6/2018 10:38:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33556)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 10:37:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 637adac0-3958-11e8-ae76-204747d02364
Report Status: 0"
Information	4/6/2018 10:37:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/6/2018 10:37:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33557)(?)])(1 )(2 )]

"
Information	4/6/2018 10:37:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33557)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 10:37:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/6/2018 10:37:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 10:37:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/6/2018 10:28:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/6/2018 10:28:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/6/2018 10:11:56 AM	MTAService.OnSessionChange	0	None	10:11:56 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/6/2018 9:47:38 AM	MTAService.OnSessionChange	0	None	9:47:38 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/6/2018 9:45:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 9:33:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/6/2018 9:33:58 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/6/2018 9:28:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 9:28:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 9:15:09 AM	MTAService.OnSessionChange	0	None	9:15:09 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/6/2018 7:55:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/6/2018 6:01:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 5:37:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79d8ca9d-392e-11e8-ae76-204747d02364
Report Status: 0"
Information	4/6/2018 5:28:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 5:28:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 5:14:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/6/2018 5:14:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:06Z. Reason: GVLK.
Information	4/6/2018 5:09:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/6/2018 5:09:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/6/2018 5:09:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/6/2018 5:09:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/6/2018 4:01:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/6/2018 2:15:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/6/2018 1:28:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 1:28:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 1:28:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/6/2018 12:37:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9026a2a4-3904-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/6/2018 12:29:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	4/5/2018 10:30:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 9:59:21 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	4/5/2018 9:58:32 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	4/5/2018 9:28:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 9:28:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 9:27:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 9:04:45 PM	MTAService.OnSessionChange	0	None	9:04:45 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 9:02:32 PM	MTAService.OnSessionChange	0	None	9:02:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 8:59:28 PM	MTAService.OnSessionChange	0	None	8:59:28 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/5/2018 8:33:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 7:37:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a64da462-38da-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/5/2018 6:39:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 6:32:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 6:27:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 6:27:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34527)(?)])(1 )(2 )]

"
Information	4/5/2018 6:27:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34527)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 6:23:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 6:23:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 6:23:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 6:11:45 PM	MTAService.OnSessionChange	0	None	6:11:45 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 5:58:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/5/2018 5:31:08 PM	MTAService.OnSessionChange	0	None	5:31:08 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 5:28:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 5:27:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 5:01:06 PM	MTAService.OnSessionChange	0	None	5:01:06 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/5/2018 4:56:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 4:54:07 PM	MTAService.OnSessionChange	0	None	4:54:07 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 4:17:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 4:12:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 4:12:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34662)(?)])(1 )(2 )]

"
Information	4/5/2018 4:12:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34662)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 4:12:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 4:12:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 4:12:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 4:11:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 4:06:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 4:06:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34668)(?)])(1 )(2 )]

"
Information	4/5/2018 4:06:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34668)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 4:04:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 4:04:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34670)(?)])(1 )(2 )]

"
Information	4/5/2018 4:04:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34670)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 4:04:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 4:04:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 4:04:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 4:03:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 3:58:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 3:58:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34676)(?)])(1 )(2 )]

"
Information	4/5/2018 3:58:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34676)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 3:37:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 3:37:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 3:37:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 3:06:50 PM	MTAService.OnSessionChange	0	None	3:06:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/5/2018 2:59:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 2:45:13 PM	MTAService.OnSessionChange	0	None	2:45:13 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 2:37:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc9c489c-38b0-11e8-ae76-204747d02364
Report Status: 0"
Information	4/5/2018 2:21:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34778)(?)])(1 )(2 )]

"
Information	4/5/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34778)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 2:16:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34778)(?)])(1 )(2 )]

"
Information	4/5/2018 2:16:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34778)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 2:15:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 2:15:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34779)(?)])(1 )(2 )]

"
Information	4/5/2018 2:15:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34779)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 2:15:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 2:15:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 2:15:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 2:13:19 PM	MTAService.OnSessionChange	0	None	2:13:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 2:07:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 2:02:25 PM	MTAService.OnSessionChange	0	None	2:02:25 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 2:02:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 2:02:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34792)(?)])(1 )(2 )]

"
Information	4/5/2018 2:02:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34792)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 2:02:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 2:02:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 2:02:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 1:53:13 PM	MTAService.OnSessionChange	0	None	1:53:13 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 1:28:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 1:28:09 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/5/2018 1:27:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 1:10:50 PM	MTAService.OnSessionChange	0	None	1:10:50 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/5/2018 1:04:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34867)(?)])(1 )(2 )]

"
Information	4/5/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34867)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 12:31:02 PM	MTAService.OnSessionChange	0	None	12:31:02 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 12:26:45 PM	MTAService.OnSessionChange	0	None	12:26:45 PM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 12:17:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8853.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Warning	4/5/2018 11:24:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 11:04:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 10:59:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:59:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34975)(?)])(1 )(2 )]

"
Information	4/5/2018 10:59:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:58:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:58:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:58:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34976)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:58:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 10:58:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 10:58:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 10:50:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 10:45:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:45:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34989)(?)])(1 )(2 )]

"
Information	4/5/2018 10:45:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34989)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:45:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 10:45:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 10:45:45 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/5/2018 10:28:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/5/2018 10:18:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 10:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35021)(?)])(1 )(2 )]

"
Information	4/5/2018 10:13:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35021)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:11:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:11:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35023)(?)])(1 )(2 )]

"
Information	4/5/2018 10:11:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35023)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:10:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:10:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35023)(?)])(1 )(2 )]

"
Information	4/5/2018 10:10:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35023)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:10:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:10:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35024)(?)])(1 )(2 )]

"
Information	4/5/2018 10:10:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35024)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:09:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:09:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35025)(?)])(1 )(2 )]

"
Information	4/5/2018 10:09:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35025)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:08:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:08:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35026)(?)])(1 )(2 )]

"
Information	4/5/2018 10:08:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35026)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:08:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 10:08:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35026)(?)])(1 )(2 )]

"
Information	4/5/2018 10:08:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35026)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 10:08:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 10:08:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 10:08:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 10:08:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	4/5/2018 10:03:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 9:58:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 9:58:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35036)(?)])(1 )(2 )]

"
Information	4/5/2018 9:58:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35036)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 9:57:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 9:57:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35037)(?)])(1 )(2 )]

"
Information	4/5/2018 9:57:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35037)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 9:57:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 9:57:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 9:57:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 9:55:11 AM	MTAService.OnSessionChange	0	None	9:55:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/5/2018 9:43:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/5/2018 9:43:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/5/2018 9:43:49 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	4/5/2018 9:42:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/5/2018 9:38:30 AM	MTAService.OnSessionChange	0	None	9:38:30 AM - Session change notice received: SessionLock Session ID: 1
Information	4/5/2018 9:37:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/5/2018 9:37:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35057)(?)])(1 )(2 )]

"
Information	4/5/2018 9:37:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35057)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/5/2018 9:37:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/5/2018 9:37:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/5/2018 9:37:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/5/2018 9:37:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2e099f3-3886-11e8-ae76-204747d02364
Report Status: 0"
Warning	4/5/2018 9:29:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/5/2018 9:27:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 9:27:38 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/5/2018 9:27:38 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/5/2018 9:27:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/5/2018 9:27:25 AM	MTAService.OnSessionChange	0	None	9:27:25 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2018 9:39:16 PM	MTAService.OnSessionChange	0	None	9:39:16 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/4/2018 9:26:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 7:56:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 7:51:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 7:51:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35883)(?)])(1 )(2 )]

"
Information	4/4/2018 7:51:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35883)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 7:51:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 7:51:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 7:51:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 7:48:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 7:43:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 7:43:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35891)(?)])(1 )(2 )]

"
Information	4/4/2018 7:43:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35891)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 7:42:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 7:42:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35892)(?)])(1 )(2 )]

"
Information	4/4/2018 7:42:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35892)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 7:42:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 7:42:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 7:42:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2018 7:28:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 7:12:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 145dc77d-380e-11e8-ae76-204747d02364
Report Status: 0"
Information	4/4/2018 7:01:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2018 6:02:30 PM	MTAService.OnSessionChange	0	None	6:02:30 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2018 5:56:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	4/4/2018 5:49:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 5:17:21 PM	MTAService.OnSessionChange	0	None	5:17:21 PM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2018 5:13:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 5:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 5:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36046)(?)])(1 )(2 )]

"
Information	4/4/2018 5:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36046)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 5:08:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 5:08:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 5:08:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2018 3:51:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 3:00:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2018 2:15:50 PM	MTAService.OnSessionChange	0	None	2:15:50 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/4/2018 2:13:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 2:12:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 29caa038-37e4-11e8-ae76-204747d02364
Report Status: 0"
Information	4/4/2018 1:35:31 PM	MTAService.OnSessionChange	0	None	1:35:31 PM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2018 12:58:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	4/4/2018 12:53:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 12:51:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	4/4/2018 12:47:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36307)(?)])(1 )(2 )]

"
Information	4/4/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36307)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 12:47:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2018 12:35:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 12:34:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 12:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36325)(?)])(1 )(2 )]

"
Information	4/4/2018 12:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36325)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:28:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:28:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36326)(?)])(1 )(2 )]

"
Information	4/4/2018 12:28:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36326)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:28:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 12:28:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 12:28:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 12:26:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 12:21:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:21:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36333)(?)])(1 )(2 )]

"
Information	4/4/2018 12:21:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36333)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:20:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:20:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36334)(?)])(1 )(2 )]

"
Information	4/4/2018 12:20:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36334)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:20:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:20:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36334)(?)])(1 )(2 )]

"
Information	4/4/2018 12:20:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36334)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:18:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 12:18:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36336)(?)])(1 )(2 )]

"
Information	4/4/2018 12:18:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36336)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 12:18:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 12:18:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 12:18:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 12:09:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8852.0000
 
 Number of signatures in EXTRA.DAT : 10
 Names of threats that EXTRA.DAT can detect : Generic.Tra!0965cf41e461 (ED)
Generic.Tra!28dc8550ab76 (ED)
Generic.Tra!339f02063c8e (ED)
Generic.Tra!377be29c27eb (ED)
Generic.Tra!3b2e52bcee15 (ED)
Generic.Tra!49b2e542a7ed (ED)
Generic.Tra!645898897c21 (ED)
Generic.Tra!985d44beb9e3 (ED)
Generic.Tra!be3afe1ddf0b (ED)
Generic.Tra!f9e86a6b416b (ED)
"
Information	4/4/2018 11:58:11 AM	MTAService.OnSessionChange	0	None	11:58:11 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2018 11:34:11 AM	MTAService.OnSessionChange	0	None	11:34:11 AM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2018 11:07:46 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 2, Deleted: 1, Modified: 2, Compared: 20686, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/4/2018 11:05:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 11:00:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/4/2018 11:00:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/4/2018 11:00:05 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 702

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1045

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 390

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 32

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 499

Information	4/4/2018 10:59:00 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	4/4/2018 10:58:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 10:58:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36415)(?)])(1 )(2 )]

"
Information	4/4/2018 10:58:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36415)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:58:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 10:58:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 10:58:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/4/2018 10:58:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/4/2018 10:57:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 10:57:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:13:25Z. Reason: GVLK.
Information	4/4/2018 10:52:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 10:52:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2018 10:52:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:52:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 10:52:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 10:48:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 10:48:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-11T05:12:29Z. Reason: GVLK.
Information	4/4/2018 10:47:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 10:47:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36427)(?)])(1 )(2 )]

"
Information	4/4/2018 10:47:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36427)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:46:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 10:46:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36428)(?)])(1 )(2 )]

"
Information	4/4/2018 10:46:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36428)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:46:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 10:46:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 10:46:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 10:43:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:43:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:43:28 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/04/04 05:13"
Information	4/4/2018 10:43:28 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/04/04 05:13, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	4/4/2018 10:39:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 10:34:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 10:34:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36440)(?)])(1 )(2 )]

"
Information	4/4/2018 10:34:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36440)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:34:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 10:34:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 10:34:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	4/4/2018 10:28:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/4/2018 10:24:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2018 10:24:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 10:24:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 10:24:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 10:08:26 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8852.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	4/4/2018 10:03:05 AM	MTAService.OnSessionChange	0	None	10:03:05 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/4/2018 9:59:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 9:59:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:39Z. Reason: GVLK.
Information	4/4/2018 9:54:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2018 9:54:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 9:54:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 9:54:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 9:52:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 9:52:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:31Z. Reason: GVLK.
Information	4/4/2018 9:47:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2018 9:47:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 9:47:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 9:47:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/4/2018 9:41:38 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	4/4/2018 9:33:04 AM	MTAService.OnSessionChange	0	None	9:33:04 AM - Session change notice received: SessionLock Session ID: 1
Information	4/4/2018 9:29:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 9:29:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:42Z. Reason: GVLK.
Error	4/4/2018 9:17:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/4/2018 9:16:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/4/2018 9:15:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	4/4/2018 9:15:12 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	4/4/2018 9:12:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3fe629bf-37ba-11e8-ae76-204747d02364
Report Status: 0"
Information	4/4/2018 9:11:53 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	4/4/2018 9:11:48 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {00B78E28-1141-4297-A671-8778350AB73A}
Error	4/4/2018 9:11:48 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {00B78E28-1141-4297-A671-8778350AB73A}
Error	4/4/2018 9:11:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/4/2018 9:11:28 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	4/4/2018 9:11:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/4/2018 9:11:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36523)(?)])(1 )(2 )]

"
Information	4/4/2018 9:11:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36523)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 9:11:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/4/2018 9:11:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 9:11:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 9:10:51 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/4/2018 9:10:50 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/4/2018 9:10:49 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/4/2018 9:10:46 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/4/2018 9:10:17 AM	ESENT	302	Logging/Recovery	Windows (7736) Windows: The database engine has successfully completed recovery steps.
Information	4/4/2018 9:10:10 AM	ESENT	301	Logging/Recovery	Windows (7736) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/4/2018 9:10:10 AM	ESENT	300	Logging/Recovery	Windows (7736) Windows: The database engine is initiating recovery steps.
Information	4/4/2018 9:10:10 AM	ESENT	102	General	Windows (7736) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/4/2018 9:09:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/4/2018 9:09:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/4/2018 9:09:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/4/2018 9:09:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/4/2018 9:09:48 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8851.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	4/4/2018 9:09:25 AM	Service1	0	None	Service started successfully.
Information	4/4/2018 9:09:23 AM	MTAService	0	None	Service started successfully.
Error	4/4/2018 9:09:21 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/4/2018 9:09:20 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/4/2018 9:09:18 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/4/2018 9:09:07 AM	PostgreSQL	0	None	"2018-04-04 09:09:07 IST LOG:  redirecting log output to logging collector process
2018-04-04 09:09:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/4/2018 9:09:05 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	4/4/2018 9:09:05 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/4/2018 9:09:04 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/4/2018 9:09:01 AM	MTAService.OnStart	0	None	9:09:01 AM - User is already logged in : 212558710
Information	4/4/2018 9:09:00 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/4/2018 9:08:55 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:55 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/4/2018 9:08:55 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/4/2018 9:08:55 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/4/2018 9:08:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/4/2018 9:08:54 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/4/2018 9:08:53 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/4/2018 9:08:53 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/4/2018 9:08:53 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/4/2018 9:08:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/4/2018 9:08:52 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:52 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/4/2018 9:08:52 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/4/2018 9:08:52 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/4/2018 9:08:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/4/2018 9:08:52 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	4/4/2018 9:08:52 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/4/2018 9:08:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/4/2018 9:08:52 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/4/2018 9:08:47 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:47 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:47 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/4/2018 9:08:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/4/2018 9:08:46 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:46 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/4/2018 9:08:46 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/4/2018 9:08:45 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/4/2018 9:08:45 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/4/2018 9:08:45 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:45 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:45 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3912 at 4/2/2018 9:37:10 AM (local) 4/2/2018 4:07:10 AM (UTC). This is an informational message only; no user action is required.
Information	4/4/2018 9:08:44 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/4/2018 9:08:42 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/4/2018 9:08:42 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/4/2018 9:08:42 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/4/2018 9:08:42 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/4/2018 9:08:42 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4376.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/4/2018 9:08:41 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/4/2018 9:08:04 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/4/2018 9:07:59 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/4/2018 9:07:46 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/4/2018 9:07:47 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/4/2018 9:07:46 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	4/3/2018 8:24:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 7:24:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c871d57-3746-11e8-9123-ec114151b318
Report Status: 0"
Warning	4/3/2018 6:27:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 6:14:12 PM	MTAService.OnSessionChange	0	None	6:14:12 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 5:14:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2018 5:14:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2018 5:13:53 PM	MTAService.OnSessionChange	0	None	5:13:53 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2018 5:12:14 PM	MTAService.OnSessionChange	0	None	5:12:14 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 5:12:05 PM	MTAService.OnSessionChange	0	None	5:12:05 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/3/2018 4:41:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 4:18:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/3/2018 4:13:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/3/2018 4:13:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37541)(?)])(1 )(2 )]

"
Information	4/3/2018 4:13:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37541)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 4:13:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/3/2018 4:13:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 4:13:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/3/2018 3:34:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/3/2018 3:29:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/3/2018 3:29:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37585)(?)])(1 )(2 )]

"
Information	4/3/2018 3:29:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 3:29:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/3/2018 3:29:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 3:29:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/3/2018 3:12:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2018 3:12:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:45Z. Reason: GVLK.
Information	4/3/2018 3:07:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2018 3:07:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 3:07:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 3:07:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	4/3/2018 2:42:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 2:34:49 PM	MTAService.OnSessionChange	0	None	2:34:49 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 2:24:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 929e417a-371c-11e8-9123-ec114151b318
Report Status: 0"
Information	4/3/2018 2:06:37 PM	MTAService.OnSessionChange	0	None	2:06:37 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2018 1:42:15 PM	MTAService.OnSessionChange	0	None	1:42:15 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 1:25:59 PM	MTAService.OnSessionChange	0	None	1:25:59 PM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2018 1:14:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2018 1:14:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	4/3/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	4/3/2018 12:47:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/3/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37747)(?)])(1 )(2 )]

"
Information	4/3/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37747)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/3/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/3/2018 12:22:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8851.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	4/3/2018 11:52:28 AM	MTAService.OnSessionChange	0	None	11:52:28 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 11:32:52 AM	MTAService.OnSessionChange	0	None	11:32:52 AM - Session change notice received: SessionLock Session ID: 1
Information	4/3/2018 11:30:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	4/3/2018 11:30:26 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	4/3/2018 11:06:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	4/3/2018 10:12:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	4/3/2018 10:12:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/3/2018 9:48:50 AM	MTAService.OnSessionChange	0	None	9:48:50 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/3/2018 9:44:38 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	4/3/2018 9:36:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2018 9:36:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:21Z. Reason: GVLK.
Information	4/3/2018 9:31:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2018 9:31:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 9:31:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 9:31:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/3/2018 9:31:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/3/2018 9:31:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:10Z. Reason: GVLK.
Information	4/3/2018 9:26:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/3/2018 9:26:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/3/2018 9:26:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/3/2018 9:26:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/3/2018 9:24:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8e44140-36f2-11e8-9123-ec114151b318
Report Status: 0"
Information	4/3/2018 9:24:06 AM	MTAService.OnSessionChange	0	None	9:24:06 AM - Session change notice received: SessionLock Session ID: 1
Warning	4/3/2018 9:16:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/3/2018 9:14:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/3/2018 9:14:10 AM	MTAService.OnSessionChange	0	None	9:14:10 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 8:27:18 PM	MTAService.OnSessionChange	0	None	8:27:18 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 7:41:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b0bd59c4-367f-11e8-9123-204747d02364
Report Status: 0"
Warning	4/2/2018 7:37:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 7:22:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 7:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 7:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38797)(?)])(1 )(2 )]

"
Information	4/2/2018 7:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38797)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 7:13:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 7:13:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38801)(?)])(1 )(2 )]

"
Information	4/2/2018 7:13:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38801)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 7:13:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 7:13:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 7:13:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 6:19:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2018 6:19:43 PM	MTAService.OnSessionChange	0	None	6:19:43 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	4/2/2018 5:51:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 5:38:18 PM	MTAService.OnSessionChange	0	None	5:38:18 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 4:44:31 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	4/2/2018 4:41:53 PM	MTAService.OnSessionChange	0	None	4:41:53 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 4:16:58 PM	MTAService.OnSessionChange	0	None	4:16:58 PM - Session change notice received: SessionLock Session ID: 1
Warning	4/2/2018 3:56:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 3:10:48 PM	MTAService.OnSessionChange	0	None	3:10:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 3:06:56 PM	MTAService.OnSessionChange	0	None	3:06:56 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 2:41:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c7006584-3655-11e8-9123-204747d02364
Report Status: 0"
Information	4/2/2018 2:19:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2018 2:19:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	4/2/2018 2:13:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 1:49:19 PM	MTAService.OnSessionChange	0	None	1:49:19 PM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 1:32:29 PM	MTAService.OnSessionChange	0	None	1:32:29 PM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39187)(?)])(1 )(2 )]

"
Information	4/2/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39187)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 12:27:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 12:22:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 12:22:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39212)(?)])(1 )(2 )]

"
Information	4/2/2018 12:22:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39212)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 12:19:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 12:19:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39215)(?)])(1 )(2 )]

"
Information	4/2/2018 12:19:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39215)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 12:19:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 12:19:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 12:19:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/2/2018 12:13:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 12:10:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8850.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	4/2/2018 11:54:09 AM	MTAService.OnSessionChange	0	None	11:54:09 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 11:48:09 AM	MTAService.OnSessionChange	0	None	11:48:09 AM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 11:00:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 11:00:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:22Z. Reason: GVLK.
Information	4/2/2018 10:55:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 10:55:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:55:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 10:55:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	4/2/2018 10:54:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/2/2018 10:51:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:51:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:35Z. Reason: GVLK.
Information	4/2/2018 10:46:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 10:46:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:46:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 10:46:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 10:30:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:30:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:23Z. Reason: GVLK.
Information	4/2/2018 10:26:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:25:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 10:25:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:25:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 10:25:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 10:21:53 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 49, Deleted: 0, Modified: 11, Compared: 20659, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/2/2018 10:21:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 10:21:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39333)(?)])(1 )(2 )]

"
Information	4/2/2018 10:21:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39333)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:20:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 10:20:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39334)(?)])(1 )(2 )]

"
Information	4/2/2018 10:20:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39334)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:19:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/2/2018 10:19:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2236.
Information	4/2/2018 10:19:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2018 10:19:53 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	4/2/2018 10:19:52 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 250

Information	4/2/2018 10:19:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	4/2/2018 10:19:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 10:19:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39335)(?)])(1 )(2 )]

"
Information	4/2/2018 10:19:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39335)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:19:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	4/2/2018 10:19:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 10:19:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 10:19:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	4/2/2018 10:16:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	4/2/2018 10:14:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Monday, March 26, 2018 11:42:10 PM.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=EC-ACC, OU=Jerarquia Entitats de Certificacio Catalanes, OU=Vegeu https://www.catcert.net/verarrel (c)03, OU=Serveis Publics de Certificacio, O=Agencia Catalana de Certificacio (NIF Q-0801176-I), C=ES> Sha1 thumbprint: <28903A635B5280FAE6774C0B6DA7D6BAA64AF2E8>.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=Starfield Services Root Certificate Authority, OU=http://certificates.starfieldtech.com/repository/, O=""Starfield Technologies, Inc."", L=Scottsdale, S=Arizona, C=US> Sha1 thumbprint: <5D003860F002ED829DEAA41868F788186D62127F>."
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=Class 3 Public Primary Certification Authority, O=""VeriSign, Inc."", C=US> Sha1 thumbprint: <742C3192E607E424EB4549542BE1BBC53E6174E2>."
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=CA Disig Root R1, O=Disig a.s., L=Bratislava, C=SK> Sha1 thumbprint: <8E1C74F8A620B9E58AF461FAEC2B4756511A52C6>.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=NetLock Kozjegyzoi (Class A) Tanusitvanykiado, OU=Tanusitvanykiadok, O=NetLock Halozatbiztonsagi Kft., L=Budapest, S=Hungary, C=HU> Sha1 thumbprint: <ACED5F6553FD25CE015F1F7A483B6A749F6178C6>.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=LuxTrust Global Root, O=LuxTrust s.a., C=LU> Sha1 thumbprint: <C93C34EA90D9130C0F03004B98BD8B3570915611>.
Information	4/2/2018 10:14:31 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=Security Communication EV RootCA1, O=""SECOM Trust Systems CO.,LTD."", C=JP> Sha1 thumbprint: <FEB8C432DCF9769ACEAE3DD8908FFD288665647D>."
Information	4/2/2018 10:09:22 AM	MTAService.OnSessionChange	0	None	10:09:22 AM - Session change notice received: SessionUnlock Session ID: 1
Information	4/2/2018 10:07:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:07:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:11Z. Reason: GVLK.
Information	4/2/2018 10:02:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 10:02:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 10:02:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 10:02:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 10:01:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:00:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 10:00:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:20Z. Reason: GVLK.
Error	4/2/2018 9:59:40 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Error	4/2/2018 9:56:47 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	4/2/2018 9:56:47 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7B1E0E2D-383D-45D3-8D7A-464A3B91A9E0}
Error	4/2/2018 9:56:47 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7B1E0E2D-383D-45D3-8D7A-464A3B91A9E0}
Information	4/2/2018 9:56:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 9:56:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39358)(?)])(1 )(2 )]

"
Information	4/2/2018 9:56:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39358)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 9:56:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 9:56:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 9:56:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 9:56:37 AM	MTAService.OnSessionChange	0	None	9:56:37 AM - Session change notice received: SessionLock Session ID: 1
Information	4/2/2018 9:55:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 9:55:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 9:55:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 9:55:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 9:52:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	4/2/2018 9:52:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:15Z. Reason: GVLK.
Information	4/2/2018 9:46:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	4/2/2018 9:45:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/2/2018 9:43:42 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	4/2/2018 9:43:42 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	4/2/2018 9:41:32 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C4D53390-634B-45B0-B46F-42282D1CE4FC}
Error	4/2/2018 9:41:32 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C4D53390-634B-45B0-B46F-42282D1CE4FC}
Error	4/2/2018 9:41:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	4/2/2018 9:41:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	4/2/2018 9:41:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39373)(?)])(1 )(2 )]

"
Information	4/2/2018 9:41:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39373)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 9:41:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	4/2/2018 9:41:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 9:41:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 9:40:04 AM	MTAService.OnSessionChange	0	None	9:40:04 AM - Logon : 212558710
Information	4/2/2018 9:40:04 AM	MTAService.OnSessionChange	0	None	9:40:04 AM - Session change notice received: SessionLogon Session ID: 1
Information	4/2/2018 9:40:03 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	4/2/2018 9:40:03 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	4/2/2018 9:40:03 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	4/2/2018 9:40:03 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	4/2/2018 9:40:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	4/2/2018 9:40:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	4/2/2018 9:40:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	4/2/2018 9:39:59 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	4/2/2018 9:39:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	4/2/2018 9:39:56 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/2/2018 9:39:55 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/2/2018 9:39:54 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/2/2018 9:38:14 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	4/2/2018 9:38:11 AM	ESENT	302	Logging/Recovery	Windows (6552) Windows: The database engine has successfully completed recovery steps.
Information	4/2/2018 9:38:10 AM	ESENT	301	Logging/Recovery	Windows (6552) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	4/2/2018 9:38:09 AM	ESENT	301	Logging/Recovery	Windows (6552) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS005FD.log.
Information	4/2/2018 9:38:09 AM	ESENT	300	Logging/Recovery	Windows (6552) Windows: The database engine is initiating recovery steps.
Information	4/2/2018 9:38:09 AM	ESENT	102	General	Windows (6552) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	4/2/2018 9:37:52 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8848.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	4/2/2018 9:37:46 AM	Service1	0	None	Service started successfully.
Error	4/2/2018 9:37:41 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	4/2/2018 9:37:41 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	4/2/2018 9:37:36 AM	PostgreSQL	0	None	Server started and accepting connections

Information	4/2/2018 9:37:35 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	4/2/2018 9:37:35 AM	PostgreSQL	0	None	"2018-04-02 09:37:35 IST LOG:  redirecting log output to logging collector process
2018-04-02 09:37:35 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	4/2/2018 9:37:33 AM	PostgreSQL	0	None	Waiting for server startup...

Information	4/2/2018 9:37:32 AM	MTAService	0	None	Service started successfully.
Information	4/2/2018 9:37:32 AM	MTAService.OnStart	0	None	9:37:31 AM - Waiting for user to Logon
Information	4/2/2018 9:37:32 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	4/2/2018 9:37:22 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	4/2/2018 9:37:21 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:21 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	4/2/2018 9:37:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	4/2/2018 9:37:21 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	4/2/2018 9:37:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	4/2/2018 9:37:20 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	4/2/2018 9:37:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	4/2/2018 9:37:18 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	4/2/2018 9:37:18 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	4/2/2018 9:37:10 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3908 at 3/31/2018 3:32:38 PM (local) 3/31/2018 10:02:38 AM (UTC). This is an informational message only; no user action is required.
Information	4/2/2018 9:37:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	4/2/2018 9:37:08 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	4/2/2018 9:37:08 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	4/2/2018 9:37:08 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	4/2/2018 9:37:08 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3912.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	4/2/2018 9:37:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	4/2/2018 9:36:32 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	4/2/2018 9:36:23 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	4/2/2018 9:36:07 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	4/2/2018 9:36:08 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	4/2/2018 9:36:07 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/31/2018 3:32:45 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Warning	3/31/2018 3:32:37 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 948 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 6784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/31/2018 3:32:39 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	3/31/2018 3:32:38 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	3/31/2018 3:32:38 PM	McLogEvent	257	None	The scan of C:\Windows\System32\en-US\KERNELBASE.dll.mui has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8848.0000.
Information	3/31/2018 3:32:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/31/2018 3:32:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/31/2018 3:32:36 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	3/31/2018 3:32:33 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	3/31/2018 3:16:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 692386d2-34c8-11e8-ba4f-08002700381d
Report Status: 0"
Information	3/31/2018 12:52:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/31/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42067)(?)])(1 )(2 )]

"
Information	3/31/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42067)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 12:47:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 12:09:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8848.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/31/2018 12:02:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 12:02:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:28Z. Reason: GVLK.
Information	3/31/2018 11:57:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 11:57:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 11:57:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 11:57:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 11:32:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 11:32:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:29Z. Reason: GVLK.
Information	3/31/2018 11:27:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 11:27:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 11:27:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 11:27:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 11:02:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 11:02:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:28Z. Reason: GVLK.
Information	3/31/2018 10:57:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 10:57:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:57:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:57:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:48:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:47:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:47:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:41Z. Reason: GVLK.
Error	3/31/2018 10:43:02 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DCAB6AF1-4F65-476D-80E8-9842520793C1}
Error	3/31/2018 10:43:02 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DCAB6AF1-4F65-476D-80E8-9842520793C1}
Error	3/31/2018 10:42:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/31/2018 10:42:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/31/2018 10:42:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/31/2018 10:42:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42192)(?)])(1 )(2 )]

"
Information	3/31/2018 10:42:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42192)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:42:50 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2018 10:42:50 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:42:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/31/2018 10:42:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/31/2018 10:42:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 10:42:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:42:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:42:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:42:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/31/2018 10:42:11 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/31/2018 10:42:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/31/2018 10:42:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/31/2018 10:32:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:32:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:32:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:34Z. Reason: GVLK.
Error	3/31/2018 10:27:37 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	3/31/2018 10:27:37 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {693BA211-A42A-4F98-BAFD-9EE270516E2A}
Error	3/31/2018 10:27:37 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {693BA211-A42A-4F98-BAFD-9EE270516E2A}
Information	3/31/2018 10:27:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/31/2018 10:27:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42207)(?)])(1 )(2 )]

"
Information	3/31/2018 10:27:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42207)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:27:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2018 10:27:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:27:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:27:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 10:27:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:27:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:27:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:26:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:21:25 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:25 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8431.2236. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/31/2018 10:21:25 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	3/31/2018 10:21:24 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/31/2018 10:21:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42213)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:21:21 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/31/2018 10:21:21 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/31/2018 10:21:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:21:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2018 10:21:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:21:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:21:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:21:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/31/2018 10:21:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:12Z. Reason: GVLK.
Information	3/31/2018 10:21:09 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:09 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:08 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2236. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/31/2018 10:21:08 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	3/31/2018 10:21:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2236. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/31/2018 10:21:06 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	3/31/2018 10:21:02 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/31/2018 10:21:01 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:01 AM	ESENT	102	General	Windows (7788) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/31/2018 10:21:01 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:21:01 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2236. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/31/2018 10:21:01 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	3/31/2018 10:20:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:20:44 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	3/31/2018 10:20:44 AM	ESENT	103	General	Windows (7868) Windows: The database engine stopped the instance (0).
Information	3/31/2018 10:20:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:20:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2236. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/31/2018 10:20:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	3/31/2018 10:19:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 7836.
Information	3/31/2018 10:19:14 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/31/2018 10:19:14 AM	ESENT	102	General	Windows (7868) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/31/2018 10:19:11 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	3/31/2018 10:19:11 AM	ESENT	103	General	Windows (6532) Windows: The database engine stopped the instance (0).
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:10 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:09 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:09 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	3/31/2018 10:19:09 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:09 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:19:09 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	3/31/2018 10:18:57 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/31/2018 10:18:55 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/31/2018 10:18:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	3/31/2018 10:18:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	3/31/2018 10:18:17 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	3/31/2018 10:18:17 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	3/31/2018 10:18:17 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	3/31/2018 10:18:16 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	3/31/2018 10:18:15 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	3/31/2018 10:18:14 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	3/31/2018 10:18:13 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	3/31/2018 10:18:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	3/31/2018 10:18:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/31/2018 10:18:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:18:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:17:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎31T04:47:23.166893000Z.
Warning	3/31/2018 10:15:36 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 88 second(s) to handle the notification event (CreateSession).
Information	3/31/2018 10:15:22 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	3/31/2018 10:15:16 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/31/2018 10:15:15 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/31/2018 10:15:13 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	3/31/2018 10:15:07 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	3/31/2018 10:14:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/31/2018 10:14:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/31/2018 10:14:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/31/2018 10:14:07 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	3/31/2018 10:14:06 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	3/31/2018 10:14:06 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	3/31/2018 10:14:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/31/2018 10:13:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/31/2018 10:13:58 AM	ESENT	302	Logging/Recovery	Windows (6532) Windows: The database engine has successfully completed recovery steps.
Information	3/31/2018 10:13:52 AM	ESENT	301	Logging/Recovery	Windows (6532) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/31/2018 10:13:52 AM	ESENT	300	Logging/Recovery	Windows (6532) Windows: The database engine is initiating recovery steps.
Information	3/31/2018 10:13:52 AM	ESENT	102	General	Windows (6532) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/31/2018 10:13:12 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8846.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/31/2018 10:12:37 AM	Service1	0	None	Service started successfully.
Error	3/31/2018 10:12:18 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/31/2018 10:12:17 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/31/2018 10:11:58 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/31/2018 10:11:56 AM	PostgreSQL	0	None	Server started and accepting connections

Information	3/31/2018 10:11:54 AM	PostgreSQL	0	None	"2018-03-31 10:11:54 IST LOG:  redirecting log output to logging collector process
2018-03-31 10:11:54 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/31/2018 10:11:50 AM	PostgreSQL	0	None	Waiting for server startup...

Information	3/31/2018 10:11:49 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:49 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/31/2018 10:11:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/31/2018 10:11:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/31/2018 10:11:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/31/2018 10:11:47 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/31/2018 10:11:47 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:46 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/31/2018 10:11:46 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/31/2018 10:11:46 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/31/2018 10:11:46 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/31/2018 10:11:45 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:44 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/31/2018 10:11:43 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/31/2018 10:11:43 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/31/2018 10:11:43 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/31/2018 10:11:42 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/31/2018 10:11:39 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:39 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/31/2018 10:11:37 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/31/2018 10:11:37 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:37 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/31/2018 10:11:37 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/31/2018 10:11:36 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/31/2018 10:11:36 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3872 at 3/31/2018 10:02:58 AM (local) 3/31/2018 4:32:58 AM (UTC). This is an informational message only; no user action is required.
Information	3/31/2018 10:11:32 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/31/2018 10:11:30 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/31/2018 10:11:30 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/31/2018 10:11:30 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/31/2018 10:11:30 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3908.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/31/2018 10:11:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/31/2018 10:10:13 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/31/2018 10:10:02 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/31/2018 10:07:12 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/31/2018 10:07:13 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/31/2018 10:07:12 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/31/2018 10:03:11 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	3/31/2018 10:02:58 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	3/31/2018 9:56:22 AM	MTAService.OnSessionChange	0	None	9:56:21 AM - Logoff
Warning	3/31/2018 9:56:17 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 37 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 11620 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 11620 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 11620 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 11620 (\Device\HarddiskVolume1\Program Files\MTA\Controller\MTA.Controller.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 2016 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/31/2018 9:56:21 AM	MTAService.OnSessionChange	0	None	9:56:21 AM - Session change notice received: SessionLogoff Session ID: 1
Information	3/31/2018 9:56:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/31/2018 9:56:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/31/2018 9:56:15 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	3/31/2018 9:55:48 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	3/31/2018 9:55:32 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/31/2018 9:55:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/31/2018 9:55:13 AM	MTAService.OnSessionChange	0	None	9:55:13 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/31/2018 9:55:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/31/2018 9:55:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/31/2018 9:55:07 AM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Information	3/29/2018 7:59:38 PM	MTAService.OnSessionChange	0	None	7:59:38 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2018 7:59:25 PM	MTAService.OnSessionChange	0	None	7:59:25 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 7:58:45 PM	MTAService.OnSessionChange	0	None	7:58:45 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2018 7:51:48 PM	MTAService.OnSessionChange	0	None	7:51:48 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 7:30:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8d348cb7-3359-11e8-91eb-204747d02364
Report Status: 0"
Information	3/29/2018 7:21:11 PM	MTAService.OnSessionChange	0	None	7:21:11 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2018 6:58:10 PM	MTAService.OnSessionChange	0	None	6:58:10 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 6:53:13 PM	MTAService.OnSessionChange	0	None	6:53:13 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/29/2018 6:20:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2018 5:47:05 PM	MTAService.OnSessionChange	0	None	5:47:05 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 5:20:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/29/2018 5:20:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/29/2018 4:57:54 PM	MTAService.OnSessionChange	0	None	4:57:54 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2018 4:49:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/29/2018 4:44:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:44:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44710)(?)])(1 )(2 )]

"
Information	3/29/2018 4:44:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44710)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:43:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:43:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44711)(?)])(1 )(2 )]

"
Information	3/29/2018 4:43:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44711)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:42:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:42:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44712)(?)])(1 )(2 )]

"
Information	3/29/2018 4:42:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44712)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:41:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:41:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44713)(?)])(1 )(2 )]

"
Information	3/29/2018 4:41:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44713)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:41:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/29/2018 4:41:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2018 4:41:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/29/2018 4:40:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/29/2018 4:35:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:35:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44719)(?)])(1 )(2 )]

"
Information	3/29/2018 4:35:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44719)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	3/29/2018 4:35:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2018 4:35:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44719)(?)])(1 )(2 )]

"
Information	3/29/2018 4:35:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44719)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:34:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:34:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44720)(?)])(1 )(2 )]

"
Information	3/29/2018 4:34:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44720)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:34:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:34:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44720)(?)])(1 )(2 )]

"
Information	3/29/2018 4:34:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44720)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:30:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:30:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44724)(?)])(1 )(2 )]

"
Information	3/29/2018 4:30:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44724)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:29:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:29:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44725)(?)])(1 )(2 )]

"
Information	3/29/2018 4:29:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44725)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:28:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:28:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44726)(?)])(1 )(2 )]

"
Information	3/29/2018 4:28:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44726)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:28:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:28:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44726)(?)])(1 )(2 )]

"
Information	3/29/2018 4:28:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44726)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:27:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44727)(?)])(1 )(2 )]

"
Information	3/29/2018 4:27:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44727)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:26:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:26:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44728)(?)])(1 )(2 )]

"
Information	3/29/2018 4:26:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44728)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]

"
Information	3/29/2018 4:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:25:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:25:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]

"
Information	3/29/2018 4:25:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:24:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:24:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]

"
Information	3/29/2018 4:24:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44729)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:24:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:24:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44730)(?)])(1 )(2 )]

"
Information	3/29/2018 4:24:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44730)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:23:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:23:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44731)(?)])(1 )(2 )]

"
Information	3/29/2018 4:23:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44731)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:23:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:22:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44731)(?)])(1 )(2 )]

"
Information	3/29/2018 4:22:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44731)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:22:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:22:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44732)(?)])(1 )(2 )]

"
Information	3/29/2018 4:22:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44732)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44733)(?)])(1 )(2 )]

"
Information	3/29/2018 4:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44733)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:17:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:17:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44737)(?)])(1 )(2 )]

"
Information	3/29/2018 4:17:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44737)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:16:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:16:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44738)(?)])(1 )(2 )]

"
Information	3/29/2018 4:16:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44738)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:15:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:15:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44739)(?)])(1 )(2 )]

"
Information	3/29/2018 4:15:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44739)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:14:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:14:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44740)(?)])(1 )(2 )]

"
Information	3/29/2018 4:14:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44740)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:14:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:14:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44740)(?)])(1 )(2 )]

"
Information	3/29/2018 4:14:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44740)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:12:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:12:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44742)(?)])(1 )(2 )]

"
Information	3/29/2018 4:12:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44742)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:11:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44743)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:11:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44743)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:11:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/29/2018 4:11:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/29/2018 4:11:17 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	3/29/2018 4:10:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 4:10:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44744)(?)])(1 )(2 )]

"
Information	3/29/2018 4:10:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44744)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 4:10:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/29/2018 4:10:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2018 4:10:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/29/2018 3:57:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	3/29/2018 2:41:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2018 2:30:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a384dd7e-332f-11e8-91eb-204747d02364
Report Status: 0"
Information	3/29/2018 2:13:03 PM	MTAService.OnSessionChange	0	None	2:13:03 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 1:59:17 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/29/2018 1:58:43 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/29/2018 1:27:06 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/29/2018 1:20:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/29/2018 1:00:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2018 12:59:22 PM	MTAService.OnSessionChange	0	None	12:59:22 PM - Session change notice received: SessionLock Session ID: 1
Information	3/29/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/29/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44947)(?)])(1 )(2 )]

"
Information	3/29/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44947)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 12:31:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8846.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/29/2018 12:21:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/29/2018 12:19:46 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/29/2018 12:07:01 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/29/2018 11:52:41 AM	MTAService.OnSessionChange	0	None	11:52:41 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 11:32:17 AM	MTAService.OnSessionChange	0	None	11:32:17 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/29/2018 11:19:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/29/2018 10:35:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/29/2018 10:17:07 AM	MTAService.OnSessionChange	0	None	10:17:07 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 9:58:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2018 9:58:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:03Z. Reason: GVLK.
Information	3/29/2018 9:53:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2018 9:53:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 9:53:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2018 9:53:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/29/2018 9:50:46 AM	MTAService.OnSessionChange	0	None	9:50:46 AM - Session change notice received: SessionLock Session ID: 1
Error	3/29/2018 9:47:11 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/29/2018 9:30:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b914f6b2-3305-11e8-91eb-204747d02364
Report Status: 0"
Information	3/29/2018 9:29:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/29/2018 9:29:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:13:16Z. Reason: GVLK.
Error	3/29/2018 9:24:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/29/2018 9:24:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/29/2018 9:24:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/29/2018 9:24:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/29/2018 9:24:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/29/2018 9:22:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/29/2018 9:21:34 AM	MTAService.OnSessionChange	0	None	9:21:34 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/29/2018 9:20:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/28/2018 9:40:22 PM	MTAService.OnSessionChange	0	None	9:40:22 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2018 9:04:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7fd9884a-329d-11e8-91eb-204747d02364
Report Status: 0"
Information	3/28/2018 8:59:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 8:57:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/28/2018 8:49:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/28/2018 7:16:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 6:18:49 PM	MTAService.OnSessionChange	0	None	6:18:49 PM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/28/2018 5:42:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 5:01:04 PM	MTAService.OnSessionChange	0	None	5:01:04 PM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2018 4:59:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 4:59:26 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/28/2018 4:59:25 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 1420

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1467

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1544

Information	3/28/2018 4:57:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 4:56:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2018 4:56:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46138)(?)])(1 )(2 )]

"
Information	3/28/2018 4:56:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46138)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 4:04:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 961c6c55-3273-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/28/2018 4:03:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 4:00:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 4:00:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:30Z. Reason: GVLK.
Information	3/28/2018 3:55:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 3:55:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 3:55:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 3:55:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/28/2018 2:24:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 2:24:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:50Z. Reason: GVLK.
Information	3/28/2018 2:22:27 PM	MTAService.OnSessionChange	0	None	2:22:27 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/28/2018 2:19:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 2:19:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 2:19:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 2:19:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/28/2018 2:08:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 1:15:12 PM	MTAService.OnSessionChange	0	None	1:15:07 PM - Session change notice received: SessionLock Session ID: 1
Error	3/28/2018 12:52:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/28/2018 12:52:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2018 12:48:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/28/2018 12:48:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46386)(?)])(1 )(2 )]

"
Information	3/28/2018 12:48:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46386)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 12:42:28 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 10749 milliseconds
Information	3/28/2018 12:42:10 PM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8845.0000.
Information	3/28/2018 12:14:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/28/2018 12:14:07 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	3/28/2018 12:13:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 12:07:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/28/2018 12:02:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8845.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/28/2018 11:53:02 AM	MTAService.OnSessionChange	0	None	11:53:02 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/28/2018 11:31:53 AM	MTAService.OnSessionChange	0	None	11:31:53 AM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2018 11:04:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac38ec17-3249-11e8-91eb-204747d02364
Report Status: 0"
Information	3/28/2018 10:48:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 10:48:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-04-04T05:12:25Z. Reason: GVLK.
Information	3/28/2018 10:43:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 10:43:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 10:43:25 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/03/28 05:13"
Information	3/28/2018 10:43:24 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/03/28 05:13, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/28/2018 10:38:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 10:38:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 10:38:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 10:38:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/28/2018 10:35:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/28/2018 10:18:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 10:01:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 10:01:06 AM	MTAService.OnSessionChange	0	None	10:01:06 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/28/2018 9:34:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/28/2018 9:34:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/28/2018 9:34:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/28/2018 9:33:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 20629, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/28/2018 9:32:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/28/2018 9:32:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/28/2018 9:27:19 AM	MTAService.OnSessionChange	0	None	9:27:19 AM - Session change notice received: SessionLock Session ID: 1
Information	3/28/2018 9:12:12 AM	MTAService.OnSessionChange	0	None	9:12:12 AM - Session change notice received: SessionUnlock Session ID: 1
Warning	3/28/2018 8:19:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/28/2018 6:25:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 6:04:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c28076be-321f-11e8-91eb-204747d02364
Report Status: 0"
Information	3/28/2018 6:01:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 4:46:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 4:46:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:20Z. Reason: GVLK.
Information	3/28/2018 4:41:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 4:41:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 4:41:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 4:41:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/28/2018 4:38:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/28/2018 4:38:11 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/28/2018 4:30:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 4:30:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:15Z. Reason: GVLK.
Error	3/28/2018 4:25:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/28/2018 4:25:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 4:25:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 4:25:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 4:25:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/28/2018 2:59:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 2:05:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/28/2018 2:05:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:50Z. Reason: GVLK.
Information	3/28/2018 2:01:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/28/2018 2:00:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/28/2018 2:00:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/28/2018 2:00:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/28/2018 2:00:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/28/2018 1:04:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8b86d9e-31f5-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/28/2018 1:01:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/28/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/27/2018 11:06:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 10:01:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 9:54:21 PM	MTAService.OnSessionChange	0	None	9:54:21 PM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2018 9:26:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 8:04:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eeff2378-31cb-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/27/2018 7:55:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 7:46:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 7:46:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47408)(?)])(1 )(2 )]

"
Information	3/27/2018 7:46:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47408)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 7:37:08 PM	MTAService.OnSessionChange	0	None	7:37:08 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 7:36:05 PM	MTAService.OnSessionChange	0	None	7:36:05 PM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2018 6:43:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 6:43:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47471)(?)])(1 )(2 )]

"
Information	3/27/2018 6:43:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47471)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 6:40:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 6:40:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47474)(?)])(1 )(2 )]

"
Information	3/27/2018 6:40:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47474)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	3/27/2018 6:06:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 6:01:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 5:35:32 PM	MTAService.OnSessionChange	0	None	5:35:32 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 5:14:07 PM	MTAService.OnSessionChange	0	None	5:14:07 PM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2018 4:29:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 4:29:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:10Z. Reason: GVLK.
Information	3/27/2018 4:24:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 4:24:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 4:24:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 4:24:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/27/2018 4:06:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 3:54:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 3:54:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 3:54:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 3:04:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 054378a2-31a2-11e8-91eb-204747d02364
Report Status: 0"
Information	3/27/2018 2:19:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	3/27/2018 2:18:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 2:13:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 2:13:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47741)(?)])(1 )(2 )]

"
Information	3/27/2018 2:13:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47741)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 2:12:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47742)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 2:12:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47742)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 2:12:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/27/2018 2:12:16 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/27/2018 2:12:15 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	3/27/2018 2:12:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 2:12:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 2:12:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 2:05:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 2:00:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 2:00:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	3/27/2018 2:00:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 2:00:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47754)(?)])(1 )(2 )]

"
Information	3/27/2018 2:00:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47754)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 2:00:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 2:00:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 2:00:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 1:55:54 PM	MTAService.OnSessionChange	0	None	1:55:54 PM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 12:55:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8844.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/27/2018 12:53:03 PM	MTAService.OnSessionChange	0	None	12:53:03 PM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47827)(?)])(1 )(2 )]

"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47827)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/27/2018 12:41:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 12:37:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 12:32:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47842)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 12:32:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47842)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 12:32:31 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/27/2018 12:32:31 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/27/2018 12:32:31 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	3/27/2018 12:27:45 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 656

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 546

Information	3/27/2018 12:27:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/27/2018 12:27:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 12:27:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47847)(?)])(1 )(2 )]

"
Information	3/27/2018 12:27:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47847)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 12:27:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 12:27:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 12:27:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 12:19:15 PM	PostgreSQL	0	None	Server started and accepting connections

Information	3/27/2018 12:19:14 PM	PostgreSQL	0	None	"2018-03-27 12:19:14 IST LOG:  redirecting log output to logging collector process
2018-03-27 12:19:14 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/27/2018 12:19:13 PM	PostgreSQL	0	None	Waiting for server startup...

Information	3/27/2018 12:05:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/27/2018 12:05:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/27/2018 12:05:06 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/27/2018 11:19:52 AM	MTAService.OnSessionChange	0	None	11:19:52 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 11:19:21 AM	MTAService.OnSessionChange	0	None	11:19:21 AM - Session change notice received: SessionLock Session ID: 1
Warning	3/27/2018 10:52:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/27/2018 10:35:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/27/2018 10:19:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 10:14:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:14:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47980)(?)])(1 )(2 )]

"
Information	3/27/2018 10:14:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47980)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:13:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:13:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47981)(?)])(1 )(2 )]

"
Information	3/27/2018 10:13:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47981)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:13:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:13:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47981)(?)])(1 )(2 )]

"
Information	3/27/2018 10:13:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47981)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:12:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:12:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47982)(?)])(1 )(2 )]

"
Information	3/27/2018 10:12:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47982)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:11:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:11:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47983)(?)])(1 )(2 )]

"
Information	3/27/2018 10:11:55 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47983)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:10:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:10:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47984)(?)])(1 )(2 )]

"
Information	3/27/2018 10:10:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47984)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:06:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 10:06:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47988)(?)])(1 )(2 )]

"
Information	3/27/2018 10:06:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47988)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 10:06:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 10:06:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 10:06:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 10:04:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b7ca802-3178-11e8-91eb-204747d02364
Report Status: 0"
Information	3/27/2018 9:58:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 9:58:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 9:57:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 9:57:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 9:56:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 9:51:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 9:51:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48003)(?)])(1 )(2 )]

"
Information	3/27/2018 9:51:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48003)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 9:51:49 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 9:51:49 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 9:51:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 9:42:55 AM	MTAService.OnSessionChange	0	None	9:42:55 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 9:37:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 9:37:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:22Z. Reason: GVLK.
Information	3/27/2018 9:32:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 9:32:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 9:32:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 9:32:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/27/2018 9:28:00 AM	MTAService.OnSessionChange	0	None	9:28:00 AM - Session change notice received: SessionLock Session ID: 1
Information	3/27/2018 9:16:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 9:11:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/27/2018 9:11:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48043)(?)])(1 )(2 )]

"
Information	3/27/2018 9:11:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48043)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 9:11:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/27/2018 9:11:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 9:11:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/27/2018 8:57:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/27/2018 8:57:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 8:34:05 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/27/2018 8:27:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/27/2018 8:27:28 AM	MTAService.OnSessionChange	0	None	8:27:26 AM - Session change notice received: SessionUnlock Session ID: 1
Information	3/27/2018 7:21:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 7:21:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:21Z. Reason: GVLK.
Information	3/27/2018 7:16:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 7:16:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 7:16:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 7:16:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/27/2018 7:15:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 5:58:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 5:57:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 5:57:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 5:37:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 5:37:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:53Z. Reason: GVLK.
Information	3/27/2018 5:33:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎03‎-‎27T00:03:08.807062100Z.
Information	3/27/2018 5:32:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 5:32:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 5:32:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 5:32:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/27/2018 5:23:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 5:04:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31e084bc-314e-11e8-91eb-204747d02364
Report Status: 0"
Information	3/27/2018 4:15:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 4:15:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:46Z. Reason: GVLK.
Information	3/27/2018 4:10:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 4:10:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 4:10:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 4:10:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/27/2018 4:01:49 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/27/2018 4:00:09 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	3/27/2018 4:00:03 AM	GE Software	0	(1)	++No Reboot requested by Hive_HiveStreaming_2017.1.308_20.04.2017_V01
Information	3/27/2018 4:00:00 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	3/27/2018 4:00:00 AM	GE Software	0	(1)	Updating Pactrack registry keys with hive_hivestreaming_2017.1.308_20.04.2017_v01
Information	3/27/2018 4:00:00 AM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Information	3/27/2018 4:00:00 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	3/27/2018 3:59:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎26T22:29:18.446082300Z.
Information	3/27/2018 3:59:50 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Options\Packages\Hive_HiveStreaming_2017.1.308_20.04.2017_V01\hive_service_setup.msi. Client Process Id: 21192.
Information	3/27/2018 3:59:49 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Hive Streaming. Product Version: 17.1.308.308. Product Language: 1033. Manufacturer: Hive Streaming AB. Installation success or error status: 0.
Information	3/27/2018 3:59:49 AM	MsiInstaller	11707	None	Product: Hive Streaming -- Installation completed successfully.
Information	3/27/2018 3:59:18 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎26T22:29:18.446082300Z.
Information	3/27/2018 3:59:16 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Options\Packages\Hive_HiveStreaming_2017.1.308_20.04.2017_V01\hive_service_setup.msi. Client Process Id: 21192.
Information	3/27/2018 3:59:15 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	3/27/2018 3:59:15 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/27/2018 3:59:14 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/27/2018 3:59:12 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Hive_HiveStreaming_2017.1.308_20.04.2017_V01\hive_hivestreaming_2017.1.308_20.04.2017_v01.exe with the following commandline: /Q /NOCHECK
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Hive_HiveStreaming_2017.1.308_20.04.2017_V01
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Installation Check - PRODUCT_GUID nor PRODUCT_ARPKEY variables are set; therefore, we will skip the check to see if this program is already installed on the system.
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++ Hive_HiveStreaming_2017.1.308_20.04.2017_V01 was launched using the following Command line: /Q
Information	3/27/2018 3:59:07 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	3/27/2018 3:59:06 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	3/27/2018 3:59:06 AM	GE Software	0	(1)	++ The installation of hive_hivestreaming_2017.1.308_20.04.2017_v01.exe was launched with the following Command Line Switches: /Q
Information	3/27/2018 3:52:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/27/2018 3:52:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:30Z. Reason: GVLK.
Error	3/27/2018 3:47:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/27/2018 3:47:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/27/2018 3:47:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/27/2018 3:47:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/27/2018 3:47:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/27/2018 3:36:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 1:58:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 1:57:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/27/2018 1:57:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/27/2018 1:37:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/27/2018 12:04:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 48115053-3124-11e8-91eb-204747d02364
Report Status: 0"
Information	3/27/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/26/2018 11:49:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/26/2018 10:17:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 9:58:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 9:57:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 9:57:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2018 8:20:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 7:04:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5e6ad8a2-30fa-11e8-91eb-204747d02364
Report Status: 0"
Error	3/26/2018 6:56:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/26/2018 6:30:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 5:58:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 5:57:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 5:29:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 5:29:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:26Z. Reason: GVLK.
Information	3/26/2018 5:24:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2018 5:24:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 5:24:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 5:24:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/26/2018 4:48:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 3:30:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 3:30:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:23Z. Reason: GVLK.
Information	3/26/2018 3:25:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2018 3:25:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 3:25:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 3:25:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/26/2018 3:10:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 2:04:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74cf36b2-30d0-11e8-91eb-204747d02364
Report Status: 0"
Information	3/26/2018 1:58:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 1:57:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2018 1:14:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 12:52:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49267)(?)])(1 )(2 )]

"
Information	3/26/2018 12:47:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49267)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 12:47:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/26/2018 12:47:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 12:47:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/26/2018 12:17:03 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8843.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/26/2018 12:07:24 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/26/2018 11:20:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 9:58:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 9:57:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2018 9:36:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 9:04:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b0109c5-30a6-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/26/2018 7:36:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 6:08:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/26/2018 5:57:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 5:56:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2018 5:54:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/26/2018 4:14:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 4:04:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a14c89fb-307c-11e8-91eb-204747d02364
Report Status: 0"
Information	3/26/2018 3:44:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 3:44:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:00Z. Reason: GVLK.
Information	3/26/2018 3:39:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2018 3:39:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 3:39:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 3:38:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/26/2018 3:31:03 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/26/2018 3:18:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 3:18:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:42Z. Reason: GVLK.
Error	3/26/2018 3:14:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/26/2018 3:13:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2018 3:13:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 3:13:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 3:13:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2018 2:41:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/26/2018 2:41:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:50Z. Reason: GVLK.
Warning	3/26/2018 2:37:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 2:36:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/26/2018 2:36:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/26/2018 2:36:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/26/2018 2:36:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/26/2018 1:57:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/26/2018 1:56:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/26/2018 12:44:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/26/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/25/2018 11:04:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b77bf173-3052-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/25/2018 10:51:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 9:57:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 9:56:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/25/2018 8:51:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/25/2018 7:18:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/25/2018 6:56:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/25/2018 6:17:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2018 6:17:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:50Z. Reason: GVLK.
Information	3/25/2018 6:12:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2018 6:12:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2018 6:12:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2018 6:12:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2018 6:04:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cdbedc95-3028-11e8-91eb-204747d02364
Report Status: 0"
Information	3/25/2018 5:56:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 5:56:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 5:55:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/25/2018 5:41:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/25/2018 3:57:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/25/2018 2:24:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 1:56:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:56:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:55:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:55:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/25/2018 1:55:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:04:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e40812cc-2ffe-11e8-91eb-204747d02364
Report Status: 0"
Information	3/25/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/25/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/25/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50707)(?)])(1 )(2 )]

"
Information	3/25/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50707)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/25/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/25/2018 12:31:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8842.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Warning	3/25/2018 12:28:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/25/2018 10:30:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 9:56:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 9:56:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 9:55:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 9:32:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/25/2018 9:32:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/25/2018 9:32:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/25/2018 9:31:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 20588, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/25/2018 9:30:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/25/2018 9:30:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/25/2018 9:30:09 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/25/2018 9:30:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	3/25/2018 8:38:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 8:04:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fa348ecc-2fd4-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/25/2018 6:49:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 5:56:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 5:55:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 5:55:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 5:55:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/25/2018 5:01:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 4:35:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2018 4:35:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:11Z. Reason: GVLK.
Information	3/25/2018 4:30:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2018 4:30:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2018 4:30:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2018 4:30:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/25/2018 4:27:10 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/25/2018 4:19:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2018 4:19:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:39Z. Reason: GVLK.
Error	3/25/2018 4:14:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/25/2018 4:14:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2018 4:14:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2018 4:14:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2018 4:14:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2018 3:32:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/25/2018 3:17:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/25/2018 3:17:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:30Z. Reason: GVLK.
Information	3/25/2018 3:12:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎03‎-‎24T21:42:45.937625300Z.
Information	3/25/2018 3:12:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/25/2018 3:12:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/25/2018 3:12:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/25/2018 3:12:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/25/2018 3:04:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1086ecff-2fab-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/25/2018 3:02:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 1:56:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:55:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/25/2018 1:55:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/25/2018 1:16:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/25/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/24/2018 11:20:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 10:03:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 26b1f99f-2f81-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 9:56:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 9:55:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 9:55:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/24/2018 9:49:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 9:35:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 9:35:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:26Z. Reason: GVLK.
Information	3/24/2018 9:30:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 9:30:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 9:30:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 9:30:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/24/2018 8:01:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/24/2018 6:56:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/24/2018 6:23:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 5:55:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 5:55:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 5:03:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d17de4f-2f57-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/24/2018 4:46:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/24/2018 2:58:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 2:44:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 2:44:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:39Z. Reason: GVLK.
Information	3/24/2018 2:39:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 2:39:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 2:39:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 2:39:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 1:55:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 1:55:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 1:55:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/24/2018 1:25:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 12:52:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/24/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52147)(?)])(1 )(2 )]

"
Information	3/24/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52147)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/24/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 12:12:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8841.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/24/2018 12:03:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53415617-2f2d-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/24/2018 11:34:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 9:55:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 9:55:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/24/2018 9:47:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 8:21:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 8:21:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:28Z. Reason: GVLK.
Information	3/24/2018 8:16:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 8:16:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 8:16:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 8:16:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 8:14:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 59
P9: {D6D80A6B-675E-4CE1-8CDC-AB21B323D0A9}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 476deaa1-2f0d-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 8:14:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 8:14:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:06Z. Reason: GVLK.
Information	3/24/2018 8:09:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 8:09:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 8:09:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 8:09:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/24/2018 7:54:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 7:51:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 7:51:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:28Z. Reason: GVLK.
Information	3/24/2018 7:46:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 7:46:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 7:46:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 7:46:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 7:44:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 7:44:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:43Z. Reason: GVLK.
Information	3/24/2018 7:44:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 59
P9: {7F077B0E-507D-4DDF-950A-4D33CA298DB7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 181a6cf1-2f09-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 7:39:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 7:39:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 7:39:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 7:39:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 7:29:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 7:29:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:32Z. Reason: GVLK.
Information	3/24/2018 7:24:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 7:24:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 7:24:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 7:24:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 7:22:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 7:22:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:51Z. Reason: GVLK.
Information	3/24/2018 7:22:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 59
P9: {C4EB7DC1-3247-4508-B89E-8DFED4A1F6C9}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f7d6821-2f06-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 7:17:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 7:17:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 7:17:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 7:17:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 7:03:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69758271-2f03-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/24/2018 6:12:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 6:07:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 6:07:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:14Z. Reason: GVLK.
Information	3/24/2018 6:02:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 6:02:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 6:02:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 6:02:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 6:00:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 59
P9: {8AFDDEA0-953D-4244-BC08-7334B04D91B2}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7db43e61-2efa-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 5:55:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 5:55:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 5:53:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎24T00:21:04.141526600Z.
Information	3/24/2018 5:54:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 7680.
Information	3/24/2018 5:53:59 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	3/24/2018 5:53:59 AM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6.2 -- Configuration completed successfully.
Information	3/24/2018 5:53:59 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4074880. Installation success or error status: 0.
Information	3/24/2018 5:53:59 AM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6.2 - Update 'KB4074880' installed successfully.
Information	3/24/2018 5:53:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 5:53:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:24Z. Reason: GVLK.
Information	3/24/2018 5:52:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:34 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:33 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:32 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:32 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:32 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:31 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:30 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:30 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:21 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 5:52:22 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00009.log
Information	3/24/2018 5:52:16 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 5:52:16 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:12 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	3/24/2018 5:52:10 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00008.log
Information	3/24/2018 5:52:09 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 5:52:06 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 5:52:06 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:52:02 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 5:52:02 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 5:51:52 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	3/24/2018 5:51:42 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:51:41 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 5:51:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎24T00:21:04.141526600Z.
Information	3/24/2018 5:51:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\1d4a4c30.msi. Client Process Id: 7680.
Information	3/24/2018 5:48:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 5:48:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 5:48:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 5:48:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 4:55:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 4:55:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:18Z. Reason: GVLK.
Information	3/24/2018 4:50:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 4:50:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 4:50:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 4:50:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 4:48:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000b
P3: 40E14331-2F87-4618-B57C-C29895B3CD23
P4: Install
P5: 200
P6: 0
P7: 8024000b
P8: Tanium Patch Deployment 59
P9: {DC123350-AD4F-4BE1-8D91-FCEF2E1B82C6}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7521b228-2ef0-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 4:46:13 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/24/2018 4:44:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 4:44:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:31Z. Reason: GVLK.
Information	3/24/2018 4:43:39 AM	MTAService	0	None	Service started successfully.
Information	3/24/2018 4:43:27 AM	MTAService.OnStart	0	None	4:43:25 AM - User is already logged in : 212558710
Information	3/24/2018 4:41:58 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎23T23:01:14.782261900Z.
Information	3/24/2018 4:41:58 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎23T23:03:47.999582100Z.
Information	3/24/2018 4:41:58 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎23T23:00:55.730356900Z.
Information	3/24/2018 4:41:58 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: D:\34c10a1ef020f5f7ed4068c474\netfx_Full_x64.msi. Client Process Id: 16348.
Information	3/24/2018 4:41:58 AM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6.2. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	3/24/2018 4:41:58 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	3/24/2018 4:41:58 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft .NET Framework 4.6.2. Product Version: 4.6.01590. Product Language: 0. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	3/24/2018 4:41:58 AM	MsiInstaller	11707	None	Product: Microsoft .NET Framework 4.6.2 -- Installation completed successfully.
Warning	3/24/2018 4:40:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 4:40:11 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:10 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:08 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:07 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:40:07 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:39:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 4:39:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 4:39:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 4:39:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/24/2018 4:33:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎23T23:03:47.999582100Z.
Information	3/24/2018 4:33:32 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 4:33:33 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00007.log
Information	3/24/2018 4:33:27 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 4:33:27 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:33:23 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	3/24/2018 4:33:22 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 4:33:22 AM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00006.log
Information	3/24/2018 4:33:19 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 4:33:19 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:33:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/24/2018 4:33:13 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/24/2018 4:33:04 AM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	3/24/2018 4:32:57 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:32:56 AM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	3/24/2018 4:32:17 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎23T23:02:17.266509700Z.
Information	3/24/2018 4:32:17 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/24/2018 4:32:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 10888) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2018 4:32:17 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 5408) cannot be restarted - Application SID does not match Conductor SID..
Information	3/24/2018 4:32:17 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll is being used by the following process: Name: RAVBg64 , Id 4956.
Information	3/24/2018 4:32:17 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll is being used by the following process: Name: NetworkAdapterManager , Id 3988.
Information	3/24/2018 4:32:17 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎23T23:02:17.266509700Z.
Information	3/24/2018 4:32:16 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll is being used by the following process: Name: RAVBg64 , Id 4956.
Information	3/24/2018 4:32:16 AM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6.2. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll is being used by the following process: Name: NetworkAdapterManager , Id 3988.
Information	3/24/2018 4:31:36 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎23T23:01:35.772360700Z.
Information	3/24/2018 4:31:35 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/24/2018 4:31:35 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 4956) cannot be restarted - Application SID does not match Conductor SID..
Information	3/24/2018 4:31:35 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎23T23:01:35.772360700Z.
Information	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 10888) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 5408) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 4956) cannot be restarted - Application SID does not match Conductor SID..
Information	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎23T23:01:14.782261900Z.
Information	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft VS Code\resources\app\out\vs\workbench\services\files\node\watcher\win32\CodeHelper.exe' (pid 10888) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 5408) cannot be restarted - Application SID does not match Conductor SID..
Warning	3/24/2018 4:31:14 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 4956) cannot be restarted - Application SID does not match Conductor SID..
Information	3/24/2018 4:30:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎23T23:00:55.730356900Z.
Information	3/24/2018 4:30:55 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: D:\34c10a1ef020f5f7ed4068c474\netfx_Full_x64.msi. Client Process Id: 16348.
Information	3/24/2018 4:10:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 4:10:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:03Z. Reason: GVLK.
Information	3/24/2018 4:05:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 4:05:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 4:05:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 4:05:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/24/2018 4:02:03 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/24/2018 3:54:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/24/2018 3:54:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:21Z. Reason: GVLK.
Error	3/24/2018 3:49:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/24/2018 3:49:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/24/2018 3:49:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/24/2018 3:49:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/24/2018 3:49:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/24/2018 3:07:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 2:03:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7fc27690-2ed9-11e8-91eb-204747d02364
Report Status: 0"
Information	3/24/2018 1:55:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/24/2018 1:54:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/24/2018 1:20:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/24/2018 12:50:48 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/23/2018 11:48:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/23/2018 10:02:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 9:55:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 9:54:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 9:54:52 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/23/2018 9:54:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 9:03:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 962484f5-2eaf-11e8-91eb-204747d02364
Report Status: 0"
Information	3/23/2018 8:43:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 8:43:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:56Z. Reason: GVLK.
Information	3/23/2018 8:38:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 8:38:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 8:38:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 8:38:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2018 8:28:01 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/23/2018 8:26:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 8:17:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 8:17:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:00Z. Reason: GVLK.
Information	3/23/2018 8:12:03 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/23/2018 8:12:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 8:12:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 8:12:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 8:11:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2018 8:09:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 8:09:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:14Z. Reason: GVLK.
Information	3/23/2018 8:04:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 8:04:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 8:04:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 8:04:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/23/2018 6:56:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/23/2018 6:42:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 5:55:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 5:54:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 5:54:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/23/2018 4:59:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 4:36:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 4:36:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:10Z. Reason: GVLK.
Information	3/23/2018 4:31:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 4:31:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 4:31:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 4:31:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2018 4:03:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac588136-2e85-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/23/2018 3:16:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 1:55:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:54:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:54:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:52:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 1:52:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:48Z. Reason: GVLK.
Information	3/23/2018 1:47:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 1:47:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 1:47:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 1:47:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/23/2018 1:29:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/23/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53587)(?)])(1 )(2 )]

"
Information	3/23/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53587)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/23/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/23/2018 12:25:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8840.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!645898897c21 (ED)
"
Information	3/23/2018 12:04:59 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/23/2018 12:04:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/23/2018 12:04:42 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	3/23/2018 11:31:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 11:03:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2795b44-2e5b-11e8-91eb-204747d02364
Report Status: 0"
Information	3/23/2018 9:55:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 9:54:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 9:54:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/23/2018 9:52:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/23/2018 7:52:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 6:21:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 6:21:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:25Z. Reason: GVLK.
Information	3/23/2018 6:16:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 6:16:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 6:16:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 6:16:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/23/2018 6:03:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8bd2f7a-2e31-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/23/2018 5:56:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 5:54:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 5:54:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 5:54:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 4:21:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T22:51:27.566842800Z.
Information	3/23/2018 4:21:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T22:51:26.101842800Z.
Information	3/23/2018 4:21:30 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2159000\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 20116.
Information	3/23/2018 4:21:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T22:51:25.221842800Z.
Information	3/23/2018 4:21:30 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/23/2018 4:21:30 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/23/2018 4:21:29 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/23/2018 4:21:27 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2018 4:21:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2018 4:21:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T22:51:27.566842800Z.
Information	3/23/2018 4:21:27 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2018 4:21:27 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2018 4:21:26 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T22:51:26.101842800Z.
Information	3/23/2018 4:21:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T22:51:25.221842800Z.
Information	3/23/2018 4:21:24 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2159000\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 20116.
Warning	3/23/2018 4:18:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 3:18:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎03‎-‎22T21:48:04.078842800Z.
Information	3/23/2018 3:17:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/23/2018 3:17:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:59Z. Reason: GVLK.
Information	3/23/2018 3:11:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/23/2018 3:11:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/23/2018 3:11:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/23/2018 3:11:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/23/2018 2:28:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/23/2018 1:54:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:54:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:54:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/23/2018 1:50:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T20:20:34.563910800Z.
Information	3/23/2018 1:50:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T20:20:33.615816000Z.
Information	3/23/2018 1:50:37 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T20:20:33.123766800Z.
Information	3/23/2018 1:50:37 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158805\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17716.
Information	3/23/2018 1:50:37 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/23/2018 1:50:37 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/23/2018 1:50:36 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/23/2018 1:50:34 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2018 1:50:34 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2018 1:50:34 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T20:20:34.563910800Z.
Information	3/23/2018 1:50:34 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/23/2018 1:50:34 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/23/2018 1:50:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T20:20:33.615816000Z.
Information	3/23/2018 1:50:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T20:20:33.123766800Z.
Information	3/23/2018 1:50:32 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158805\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17716.
Information	3/23/2018 1:03:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eefd3403-2e07-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/23/2018 12:48:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 11:21:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T17:51:26.567743400Z.
Information	3/22/2018 11:21:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T17:51:25.583743400Z.
Information	3/22/2018 11:21:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158596\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15996.
Information	3/22/2018 11:21:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T17:51:25.170743400Z.
Information	3/22/2018 11:21:29 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 11:21:29 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 11:21:28 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 11:21:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 11:21:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 11:21:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T17:51:26.567743400Z.
Information	3/22/2018 11:21:26 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 11:21:26 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 11:21:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T17:51:25.583743400Z.
Information	3/22/2018 11:21:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T17:51:25.170743400Z.
Information	3/22/2018 11:21:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158596\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 15996.
Warning	3/22/2018 11:17:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 9:54:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 9:54:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 9:54:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/22/2018 9:43:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 8:56:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T15:26:05.420342100Z.
Information	3/22/2018 8:56:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T15:26:04.211221200Z.
Information	3/22/2018 8:56:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T15:26:02.921092200Z.
Information	3/22/2018 8:56:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158387\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8460.
Information	3/22/2018 8:56:08 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 8:56:08 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 8:56:07 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 8:56:05 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 8:56:05 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 8:56:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T15:26:05.420342100Z.
Information	3/22/2018 8:56:05 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 8:56:05 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 8:56:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T15:26:04.211221200Z.
Information	3/22/2018 8:56:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T15:26:02.921092200Z.
Information	3/22/2018 8:56:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158387\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8460.
Warning	3/22/2018 8:10:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 8:09:45 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/22/2018 8:09:08 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/22/2018 8:03:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 05483331-2dde-11e8-91eb-204747d02364
Report Status: 0"
Error	3/22/2018 6:56:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/22/2018 6:36:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 6:20:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T12:50:55.295765600Z.
Information	3/22/2018 6:20:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T12:50:54.331765600Z.
Information	3/22/2018 6:20:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T12:50:53.913765600Z.
Information	3/22/2018 6:20:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158200\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 14612.
Information	3/22/2018 6:20:57 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 6:20:57 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 6:20:56 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 6:20:55 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 6:20:55 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 6:20:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T12:50:55.295765600Z.
Information	3/22/2018 6:20:55 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 6:20:55 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 6:20:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T12:50:54.331765600Z.
Information	3/22/2018 6:20:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T12:50:53.913765600Z.
Information	3/22/2018 6:20:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158200\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 14612.
Information	3/22/2018 5:54:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 5:54:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 5:54:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/22/2018 4:50:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 4:22:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 4:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/22/2018 4:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54817)(?)])(1 )(2 )]

"
Information	3/22/2018 4:17:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54817)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 4:17:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2018 4:17:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 4:17:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/22/2018 3:50:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T10:20:33.799605500Z.
Information	3/22/2018 3:50:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T10:20:32.450470600Z.
Information	3/22/2018 3:50:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158005\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12072.
Information	3/22/2018 3:50:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T10:20:30.560281600Z.
Information	3/22/2018 3:50:36 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 3:50:36 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 3:50:35 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 3:50:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 3:50:33 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 3:50:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T10:20:33.799605500Z.
Information	3/22/2018 3:50:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 3:50:33 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 3:50:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T10:20:32.450470600Z.
Information	3/22/2018 3:50:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T10:20:30.560281600Z.
Information	3/22/2018 3:50:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2158005\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12072.
Information	3/22/2018 3:03:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1af6afa2-2db4-11e8-91eb-204747d02364
Report Status: 0"
Information	3/22/2018 3:03:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 2:58:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/22/2018 2:58:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54896)(?)])(1 )(2 )]

"
Information	3/22/2018 2:58:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54896)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 2:58:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2018 2:58:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 2:58:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/22/2018 2:57:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 2:39:37 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/22/2018 2:30:42 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/22/2018 1:54:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 1:54:34 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/22/2018 1:54:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 1:46:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/22/2018 1:45:45 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/22/2018 1:28:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T07:58:42.976561300Z.
Information	3/22/2018 1:28:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T07:58:40.568320500Z.
Information	3/22/2018 1:28:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2157822\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18848.
Information	3/22/2018 1:28:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T07:58:37.589022600Z.
Information	3/22/2018 1:28:46 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 1:28:46 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 1:28:45 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 1:28:43 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 1:28:43 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 1:28:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T07:58:42.976561300Z.
Information	3/22/2018 1:28:42 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 1:28:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 1:28:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T07:58:40.568320500Z.
Information	3/22/2018 1:28:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T07:58:37.589022600Z.
Information	3/22/2018 1:28:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2157822\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 18848.
Warning	3/22/2018 1:22:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 1:01:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 12:56:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/22/2018 12:56:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55018)(?)])(1 )(2 )]

"
Information	3/22/2018 12:56:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55018)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 12:56:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2018 12:56:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 12:56:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/22/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/22/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]

"
Information	3/22/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55027)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/22/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/22/2018 12:42:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/22/2018 12:06:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8839.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	3/22/2018 11:34:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 10:58:31 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T05:28:24.338242600Z.
Information	3/22/2018 10:58:31 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T05:28:22.674076200Z.
Information	3/22/2018 10:58:30 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎03‎-‎22T05:28:16.310439900Z.
Information	3/22/2018 10:58:31 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2157632\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 6372.
Information	3/22/2018 10:58:30 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.63.16565. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	3/22/2018 10:58:30 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	3/22/2018 10:58:26 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	3/22/2018 10:58:24 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 10:58:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 10:58:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T05:28:24.338242600Z.
Information	3/22/2018 10:58:24 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	3/22/2018 10:58:24 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 11120) cannot be restarted - Application SID does not match Conductor SID..
Information	3/22/2018 10:58:22 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T05:28:22.674076200Z.
Information	3/22/2018 10:58:16 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎03‎-‎22T05:28:16.310439900Z.
Information	3/22/2018 10:58:15 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2157632\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 6372.
Information	3/22/2018 10:28:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/22/2018 10:28:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/22/2018 10:28:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/22/2018 10:28:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/22/2018 10:27:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 10:27:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:08:00Z. Reason: GVLK.
Information	3/22/2018 10:22:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2018 10:22:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 10:22:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 10:21:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/22/2018 10:12:45 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/22/2018 10:03:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3104242d-2d8a-11e8-91eb-204747d02364
Report Status: 0"
Information	3/22/2018 10:02:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/22/2018 10:02:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:28Z. Reason: GVLK.
Information	3/22/2018 9:58:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 6, Deleted: 0, Modified: 2, Compared: 20654, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Error	3/22/2018 9:57:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/22/2018 9:57:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/22/2018 9:57:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/22/2018 9:57:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/22/2018 9:57:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/22/2018 9:55:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/22/2018 9:53:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/22/2018 9:53:35 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	3/21/2018 8:00:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/21/2018 6:56:21 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/21/2018 6:55:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/21/2018 6:55:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/21/2018 6:26:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 5:46:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/21/2018 4:25:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 4:22:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/21/2018 3:55:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3dd4a56d-2cf2-11e8-91eb-204747d02364
Report Status: 0"
Information	3/21/2018 3:42:46 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/21/2018 3:04:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 2:59:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 2:59:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56335)(?)])(1 )(2 )]

"
Information	3/21/2018 2:59:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56335)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 2:59:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 2:59:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 2:59:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 2:47:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 2:42:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 2:42:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56352)(?)])(1 )(2 )]

"
Information	3/21/2018 2:42:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56352)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 2:41:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 2:41:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56353)(?)])(1 )(2 )]

"
Information	3/21/2018 2:41:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56353)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 2:41:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 2:41:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 2:41:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 2:36:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	3/21/2018 2:33:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 2:30:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 2:30:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56364)(?)])(1 )(2 )]

"
Information	3/21/2018 2:30:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56364)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 2:30:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 2:30:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 2:30:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 2:11:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 2:05:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 2:05:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56388)(?)])(1 )(2 )]

"
Information	3/21/2018 2:05:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56388)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 2:05:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 2:05:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 2:05:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 1:46:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 1:46:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 1:29:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 1:24:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 1:24:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56430)(?)])(1 )(2 )]

"
Information	3/21/2018 1:24:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56430)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 1:23:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 1:23:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56430)(?)])(1 )(2 )]

"
Information	3/21/2018 1:23:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56430)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56432)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 1:22:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 1:22:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 1:22:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 1:03:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 1:01:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8838.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/21/2018 12:58:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 12:58:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56456)(?)])(1 )(2 )]

"
Information	3/21/2018 12:58:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56456)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 12:56:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:56:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 12:56:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 12:56:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 12:53:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56467)(?)])(1 )(2 )]

"
Information	3/21/2018 12:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56467)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:47:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 12:47:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 12:47:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/21/2018 12:32:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 12:26:49 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	3/21/2018 11:43:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/21/2018 11:24:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 11:19:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 11:19:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56555)(?)])(1 )(2 )]

"
Information	3/21/2018 11:19:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56555)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 11:19:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 11:19:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 11:19:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 10:58:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 10:55:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53e3a415-2cc8-11e8-91eb-204747d02364
Report Status: 0"
Information	3/21/2018 10:53:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:53:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56581)(?)])(1 )(2 )]

"
Information	3/21/2018 10:53:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56581)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:53:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:53:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56581)(?)])(1 )(2 )]

"
Information	3/21/2018 10:53:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56581)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:52:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:52:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56582)(?)])(1 )(2 )]

"
Information	3/21/2018 10:52:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56582)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:52:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 10:52:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 10:52:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 10:44:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 10:43:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 10:43:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-28T05:07:26Z. Reason: GVLK.
Warning	3/21/2018 10:42:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 10:39:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:39:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56595)(?)])(1 )(2 )]

"
Information	3/21/2018 10:39:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56595)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:38:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:38:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:38:26 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/03/21 05:08"
Information	3/21/2018 10:38:25 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/03/21 05:08, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/21/2018 10:38:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:38:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56596)(?)])(1 )(2 )]

"
Information	3/21/2018 10:38:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56596)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:36:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:36:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56598)(?)])(1 )(2 )]

"
Information	3/21/2018 10:36:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56598)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:33:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:33:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56601)(?)])(1 )(2 )]

"
Information	3/21/2018 10:33:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56601)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:33:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 10:33:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 10:33:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 10:33:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2018 10:33:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:33:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 10:33:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 10:28:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 10:23:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:23:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56611)(?)])(1 )(2 )]

"
Information	3/21/2018 10:23:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56611)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:21:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:21:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56613)(?)])(1 )(2 )]

"
Information	3/21/2018 10:21:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56613)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:20:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:20:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56614)(?)])(1 )(2 )]

"
Information	3/21/2018 10:20:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56614)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:18:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:18:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56616)(?)])(1 )(2 )]

"
Information	3/21/2018 10:18:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56616)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:18:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:18:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56616)(?)])(1 )(2 )]

"
Information	3/21/2018 10:18:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56616)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:17:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:17:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56617)(?)])(1 )(2 )]

"
Information	3/21/2018 10:17:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56617)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:16:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/21/2018 10:16:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56618)(?)])(1 )(2 )]

"
Information	3/21/2018 10:16:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56618)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 10:16:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/21/2018 10:16:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 10:16:30 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 9:58:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 9:58:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:20Z. Reason: GVLK.
Information	3/21/2018 9:53:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2018 9:53:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 9:53:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 9:53:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 9:46:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 9:46:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/21/2018 9:02:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/21/2018 7:12:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 5:55:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a262ef1-2c9e-11e8-91eb-204747d02364
Report Status: 0"
Information	3/21/2018 5:46:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 5:46:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/21/2018 5:28:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 3:51:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 3:51:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:03Z. Reason: GVLK.
Information	3/21/2018 3:46:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2018 3:46:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 3:46:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 3:46:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/21/2018 3:43:08 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	3/21/2018 3:37:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 3:34:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 3:34:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:38Z. Reason: GVLK.
Error	3/21/2018 3:29:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/21/2018 3:29:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2018 3:29:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 3:29:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 3:29:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 3:14:49 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/21/2018 3:14:11 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/21/2018 1:49:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/21/2018 1:46:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 1:46:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/21/2018 12:55:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8065556c-2c74-11e8-91eb-204747d02364
Report Status: 0"
Information	3/21/2018 12:28:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/21/2018 12:28:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:50Z. Reason: GVLK.
Information	3/21/2018 12:23:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/21/2018 12:23:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/21/2018 12:23:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/21/2018 12:23:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/21/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/20/2018 11:58:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/20/2018 9:57:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 9:46:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2018 9:46:05 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/20/2018 9:45:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/20/2018 8:21:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 7:55:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96a38f57-2c4a-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/20/2018 6:43:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 5:45:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2018 5:45:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/20/2018 4:51:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 3:54:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 3:54:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:25Z. Reason: GVLK.
Information	3/20/2018 3:50:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 3:49:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2018 3:49:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:49:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 3:49:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 3:45:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:45:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57729)(?)])(1 )(2 )]

"
Information	3/20/2018 3:45:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57729)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:44:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:44:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57730)(?)])(1 )(2 )]

"
Information	3/20/2018 3:44:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57730)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:44:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 3:44:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 3:44:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 3:19:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 3:14:28 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/20/2018 3:14:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/20/2018 3:14:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:14:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57760)(?)])(1 )(2 )]

"
Information	3/20/2018 3:14:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57760)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:14:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 3:14:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 3:14:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 3:12:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 3:07:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:07:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57767)(?)])(1 )(2 )]

"
Information	3/20/2018 3:07:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57767)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:06:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:06:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 3:06:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57768)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 3:06:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 3:06:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 3:06:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/20/2018 2:57:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 2:55:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: acf09fd6-2c20-11e8-91eb-204747d02364
Report Status: 0"
Information	3/20/2018 2:40:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 2:35:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 2:35:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57799)(?)])(1 )(2 )]

"
Information	3/20/2018 2:35:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57799)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 2:34:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 2:34:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57800)(?)])(1 )(2 )]

"
Information	3/20/2018 2:34:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57800)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 2:34:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 2:34:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 2:34:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 1:45:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/20/2018 1:45:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/20/2018 1:24:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 1:18:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 1:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 1:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57881)(?)])(1 )(2 )]

"
Information	3/20/2018 1:13:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57881)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 1:13:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 1:13:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 1:13:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 1:11:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 1:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 1:06:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57888)(?)])(1 )(2 )]

"
Information	3/20/2018 1:06:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57888)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 1:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 1:02:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57891)(?)])(1 )(2 )]

"
Information	3/20/2018 1:02:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57891)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 1:00:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 1:00:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57894)(?)])(1 )(2 )]

"
Information	3/20/2018 1:00:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57894)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57895)(?)])(1 )(2 )]

"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57895)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 12:59:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 12:52:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57907)(?)])(1 )(2 )]

"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57907)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 12:39:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 12:34:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/20/2018 12:34:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57920)(?)])(1 )(2 )]

"
Information	3/20/2018 12:34:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57920)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 12:34:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/20/2018 12:34:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 12:34:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 12:15:01 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/20/2018 12:07:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8837.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	3/20/2018 11:44:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/20/2018 11:44:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/20/2018 11:43:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 10:25:07 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/20/2018 10:04:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/20/2018 10:04:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:53Z. Reason: GVLK.
Information	3/20/2018 9:56:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/20/2018 9:56:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/20/2018 9:56:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/20/2018 9:56:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/20/2018 9:55:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2ee78c3-2bf6-11e8-91eb-204747d02364
Report Status: 0"
Warning	3/20/2018 9:48:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/20/2018 9:45:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2018 7:09:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 7:04:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 7:04:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58970)(?)])(1 )(2 )]

"
Information	3/19/2018 7:04:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58970)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	3/19/2018 7:01:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 6:59:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:59:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58975)(?)])(1 )(2 )]

"
Information	3/19/2018 6:59:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58975)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:59:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 6:59:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 6:59:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 6:25:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 6:20:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:20:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59014)(?)])(1 )(2 )]

"
Information	3/19/2018 6:20:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59014)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:20:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 6:20:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 6:20:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 6:13:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 6:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59026)(?)])(1 )(2 )]

"
Information	3/19/2018 6:08:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59026)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:07:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:07:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59027)(?)])(1 )(2 )]

"
Information	3/19/2018 6:07:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59027)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:07:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:07:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59027)(?)])(1 )(2 )]

"
Information	3/19/2018 6:07:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59027)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 6:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59029)(?)])(1 )(2 )]

"
Information	3/19/2018 6:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59029)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 6:05:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 6:05:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 6:05:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 5:56:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2018 5:56:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/19/2018 5:05:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 4:20:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8836.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/19/2018 4:04:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 3:59:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 3:59:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59155)(?)])(1 )(2 )]

"
Information	3/19/2018 3:59:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59155)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 3:59:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 3:59:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 3:59:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/19/2018 3:30:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 2:59:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 12a3e752-2b58-11e8-91eb-204747d02364
Report Status: 0"
Information	3/19/2018 2:26:38 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/19/2018 2:03:24 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/19/2018 2:01:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 2:01:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:50Z. Reason: GVLK.
Information	3/19/2018 1:56:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2018 1:56:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/19/2018 1:56:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 1:56:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 1:56:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 1:56:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/19/2018 1:31:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59347)(?)])(1 )(2 )]

"
Information	3/19/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59347)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 12:15:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 12:14:18 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/19/2018 12:10:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 12:10:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59384)(?)])(1 )(2 )]

"
Information	3/19/2018 12:10:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59384)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 12:06:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 12:06:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59388)(?)])(1 )(2 )]

"
Information	3/19/2018 12:06:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59388)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 12:06:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 12:06:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 12:06:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/19/2018 11:44:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/19/2018 11:43:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/19/2018 11:41:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 11:29:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 11:24:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 11:24:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59430)(?)])(1 )(2 )]

"
Information	3/19/2018 11:24:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59430)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 11:24:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 11:24:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 11:24:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 10:05:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 10:05:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:22Z. Reason: GVLK.
Information	3/19/2018 10:01:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/19/2018 10:00:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/19/2018 10:00:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 10:00:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 10:00:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/19/2018 9:59:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 13, Deleted: 0, Modified: 1, Compared: 20544, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/19/2018 9:59:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 28d1af21-2b2e-11e8-91eb-204747d02364
Report Status: 0"
Information	3/19/2018 9:57:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/19/2018 9:56:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/19/2018 9:56:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2018 9:56:51 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/19/2018 9:56:45 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 343

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 202

Information	3/19/2018 9:56:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/19/2018 9:56:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	3/19/2018 9:56:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/19/2018 9:56:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59518)(?)])(1 )(2 )]

"
Information	3/19/2018 9:56:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59518)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/19/2018 9:55:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/19/2018 9:55:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/19/2018 9:55:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/19/2018 9:53:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/19/2018 9:51:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	3/18/2018 2:40:34 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/18/2018 2:06:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2018 2:06:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:44Z. Reason: GVLK.
Information	3/18/2018 2:01:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2018 2:01:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 2:01:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 2:01:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2018 1:40:36 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8835.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/18/2018 1:36:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2018 1:36:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:43Z. Reason: GVLK.
Information	3/18/2018 1:31:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2018 1:31:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 1:31:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 1:31:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2018 1:26:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2018 1:26:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:00Z. Reason: GVLK.
Information	3/18/2018 1:21:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2018 1:21:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 1:21:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 1:21:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/18/2018 1:17:36 PM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/18/2018 1:14:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 205bb094-2a80-11e8-91eb-204747d02364
Report Status: 0"
Information	3/18/2018 1:06:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2018 1:06:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:46Z. Reason: GVLK.
Information	3/18/2018 1:06:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/18/2018 1:01:44 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485947
"
Error	3/18/2018 1:01:44 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {97E94CF9-4C09-4A5E-BCD7-DBF67C7A39F6}
Information	3/18/2018 1:01:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/18/2018 1:01:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60773)(?)])(1 )(2 )]

"
Information	3/18/2018 1:01:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60773)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 12:05:47 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	3/18/2018 12:05:03 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/18/2018 12:04:25 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2018 12:04:23 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2018 12:04:22 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2018 12:04:20 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/18/2018 12:04:12 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/18/2018 12:04:07 PM	ESENT	302	Logging/Recovery	Windows (4476) Windows: The database engine has successfully completed recovery steps.
Information	3/18/2018 12:04:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/18/2018 12:04:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60830)(?)])(1 )(2 )]

"
Information	3/18/2018 12:04:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60830)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 12:04:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/18/2018 12:04:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 12:04:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2018 12:04:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 12:04:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 12:04:00 PM	ESENT	301	Logging/Recovery	Windows (4476) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/18/2018 12:03:59 PM	ESENT	300	Logging/Recovery	Windows (4476) Windows: The database engine is initiating recovery steps.
Information	3/18/2018 12:03:59 PM	ESENT	102	General	Windows (4476) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/18/2018 12:03:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/18/2018 12:03:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2018 12:03:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8834.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/18/2018 12:03:25 PM	Service1	0	None	Service started successfully.
Error	3/18/2018 12:03:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/18/2018 12:03:17 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/18/2018 12:03:17 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/18/2018 12:03:08 PM	PostgreSQL	0	None	Server started and accepting connections

Error	3/18/2018 12:03:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/18/2018 12:02:39 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	3/18/2018 12:02:37 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/18/2018 12:02:32 PM	PostgreSQL	0	None	"2018-03-18 12:02:32 IST LOG:  redirecting log output to logging collector process
2018-03-18 12:02:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/18/2018 12:02:31 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/18/2018 12:02:30 PM	PostgreSQL	0	None	Waiting for server startup...

Information	3/18/2018 12:02:23 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:23 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/18/2018 12:02:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/18/2018 12:02:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/18/2018 12:02:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/18/2018 12:02:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/18/2018 12:02:16 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/18/2018 12:02:16 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/18/2018 12:02:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/18/2018 12:02:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/18/2018 12:02:14 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:14 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:13 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/18/2018 12:02:12 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/18/2018 12:02:12 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/18/2018 12:02:12 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/18/2018 12:02:11 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3504 at 3/11/2018 2:34:53 PM (local) 3/11/2018 9:04:53 AM (UTC). This is an informational message only; no user action is required.
Information	3/18/2018 12:02:10 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3872.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/18/2018 12:02:09 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/18/2018 12:01:44 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/18/2018 12:01:36 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/18/2018 12:01:23 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/18/2018 12:01:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/18/2018 12:01:23 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Error	3/18/2018 8:32:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/18/2018 8:18:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/18/2018 8:18:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:52Z. Reason: GVLK.
Information	3/18/2018 8:13:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/18/2018 8:13:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/18/2018 8:13:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/18/2018 8:13:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/18/2018 8:13:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2453807e-2a56-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/18/2018 8:02:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/17/2018 3:11:25 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8834.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/17/2018 2:53:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/17/2018 2:50:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/17/2018 2:50:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:20Z. Reason: GVLK.
Error	3/17/2018 2:48:45 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	3/17/2018 2:48:45 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {41900FC6-FC28-43E4-90D6-55BEAFA790E8}
Information	3/17/2018 2:47:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/17/2018 2:47:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62107)(?)])(1 )(2 )]

"
Information	3/17/2018 2:47:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/17/2018 2:47:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/17/2018 2:47:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/17/2018 2:47:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/17/2018 2:45:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/17/2018 2:45:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/17/2018 2:45:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/17/2018 2:45:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/17/2018 12:29:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad837fb8-29b0-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/17/2018 12:18:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	3/16/2018 7:02:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 6:44:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 6:44:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 6:44:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 5:53:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 5:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 5:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63366)(?)])(1 )(2 )]

"
Information	3/16/2018 5:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63366)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:48:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 5:48:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63366)(?)])(1 )(2 )]

"
Information	3/16/2018 5:48:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63366)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:48:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 5:48:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 5:48:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 5:39:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e8f107ac-2912-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/16/2018 5:39:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 5:34:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 5:34:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63380)(?)])(1 )(2 )]

"
Information	3/16/2018 5:34:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63380)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 5:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63381)(?)])(1 )(2 )]

"
Information	3/16/2018 5:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63381)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:33:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 5:33:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 5:33:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/16/2018 5:14:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/16/2018 3:34:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 3:17:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 3:12:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 3:12:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63522)(?)])(1 )(2 )]

"
Information	3/16/2018 3:12:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63522)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 3:12:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 3:12:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 3:12:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 3:05:05 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/16/2018 3:04:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/16/2018 3:01:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 2:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63538)(?)])(1 )(2 )]

"
Information	3/16/2018 2:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63538)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:56:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 2:56:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 2:56:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 2:53:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 2:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63546)(?)])(1 )(2 )]

"
Information	3/16/2018 2:48:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63546)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:48:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 2:48:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 2:48:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 2:44:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 2:44:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 2:44:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 2:43:16 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/16/2018 2:35:37 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 2:30:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:30:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63564)(?)])(1 )(2 )]

"
Information	3/16/2018 2:30:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63564)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:30:34 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 2:30:34 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 2:30:34 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 2:28:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 2:23:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:23:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63571)(?)])(1 )(2 )]

"
Information	3/16/2018 2:23:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63571)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:23:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 2:23:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 2:23:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 2:15:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 2:10:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:10:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63584)(?)])(1 )(2 )]

"
Information	3/16/2018 2:10:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63584)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:09:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 2:09:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63585)(?)])(1 )(2 )]

"
Information	3/16/2018 2:09:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 2:09:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 2:09:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 2:09:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 2:00:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 1:55:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 1:55:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63599)(?)])(1 )(2 )]

"
Information	3/16/2018 1:55:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63599)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 1:55:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 1:55:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 1:55:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 1:38:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 1:38:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:19Z. Reason: GVLK.
Warning	3/16/2018 1:34:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 1:33:20 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	3/16/2018 1:33:20 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	3/16/2018 1:33:19 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	3/16/2018 1:33:19 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	3/16/2018 1:33:19 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	3/16/2018 1:33:19 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	3/16/2018 1:33:17 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	3/16/2018 1:33:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 1:33:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 1:33:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 1:33:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 1:33:16 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	3/16/2018 1:33:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 1:33:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:14Z. Reason: GVLK.
Information	3/16/2018 1:28:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 1:28:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 1:28:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 1:28:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63667)(?)])(1 )(2 )]

"
Information	3/16/2018 12:47:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63667)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 12:47:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/16/2018 12:47:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 12:47:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 12:46:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8833.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/16/2018 12:39:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff2e0893-28e8-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/16/2018 11:49:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 10:44:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 10:43:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 10:18:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/16/2018 10:17:47 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	3/16/2018 9:54:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/16/2018 8:19:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 7:39:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1573acb1-28bf-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/16/2018 6:44:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 6:43:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/16/2018 6:23:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 5:41:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 5:41:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:05Z. Reason: GVLK.
Information	3/16/2018 5:36:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 5:36:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:36:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 5:36:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 5:23:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 5:23:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:17Z. Reason: GVLK.
Information	3/16/2018 5:18:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 5:18:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 5:18:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 5:18:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/16/2018 5:11:15 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/16/2018 5:01:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 5:01:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:07Z. Reason: GVLK.
Error	3/16/2018 4:56:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/16/2018 4:56:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 4:56:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 4:56:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 4:56:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 4:46:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 4:46:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:47Z. Reason: GVLK.
Information	3/16/2018 4:41:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 4:41:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 4:41:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 4:41:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/16/2018 4:40:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/16/2018 4:40:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:33Z. Reason: GVLK.
Information	3/16/2018 4:35:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/16/2018 4:35:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/16/2018 4:35:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/16/2018 4:35:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/16/2018 4:30:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 2:44:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 2:43:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/16/2018 2:39:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2ba91047-2895-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/16/2018 2:31:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/16/2018 12:59:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/16/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/15/2018 11:29:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 10:44:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 10:43:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/15/2018 9:56:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 9:39:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 41d9f9f0-286b-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/15/2018 8:11:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/15/2018 7:21:35 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/15/2018 6:43:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 6:43:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/15/2018 6:20:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 4:39:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58079122-2841-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/15/2018 4:21:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 2:46:15 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/15/2018 2:43:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 2:43:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/15/2018 2:43:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/15/2018 2:36:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 1:08:33 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	3/15/2018 1:08:32 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	3/15/2018 12:52:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]

"
Information	3/15/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/15/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/15/2018 12:44:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 12:29:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8832.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/15/2018 11:39:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6e352b6c-2817-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/15/2018 10:56:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 10:43:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 503

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/15/2018 9:31:37 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/15/2018 9:31:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/15/2018 9:31:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/15/2018 9:31:17 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 20822, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/15/2018 9:30:08 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/15/2018 9:30:08 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	3/15/2018 9:00:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 8:27:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2018 8:27:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:02:57Z. Reason: GVLK.
Information	3/15/2018 8:22:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2018 8:22:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2018 8:22:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2018 8:22:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/15/2018 7:03:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 6:42:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 6:39:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 843a265d-27ed-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/15/2018 5:26:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 4:11:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2018 4:11:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:33Z. Reason: GVLK.
Error	3/15/2018 4:03:03 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/15/2018 4:02:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2018 4:02:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2018 4:02:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2018 4:02:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/15/2018 3:48:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2018 3:48:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:21Z. Reason: GVLK.
Error	3/15/2018 3:43:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/15/2018 3:43:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2018 3:43:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2018 3:43:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2018 3:43:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/15/2018 3:38:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 3:33:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/15/2018 3:33:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:18Z. Reason: GVLK.
Information	3/15/2018 3:28:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/15/2018 3:28:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/15/2018 3:28:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/15/2018 3:28:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/15/2018 2:42:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 2:42:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/15/2018 1:56:36 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/15/2018 1:55:55 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/15/2018 1:40:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/15/2018 1:39:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9a4fea9c-27c3-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/15/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/14/2018 11:50:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 10:42:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2018 10:42:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/14/2018 10:42:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/14/2018 9:57:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 8:39:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b0904233-2799-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/14/2018 8:22:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 7:21:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	3/14/2018 7:21:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/14/2018 7:16:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 7:16:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66158)(?)])(1 )(2 )]

"
Information	3/14/2018 7:16:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66158)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 7:16:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 7:16:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 7:16:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/14/2018 6:48:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 6:42:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2018 5:49:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 5:44:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 5:44:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66250)(?)])(1 )(2 )]

"
Information	3/14/2018 5:44:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66250)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 5:44:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 5:44:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 5:44:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/14/2018 5:06:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 5:04:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 4:59:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 4:59:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66295)(?)])(1 )(2 )]

"
Information	3/14/2018 4:59:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66295)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 4:59:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 4:59:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 4:59:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 4:06:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 4:06:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:19Z. Reason: GVLK.
Information	3/14/2018 4:01:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2018 4:01:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 4:01:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 4:01:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 3:39:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c6ba5486-276f-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/14/2018 3:30:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 3:29:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 3:24:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 3:24:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66390)(?)])(1 )(2 )]

"
Information	3/14/2018 3:24:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66390)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 3:24:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 3:24:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 3:24:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 3:09:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 3:04:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 3:04:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66410)(?)])(1 )(2 )]

"
Information	3/14/2018 3:04:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66410)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 3:04:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 3:04:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 3:04:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 2:42:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2018 2:41:18 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/14/2018 2:41:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/14/2018 2:40:58 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	3/14/2018 1:30:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 12:52:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66547)(?)])(1 )(2 )]

"
Information	3/14/2018 12:47:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66547)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 12:47:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 12:47:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 12:47:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 12:17:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8831.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	3/14/2018 11:37:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 10:53:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 10:53:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:03:41Z. Reason: GVLK.
Information	3/14/2018 10:48:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2018 10:48:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:48:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 10:48:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 10:42:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2018 10:39:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dcf1f3a5-2745-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/14/2018 10:38:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 10:38:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-21T05:02:56Z. Reason: GVLK.
Information	3/14/2018 10:33:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:33:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:33:55 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/03/14 05:03"
Information	3/14/2018 10:33:55 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/03/14 05:03, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/14/2018 10:28:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2018 10:28:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:28:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 10:28:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/14/2018 10:15:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 10:10:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 10:10:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66704)(?)])(1 )(2 )]

"
Information	3/14/2018 10:10:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66704)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:09:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 10:09:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66705)(?)])(1 )(2 )]

"
Information	3/14/2018 10:09:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 10:09:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 10:09:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 10:09:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/14/2018 10:04:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 9:23:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 9:18:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/14/2018 9:18:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66756)(?)])(1 )(2 )]

"
Information	3/14/2018 9:18:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66756)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 9:18:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/14/2018 9:18:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 9:18:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/14/2018 8:11:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 6:42:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/14/2018 6:35:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 5:39:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f3360606-271b-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/14/2018 5:04:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:51Z. Reason: GVLK.
Information	3/14/2018 4:38:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2018 4:38:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 4:38:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 4:38:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/14/2018 4:35:52 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/14/2018 4:26:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/14/2018 4:26:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:25Z. Reason: GVLK.
Error	3/14/2018 4:21:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/14/2018 4:21:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/14/2018 4:21:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/14/2018 4:21:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/14/2018 4:21:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/14/2018 3:09:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 2:42:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/14/2018 1:44:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/14/2018 1:43:42 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	3/14/2018 1:15:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/14/2018 12:39:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 097d3bd4-26f2-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/13/2018 11:43:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 10:41:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2018 10:22:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 10:22:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:46Z. Reason: GVLK.
Information	3/13/2018 10:17:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2018 10:17:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 10:17:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 10:17:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/13/2018 9:42:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 8:16:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 8:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 8:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67543)(?)])(1 )(2 )]

"
Information	3/13/2018 8:11:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67543)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	3/13/2018 8:09:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 8:08:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 8:08:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67546)(?)])(1 )(2 )]

"
Information	3/13/2018 8:08:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67546)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 8:08:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2018 8:08:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 8:08:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 7:39:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1fbfb753-26c8-11e8-8ce1-9a0733df3384
Report Status: 0"
Error	3/13/2018 7:21:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/13/2018 7:04:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 6:56:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 6:56:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67617)(?)])(1 )(2 )]

"
Information	3/13/2018 6:56:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67617)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 6:56:57 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67617)(?)])(1 )(2 )]

"
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110817  Grace type=8.
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=72fbced6-6082-4aa0-9ac9-edbe3186ceb5"
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=6d6f11ce-ea8c-4b92-868a-e91c8575c827"
Information	3/13/2018 6:56:55 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/13/2018 6:56:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 6:56:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21538)(?)])(1 )(2 )]

"
Information	3/13/2018 6:56:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21538)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 6:56:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2018 6:56:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 6:56:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 6:41:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/13/2018 6:20:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/13/2018 4:39:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/13/2018 2:52:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 2:51:51 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/13/2018 2:51:31 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/13/2018 2:51:24 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/13/2018 2:41:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2018 2:39:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35e72705-269e-11e8-8ce1-9a0733df3384
Report Status: 0"
Warning	3/13/2018 12:54:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 12:24:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8830.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/13/2018 11:23:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	3/13/2018 11:21:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 11:18:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 11:18:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21996)(?)])(1 )(2 )]

"
Information	3/13/2018 11:18:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21996)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 11:18:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2018 11:18:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 11:18:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 10:48:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 10:43:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 10:43:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22031)(?)])(1 )(2 )]

"
Information	3/13/2018 10:43:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22031)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 10:43:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 10:43:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22032)(?)])(1 )(2 )]

"
Information	3/13/2018 10:43:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22032)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 10:41:17 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 281

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 483

Information	3/13/2018 10:41:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/13/2018 10:40:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 10:40:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22034)(?)])(1 )(2 )]

"
Information	3/13/2018 10:40:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22034)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 10:38:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 10:38:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22037)(?)])(1 )(2 )]

"
Information	3/13/2018 10:38:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22037)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 10:38:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2018 10:38:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 10:38:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 9:44:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 9:44:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:36Z. Reason: GVLK.
Information	3/13/2018 9:44:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 9:39:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2018 9:39:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 9:39:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 9:39:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 9:39:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c179764-2674-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/13/2018 9:39:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/13/2018 9:39:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22096)(?)])(1 )(2 )]

"
Information	3/13/2018 9:39:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22096)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 9:39:14 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/13/2018 9:39:14 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 9:39:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/13/2018 9:37:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/13/2018 9:37:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:14Z. Reason: GVLK.
Information	3/13/2018 9:32:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/13/2018 9:32:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/13/2018 9:32:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/13/2018 9:32:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/13/2018 9:31:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/13/2018 9:29:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	3/12/2018 7:21:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/12/2018 7:20:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2018 7:01:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/12/2018 7:01:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:06Z. Reason: GVLK.
Information	3/12/2018 6:59:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5879dbfe-25f9-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/12/2018 6:56:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/12/2018 6:56:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2018 6:56:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2018 6:56:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/12/2018 6:04:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2018 6:03:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/12/2018 5:43:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/12/2018 4:11:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2018 2:58:46 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/12/2018 2:58:31 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/12/2018 2:58:31 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/12/2018 2:12:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2018 2:04:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2018 2:03:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2018 1:51:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 667bb4c9-25ce-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/12/2018 1:44:25 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	3/12/2018 12:36:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8829.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	3/12/2018 12:19:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/12/2018 10:40:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2018 10:08:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/12/2018 10:05:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 14, Deleted: 0, Modified: 0, Compared: 20644, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/12/2018 10:03:42 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/12/2018 10:03:39 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/12/2018 10:03:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2018 10:03:37 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 530

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 531

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 546

Information	3/12/2018 10:03:36 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/12/2018 10:03:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/12/2018 10:03:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/12/2018 10:03:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23512)(?)])(1 )(2 )]

"
Information	3/12/2018 10:03:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23512)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/12/2018 10:03:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/12/2018 10:03:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/12/2018 10:03:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/12/2018 8:52:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/12/2018 8:51:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c567924-25a4-11e8-8ce1-9a0733df3384
Report Status: 0"
Information	3/11/2018 9:42:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 9:42:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:12Z. Reason: GVLK.
Information	3/11/2018 9:37:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 9:37:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 9:37:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 9:37:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 9:26:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/11/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24273)(?)])(1 )(2 )]

"
Information	3/11/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24273)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 7:41:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 241c8aa6-2536-11e8-8ce1-9a0733df3384
Report Status: 0"
Error	3/11/2018 7:20:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/11/2018 3:56:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 3:56:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:13Z. Reason: GVLK.
Information	3/11/2018 3:51:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 3:51:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 3:51:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 3:51:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 3:26:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 3:26:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:13Z. Reason: GVLK.
Information	3/11/2018 3:21:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 3:21:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 3:21:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 3:21:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 2:56:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 2:56:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:20Z. Reason: GVLK.
Information	3/11/2018 2:51:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 2:51:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 2:51:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 2:51:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 2:49:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 2:49:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:12Z. Reason: GVLK.
Information	3/11/2018 2:48:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 2:43:29 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	3/11/2018 2:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/11/2018 2:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24671)(?)])(1 )(2 )]

"
Information	3/11/2018 2:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24671)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 2:43:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2018 2:43:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 2:43:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 2:42:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 2:41:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 28c4504d-250c-11e8-8ce1-204747d02364
Report Status: 0"
Information	3/11/2018 2:41:08 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	3/11/2018 2:38:51 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	3/11/2018 2:37:40 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {EB76573C-8A75-4E83-975D-A37F6484BCB4}
Information	3/11/2018 2:37:29 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/11/2018 2:37:27 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/11/2018 2:37:25 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/11/2018 2:37:10 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/11/2018 2:37:08 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/11/2018 2:36:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/11/2018 2:36:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24678)(?)])(1 )(2 )]

"
Information	3/11/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 2:36:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 2:36:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24678)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 2:36:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/11/2018 2:36:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 2:36:52 PM	ESENT	302	Logging/Recovery	Windows (7684) Windows: The database engine has successfully completed recovery steps.
Information	3/11/2018 2:36:52 PM	ESENT	301	Logging/Recovery	Windows (7684) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/11/2018 2:36:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 2:36:49 PM	ESENT	301	Logging/Recovery	Windows (7684) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS005B6.log.
Information	3/11/2018 2:36:49 PM	ESENT	300	Logging/Recovery	Windows (7684) Windows: The database engine is initiating recovery steps.
Information	3/11/2018 2:36:49 PM	ESENT	102	General	Windows (7684) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/11/2018 2:36:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 2:36:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8828.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	3/11/2018 2:36:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/11/2018 2:35:38 PM	Service1	0	None	Service started successfully.
Error	3/11/2018 2:35:26 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/11/2018 2:35:26 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/11/2018 2:35:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/11/2018 2:35:26 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/11/2018 2:35:26 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/11/2018 2:35:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/11/2018 2:35:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/11/2018 2:35:22 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	3/11/2018 2:35:19 PM	PostgreSQL	0	None	Server started and accepting connections

Information	3/11/2018 2:35:11 PM	PostgreSQL	0	None	"2018-03-11 14:35:11 IST LOG:  redirecting log output to logging collector process
2018-03-11 14:35:11 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/11/2018 2:35:10 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/11/2018 2:35:10 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/11/2018 2:35:09 PM	PostgreSQL	0	None	Waiting for server startup...

Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:57 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:56 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/11/2018 2:34:55 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/11/2018 2:34:55 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/11/2018 2:34:55 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3616 at 3/4/2018 10:31:51 PM (local) 3/4/2018 5:01:51 PM (UTC). This is an informational message only; no user action is required.
Information	3/11/2018 2:34:53 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/11/2018 2:34:50 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/11/2018 2:34:50 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/11/2018 2:34:50 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/11/2018 2:34:50 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/11/2018 2:34:50 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3504.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/11/2018 2:34:49 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/11/2018 2:34:21 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/11/2018 2:34:13 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/11/2018 2:33:59 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/11/2018 2:33:59 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/11/2018 2:33:59 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/11/2018 12:27:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/11/2018 12:27:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/11/2018 12:10:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8828.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/11/2018 8:43:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/11/2018 8:43:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:37Z. Reason: GVLK.
Information	3/11/2018 8:38:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/11/2018 8:38:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/11/2018 8:38:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/11/2018 8:38:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/11/2018 8:37:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5c71dadb-24d9-11e8-8597-204747d02364
Report Status: 0"
Information	3/11/2018 8:27:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/10/2018 9:26:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/10/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/10/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25713)(?)])(1 )(2 )]

"
Information	3/10/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25713)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2018 9:21:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/10/2018 9:21:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2018 9:21:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/10/2018 9:16:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2018 9:16:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:38Z. Reason: GVLK.
Information	3/10/2018 9:11:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2018 9:11:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2018 9:11:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2018 9:11:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2018 8:28:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8827.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/10/2018 7:36:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/10/2018 7:36:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:42Z. Reason: GVLK.
Information	3/10/2018 7:36:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/10/2018 7:31:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/10/2018 7:31:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2018 7:31:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2018 7:31:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/10/2018 7:31:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/10/2018 7:31:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25823)(?)])(1 )(2 )]

"
Information	3/10/2018 7:31:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25823)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/10/2018 7:31:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/10/2018 7:31:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/10/2018 7:31:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/10/2018 7:30:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6dfeb646-246b-11e8-8597-204747d02364
Report Status: 0"
Information	3/10/2018 7:20:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	3/10/2018 7:20:00 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/10/2018 7:19:57 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/10/2018 7:19:57 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/9/2018 7:00:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 5:49:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 11bfa0d4-2394-11e8-8597-204747d02364
Report Status: 0"
Information	3/9/2018 5:41:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/9/2018 5:21:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 5:20:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 5:20:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:26Z. Reason: GVLK.
Information	3/9/2018 5:15:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2018 5:15:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 5:15:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 5:15:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2018 3:49:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/9/2018 2:51:21 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/9/2018 1:58:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 1:41:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2018 12:49:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 27c97b04-236a-11e8-8597-204747d02364
Report Status: 0"
Information	3/9/2018 12:39:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 12:39:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:32Z. Reason: GVLK.
Information	3/9/2018 12:34:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2018 12:34:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 12:34:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 12:34:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/9/2018 12:27:11 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8826.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/9/2018 12:26:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 12:21:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/9/2018 12:21:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27693)(?)])(1 )(2 )]

"
Information	3/9/2018 12:21:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27693)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 12:21:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/9/2018 12:21:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 12:21:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/9/2018 12:18:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 11:16:21 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/9/2018 11:16:17 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	3/9/2018 10:43:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 9:52:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/9/2018 9:41:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2018 9:33:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/9/2018 9:33:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	3/9/2018 8:48:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 7:49:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3de4766c-2340-11e8-8597-204747d02364
Report Status: 0"
Warning	3/9/2018 7:03:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 5:41:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2018 5:41:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/9/2018 5:24:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 4:56:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 4:56:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:49Z. Reason: GVLK.
Information	3/9/2018 4:51:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2018 4:51:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 4:51:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 4:51:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/9/2018 4:42:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/9/2018 4:32:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 4:32:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:43Z. Reason: GVLK.
Error	3/9/2018 4:28:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/9/2018 4:27:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2018 4:27:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 4:27:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 4:27:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/9/2018 4:21:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/9/2018 4:21:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:40Z. Reason: GVLK.
Information	3/9/2018 4:16:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/9/2018 4:16:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/9/2018 4:16:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/9/2018 4:16:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/9/2018 3:29:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 2:49:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53ed8945-2316-11e8-8597-204747d02364
Report Status: 0"
Information	3/9/2018 1:41:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/9/2018 1:41:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/9/2018 1:30:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/9/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/8/2018 11:32:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 10:58:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 10:58:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:38Z. Reason: GVLK.
Information	3/8/2018 10:53:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 10:53:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 10:53:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 10:53:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/8/2018 9:49:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a0d01d5-22ec-11e8-8597-204747d02364
Report Status: 0"
Information	3/8/2018 9:45:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 9:45:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:24Z. Reason: GVLK.
Information	3/8/2018 9:40:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 9:40:55 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/8/2018 9:40:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 9:40:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 9:40:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/8/2018 9:33:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 9:26:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/8/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28593)(?)])(1 )(2 )]

"
Information	3/8/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28593)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 9:21:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/8/2018 9:21:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 9:21:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/8/2018 7:57:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/8/2018 6:11:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 5:50:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 18, Compared: 20795, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/8/2018 5:49:05 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	3/8/2018 5:49:00 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/8/2018 5:48:55 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	3/8/2018 5:40:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 5:40:48 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/8/2018 5:40:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 4:49:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 801e177b-22c2-11e8-8597-204747d02364
Report Status: 0"
Warning	3/8/2018 4:34:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 3:46:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 3:46:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:49Z. Reason: GVLK.
Information	3/8/2018 3:41:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 3:41:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 3:41:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 3:41:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/8/2018 2:51:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/8/2018 2:38:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 2:33:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	3/8/2018 2:32:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	3/8/2018 1:40:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 1:40:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2018 1:00:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 12:16:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8825.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	3/8/2018 11:57:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/8/2018 11:57:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/8/2018 11:48:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95ff81d3-2298-11e8-8597-204747d02364
Report Status: 0"
Warning	3/8/2018 11:21:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 11:18:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/8/2018 9:40:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 9:40:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2018 9:30:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/8/2018 7:38:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 6:48:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac29e0fa-226e-11e8-8597-204747d02364
Report Status: 0"
Warning	3/8/2018 6:03:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 5:40:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/8/2018 5:39:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2018 4:25:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 4:14:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 4:14:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:46Z. Reason: GVLK.
Information	3/8/2018 4:09:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 4:09:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 4:09:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 4:09:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/8/2018 4:05:22 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/8/2018 3:55:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 3:55:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:54Z. Reason: GVLK.
Error	3/8/2018 3:51:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/8/2018 3:50:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 3:50:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 3:50:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 3:50:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/8/2018 3:14:01 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/8/2018 3:11:40 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/8/2018 2:56:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/8/2018 2:56:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:39Z. Reason: GVLK.
Information	3/8/2018 2:51:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/8/2018 2:51:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/8/2018 2:51:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/8/2018 2:51:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/8/2018 2:40:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 1:48:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2435fe3-2244-11e8-8597-204747d02364
Report Status: 0"
Information	3/8/2018 1:39:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/8/2018 12:39:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/8/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/7/2018 10:52:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 9:39:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2018 9:26:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/7/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30033)(?)])(1 )(2 )]

"
Information	3/7/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30033)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/7/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 9:21:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/7/2018 8:56:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 8:48:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d87cb884-221a-11e8-8597-204747d02364
Report Status: 0"
Warning	3/7/2018 7:06:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 5:39:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2018 5:39:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2018 5:22:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 3:48:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eeb1568a-21f0-11e8-8597-204747d02364
Report Status: 0"
Warning	3/7/2018 3:31:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/7/2018 2:51:38 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/7/2018 1:42:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 1:39:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2018 12:19:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8824.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Warning	3/7/2018 11:52:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 10:57:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 10:57:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:59:06Z. Reason: GVLK.
Information	3/7/2018 10:52:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2018 10:52:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 10:52:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 10:52:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/7/2018 10:48:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 04e53e48-21c7-11e8-8597-204747d02364
Report Status: 0"
Information	3/7/2018 10:34:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 10:34:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-14T04:58:42Z. Reason: GVLK.
Information	3/7/2018 10:29:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 10:29:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 10:29:41 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/03/07 04:59"
Information	3/7/2018 10:29:40 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/03/07 04:59, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	3/7/2018 10:24:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2018 10:24:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 10:24:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 10:24:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/7/2018 10:16:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 10:14:17 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/7/2018 10:13:57 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/7/2018 9:39:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/7/2018 9:38:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	3/7/2018 8:29:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/7/2018 6:56:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 5:48:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1adcc3a8-219d-11e8-8597-204747d02364
Report Status: 0"
Information	3/7/2018 5:39:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2018 4:57:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 4:33:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 4:33:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:36Z. Reason: GVLK.
Information	3/7/2018 4:28:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2018 4:28:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 4:28:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 4:28:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/7/2018 4:24:51 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/7/2018 4:16:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 4:16:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:07Z. Reason: GVLK.
Error	3/7/2018 4:11:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/7/2018 4:11:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2018 4:11:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 4:11:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 4:11:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/7/2018 3:03:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 2:15:26 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/7/2018 2:14:44 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/7/2018 1:39:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/7/2018 1:16:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/7/2018 12:48:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30eca2c3-2173-11e8-8597-204747d02364
Report Status: 0"
Information	3/7/2018 12:15:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/7/2018 12:15:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:53:52Z. Reason: GVLK.
Information	3/7/2018 12:10:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/7/2018 12:10:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/7/2018 12:10:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/7/2018 12:10:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/6/2018 11:28:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 10:48:44 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	3/6/2018 10:48:09 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	3/6/2018 9:39:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/6/2018 9:31:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 9:26:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/6/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/6/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31473)(?)])(1 )(2 )]

"
Information	3/6/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31473)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/6/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/6/2018 7:55:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 7:48:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46ec3856-2149-11e8-8597-204747d02364
Report Status: 0"
Warning	3/6/2018 6:13:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 5:39:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/6/2018 4:28:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 3:26:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2018 3:26:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:07Z. Reason: GVLK.
Information	3/6/2018 3:21:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2018 3:21:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2018 3:21:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2018 3:21:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2018 3:00:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/6/2018 2:55:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/6/2018 2:55:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31860)(?)])(1 )(2 )]

"
Information	3/6/2018 2:55:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31860)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2018 2:55:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/6/2018 2:55:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2018 2:55:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	3/6/2018 2:51:00 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/6/2018 2:50:34 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/6/2018 2:48:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d11d65f-211f-11e8-8597-204747d02364
Report Status: 0"
Warning	3/6/2018 2:44:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/6/2018 2:16:47 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/6/2018 2:14:53 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/6/2018 1:39:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2018 1:39:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/6/2018 1:38:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/6/2018 1:29:26 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	3/6/2018 12:51:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/6/2018 12:31:03 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/6/2018 12:13:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8823.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	3/6/2018 11:12:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 10:26:02 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/6/2018 9:55:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/6/2018 9:55:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:53:44Z. Reason: GVLK.
Information	3/6/2018 9:49:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/6/2018 9:49:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/6/2018 9:49:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/6/2018 9:49:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/6/2018 9:48:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7321f195-20f5-11e8-8597-204747d02364
Report Status: 0"
Warning	3/6/2018 9:41:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/6/2018 9:40:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/6/2018 9:39:01 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/6/2018 9:38:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/6/2018 9:38:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/6/2018 9:38:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	3/6/2018 9:38:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	3/5/2018 9:26:13 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: f5fpapi.dll, version: 7132.2017.404.2206, time stamp: 0x58e419a1
Exception code: 0xc0000005
Fault offset: 0x00034441
Faulting process id: 0x1944
Faulting application start time: 0x01d3b45088e7c55c
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: C:\Program Files (x86)\F5 VPN\f5fpapi.dll
Report Id: ba4ec4b9-208d-11e8-8597-204747d02364"
Error	3/5/2018 9:26:11 PM	RasClient	20227	None	CoId={FC568F71-FECD-4B4F-B13A-EE450D60DEE2}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	3/5/2018 9:26:11 PM	RasClient	20221	None	CoId={FC568F71-FECD-4B4F-B13A-EE450D60DEE2}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	3/5/2018 9:26:11 PM	RasClient	20227	None	CoId={8C9AA493-B0F6-4079-BCE7-2F2A801E3D35}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	3/5/2018 9:26:11 PM	RasClient	20221	None	CoId={8C9AA493-B0F6-4079-BCE7-2F2A801E3D35}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/5/2018 9:26:07 PM	RasClient	20226	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	3/5/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32913)(?)])(1 )(2 )]

"
Information	3/5/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32913)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	3/5/2018 8:26:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2018 8:26:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5377d0da-2085-11e8-8597-204747d02364
Report Status: 0"
Information	3/5/2018 8:20:11 PM	RasClient	20225	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.231.51
TunnelIpv6Address = None
Dial-in User = .
Information	3/5/2018 8:20:07 PM	RasClient	20224	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/5/2018 8:20:07 PM	RasClient	20223	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 8:20:07 PM	RasClient	20222	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 8:20:07 PM	RasClient	20221	None	CoId={F6E522AC-BD15-4CF1-9E97-896E785A346B}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/5/2018 8:15:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	3/5/2018 8:15:35 PM	ESENT	508	Performance	"taskhost (4496) WebCacheLocal: A request to write to the file ""C:\Users\212558710\AppData\Local\Microsoft\Windows\WebCache\V01.log"" at offset 233472 (0x0000000000039000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (15687 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Information	3/5/2018 3:54:04 PM	RasClient	20226	None	CoId={A2EE0961-9AF4-4D14-B842-18F79AFC83F1}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	3/5/2018 3:54:00 PM	RasClient	20224	None	CoId={A2EE0961-9AF4-4D14-B842-18F79AFC83F1}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/5/2018 3:54:00 PM	RasClient	20223	None	CoId={A2EE0961-9AF4-4D14-B842-18F79AFC83F1}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 3:54:00 PM	RasClient	20222	None	CoId={A2EE0961-9AF4-4D14-B842-18F79AFC83F1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 3:54:00 PM	RasClient	20221	None	CoId={A2EE0961-9AF4-4D14-B842-18F79AFC83F1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/5/2018 3:53:54 PM	RasClient	20226	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	3/5/2018 3:38:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2018 3:34:14 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/5/2018 3:33:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33261)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 3:33:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33261)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 3:33:46 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	3/5/2018 3:33:46 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	3/5/2018 3:33:46 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	3/5/2018 3:33:14 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 2, Deleted: 0, Modified: 4, Compared: 20752, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/5/2018 3:30:35 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	3/5/2018 3:30:29 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/5/2018 3:30:29 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Indexing was disabled and then re-enabled.
Information	3/5/2018 3:30:27 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 405

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 343

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	3/5/2018 3:29:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2018 3:29:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2018 3:29:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33265)(?)])(1 )(2 )]

"
Information	3/5/2018 3:29:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 3:28:59 PM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8822.0000.
Information	3/5/2018 3:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2018 3:26:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33268)(?)])(1 )(2 )]

"
Information	3/5/2018 3:26:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33268)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 3:26:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2018 3:26:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2018 3:26:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2018 3:22:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/5/2018 3:17:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2018 3:17:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	3/5/2018 3:17:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/5/2018 3:17:15 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft VBA for Outlook Addin
Description: 
ProgID: Microsoft.VbaAddinForOutlook.1
GUID: {799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}
Load Behavior: 9
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\OUTLVBA.DLL
Boot Time (Milliseconds): 390

Information	3/5/2018 3:17:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/5/2018 3:16:32 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Warning	3/5/2018 3:15:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2018 3:14:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/5/2018 3:14:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33280)(?)])(1 )(2 )]

"
Information	3/5/2018 3:14:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33280)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	3/5/2018 3:14:16 PM	Microsoft Office 16	2000	None	Microsoft Outlook: Accepted Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Information	3/5/2018 3:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	3/5/2018 3:14:06 PM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	3/5/2018 3:13:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/5/2018 3:13:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2018 3:13:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/5/2018 3:13:32 PM	RasClient	20225	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.236.222
TunnelIpv6Address = None
Dial-in User = .
Information	3/5/2018 3:13:25 PM	RasClient	20224	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/5/2018 3:13:25 PM	RasClient	20223	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 3:13:25 PM	RasClient	20222	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 3:13:25 PM	RasClient	20221	None	CoId={F30445DE-EF80-4C96-A9ED-412F85FE2C92}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/5/2018 1:31:53 PM	RasClient	20226	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	3/5/2018 1:05:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2018 1:05:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:17Z. Reason: GVLK.
Information	3/5/2018 1:02:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8822.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	3/5/2018 1:00:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2018 1:00:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 1:00:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2018 1:00:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/5/2018 12:40:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/5/2018 12:40:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3bd60b0e-2044-11e8-8597-204747d02364
Report Status: 0"
Information	3/5/2018 12:38:19 PM	RasClient	20225	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.232.62
TunnelIpv6Address = None
Dial-in User = .
Information	3/5/2018 12:38:16 PM	RasClient	20224	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/5/2018 12:38:16 PM	RasClient	20223	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 12:38:15 PM	RasClient	20222	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/5/2018 12:38:15 PM	RasClient	20221	None	CoId={4615FBF0-0E3A-4760-9B22-BA3B583573A7}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/5/2018 12:34:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/5/2018 12:34:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:41Z. Reason: GVLK.
Information	3/5/2018 8:18:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/5/2018 8:18:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/5/2018 8:18:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/5/2018 8:18:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 10:53:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 10:53:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:03Z. Reason: GVLK.
Information	3/4/2018 10:48:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2018 10:48:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 10:48:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 10:48:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 10:47:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 10:41:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/4/2018 10:41:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34273)(?)])(1 )(2 )]

"
Information	3/4/2018 10:41:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34273)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 10:41:18 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/4/2018 10:41:18 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 10:41:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 10:41:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 10:41:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:08Z. Reason: GVLK.
Information	3/4/2018 10:38:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 10:38:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9de41a94-1fce-11e8-8597-204747d02364
Report Status: 0"
Information	3/4/2018 10:35:22 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	3/4/2018 10:33:57 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/4/2018 10:33:56 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	3/4/2018 10:33:55 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7ECDC931-D54A-4EBA-AF56-A5D203B227A9}
Error	3/4/2018 10:33:55 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7ECDC931-D54A-4EBA-AF56-A5D203B227A9}
Information	3/4/2018 10:33:55 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/4/2018 10:33:52 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/4/2018 10:33:38 PM	ESENT	302	Logging/Recovery	Windows (7940) Windows: The database engine has successfully completed recovery steps.
Information	3/4/2018 10:33:34 PM	ESENT	301	Logging/Recovery	Windows (7940) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/4/2018 10:33:34 PM	ESENT	300	Logging/Recovery	Windows (7940) Windows: The database engine is initiating recovery steps.
Information	3/4/2018 10:33:34 PM	ESENT	102	General	Windows (7940) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/4/2018 10:33:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2018 10:33:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 10:33:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 10:33:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/4/2018 10:33:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34281)(?)])(1 )(2 )]

"
Information	3/4/2018 10:33:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 10:33:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 10:33:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/4/2018 10:33:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 10:33:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 10:33:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8821.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Error	3/4/2018 10:33:03 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/4/2018 10:32:58 PM	Service1	0	None	Service started successfully.
Error	3/4/2018 10:32:51 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/4/2018 10:32:51 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	3/4/2018 10:32:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/4/2018 10:32:43 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	3/4/2018 10:32:43 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/4/2018 10:32:29 PM	PostgreSQL	0	None	Server started and accepting connections

Information	3/4/2018 10:32:07 PM	PostgreSQL	0	None	"2018-03-04 22:32:07 IST LOG:  redirecting log output to logging collector process
2018-03-04 22:32:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/4/2018 10:32:06 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/4/2018 10:32:05 PM	PostgreSQL	0	None	Waiting for server startup...

Information	3/4/2018 10:32:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/4/2018 10:32:01 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/4/2018 10:32:01 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/4/2018 10:32:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/4/2018 10:32:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/4/2018 10:31:55 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:55 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/4/2018 10:31:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/4/2018 10:31:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/4/2018 10:31:54 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/4/2018 10:31:53 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3920 at 3/3/2018 9:26:14 AM (local) 3/3/2018 3:56:14 AM (UTC). This is an informational message only; no user action is required.
Information	3/4/2018 10:31:51 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/4/2018 10:31:48 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/4/2018 10:31:48 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/4/2018 10:31:48 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/4/2018 10:31:48 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/4/2018 10:31:48 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3616.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/4/2018 10:31:47 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/4/2018 10:31:24 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/4/2018 10:31:18 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/4/2018 10:31:05 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/4/2018 10:31:05 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/4/2018 10:31:05 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	3/4/2018 5:55:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/4/2018 3:58:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/4/2018 2:21:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2018 2:16:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8dbe9d30-1f88-11e8-9661-204747d02364
Report Status: 0"
Warning	3/4/2018 12:41:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2018 12:36:34 PM	RasClient	20225	None	CoId={0558E8B2-D5FA-42D3-A636-72AA466846D0}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.233.77
TunnelIpv6Address = None
Dial-in User = .
Information	3/4/2018 12:36:30 PM	RasClient	20224	None	CoId={0558E8B2-D5FA-42D3-A636-72AA466846D0}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/4/2018 12:36:30 PM	RasClient	20223	None	CoId={0558E8B2-D5FA-42D3-A636-72AA466846D0}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/4/2018 12:36:30 PM	RasClient	20222	None	CoId={0558E8B2-D5FA-42D3-A636-72AA466846D0}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/4/2018 12:36:30 PM	RasClient	20221	None	CoId={0558E8B2-D5FA-42D3-A636-72AA466846D0}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	3/4/2018 12:34:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8821.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	3/4/2018 11:03:13 AM	RasClient	20226	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Warning	3/4/2018 10:12:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/4/2018 10:08:35 AM	RasClient	20225	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.253.106
TunnelIpv6Address = None
Dial-in User = .
Information	3/4/2018 10:08:32 AM	RasClient	20224	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	3/4/2018 10:08:32 AM	RasClient	20223	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/4/2018 10:08:31 AM	RasClient	20222	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	3/4/2018 10:08:31 AM	RasClient	20221	None	CoId={8E10DD72-9815-47C2-832C-D0085230FF3D}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	3/4/2018 9:44:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/4/2018 9:21:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 9:21:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:20Z. Reason: GVLK.
Information	3/4/2018 9:21:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/4/2018 9:16:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ced652a-1f5e-11e8-9661-204747d02364
Report Status: 0"
Information	3/4/2018 9:16:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/4/2018 9:16:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 9:16:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 9:16:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/4/2018 9:15:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/4/2018 9:15:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35079)(?)])(1 )(2 )]

"
Information	3/4/2018 9:15:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35079)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/4/2018 9:15:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/4/2018 9:15:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/4/2018 9:15:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 7:36:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c6162fd-1eec-11e8-9661-204747d02364
Report Status: 0"
Information	3/3/2018 2:38:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 2:38:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:34Z. Reason: GVLK.
Information	3/3/2018 2:36:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2686fb90-1ec2-11e8-9661-204747d02364
Report Status: 0"
Information	3/3/2018 2:33:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2018 2:33:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 2:33:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 2:33:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 10:47:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 10:47:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:15Z. Reason: GVLK.
Information	3/3/2018 10:42:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2018 10:42:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 10:42:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 10:42:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 10:27:09 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8820.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	3/3/2018 10:17:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 10:17:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:14Z. Reason: GVLK.
Information	3/3/2018 10:12:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2018 10:12:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 10:12:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 10:12:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 9:47:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 9:47:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:14Z. Reason: GVLK.
Error	3/3/2018 9:44:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/3/2018 9:44:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/3/2018 9:41:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 9:37:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2018 9:37:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 9:37:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 9:37:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/3/2018 9:36:48 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	3/3/2018 9:36:48 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {D001759B-E2DC-42A5-8E48-7ACCF1532F63}
Information	3/3/2018 9:36:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/3/2018 9:36:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:03Z. Reason: GVLK.
Information	3/3/2018 9:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/3/2018 9:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36499)(?)])(1 )(2 )]

"
Information	3/3/2018 9:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36499)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 9:32:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c27df2e2-1e97-11e8-9661-204747d02364
Report Status: 0"
Information	3/3/2018 9:30:16 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	3/3/2018 9:30:14 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {34BF47FC-0792-4E7B-AEFE-A361D2B4668A}
Information	3/3/2018 9:29:18 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/3/2018 9:29:13 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/3/2018 9:29:06 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/3/2018 9:29:01 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	3/3/2018 9:28:43 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	3/3/2018 9:28:39 AM	ESENT	302	Logging/Recovery	Windows (9168) Windows: The database engine has successfully completed recovery steps.
Information	3/3/2018 9:28:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/3/2018 9:28:36 AM	ESENT	301	Logging/Recovery	Windows (9168) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	3/3/2018 9:28:36 AM	ESENT	300	Logging/Recovery	Windows (9168) Windows: The database engine is initiating recovery steps.
Information	3/3/2018 9:28:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36506)(?)])(1 )(2 )]

"
Information	3/3/2018 9:28:35 AM	ESENT	102	General	Windows (9168) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	3/3/2018 9:28:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36506)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 9:28:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/3/2018 9:28:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 9:28:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 9:28:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/3/2018 9:28:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/3/2018 9:28:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/3/2018 9:28:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/3/2018 9:28:08 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8818.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Error	3/3/2018 9:27:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/3/2018 9:27:07 AM	Service1	0	None	Service started successfully.
Error	3/3/2018 9:27:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	3/3/2018 9:26:57 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	3/3/2018 9:26:57 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	3/3/2018 9:26:47 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	3/3/2018 9:26:43 AM	PostgreSQL	0	None	Server started and accepting connections

Information	3/3/2018 9:26:41 AM	PostgreSQL	0	None	"2018-03-03 09:26:41 IST LOG:  redirecting log output to logging collector process
2018-03-03 09:26:41 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	3/3/2018 9:26:35 AM	PostgreSQL	0	None	Waiting for server startup...

Information	3/3/2018 9:26:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	3/3/2018 9:26:28 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:28 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	3/3/2018 9:26:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	3/3/2018 9:26:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	3/3/2018 9:26:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	3/3/2018 9:26:27 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	3/3/2018 9:26:27 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	3/3/2018 9:26:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	3/3/2018 9:26:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	3/3/2018 9:26:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	3/3/2018 9:26:27 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	3/3/2018 9:26:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	3/3/2018 9:26:26 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:26 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	3/3/2018 9:26:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	3/3/2018 9:26:24 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:24 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	3/3/2018 9:26:23 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	3/3/2018 9:26:23 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	3/3/2018 9:26:23 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	3/3/2018 9:26:15 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:15 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:15 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3724 at 3/1/2018 9:16:21 PM (local) 3/1/2018 3:46:21 PM (UTC). This is an informational message only; no user action is required.
Information	3/3/2018 9:26:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	3/3/2018 9:26:13 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	3/3/2018 9:26:12 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	3/3/2018 9:26:12 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	3/3/2018 9:26:12 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	3/3/2018 9:26:12 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3920.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	3/3/2018 9:26:10 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	3/3/2018 9:25:26 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	3/3/2018 9:25:18 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	3/3/2018 9:25:01 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	3/3/2018 9:25:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	3/3/2018 9:25:01 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	3/1/2018 9:17:06 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Error	3/1/2018 9:16:33 PM	Application Error	1000	(100)	"Faulting application name: cirratosrv.exe, version: 2013.1.3.24239, time stamp: 0x527851bf
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x24e4
Faulting application start time: 0x01d3b174798daab8
Faulting application path: C:\Program Files\Cirrato Technologies\Cirrato Client\cirratosrv.exe
Faulting module path: unknown
Report Id: b7461834-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:33 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unhandled exception - wrote memory dump to C:\Windows\TEMP\cirratosrv(2013.1.3.24239)(2018-03-01)(21.16.33).dmp
"
Error	3/1/2018 9:16:32 PM	Application Error	1000	(100)	"Faulting application name: armsvc.exe, version: 1.824.26.5200, time stamp: 0x5a7e512d
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x4fac
Faulting application start time: 0x01d3afeb2b702e2c
Faulting application path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
Faulting module path: unknown
Report Id: b68321c0-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:32 PM	Application Error	1000	(100)	"Faulting application name: cscript.exe, version: 5.8.7601.18283, time stamp: 0x5258a2c3
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x20c0
Faulting application start time: 0x01d3ab959897b66a
Faulting application path: C:\Windows\SysWOW64\cscript.exe
Faulting module path: unknown
Report Id: b64a11d0-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:32 PM	Application Error	1000	(100)	"Faulting application name: cmd.exe, version: 6.1.7601.17514, time stamp: 0x4ce78e2b
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x18b0
Faulting application start time: 0x01d3ab95988bcf03
Faulting application path: C:\Windows\SysWOW64\cmd.exe
Faulting module path: unknown
Report Id: b6408f28-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:30 PM	Application Error	1000	(100)	"Faulting application name: o2flash.exe, version: 1.0.0.3, time stamp: 0x45371e37
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x1fb4
Faulting application start time: 0x01d3ab90ad562fc9
Faulting application path: C:\Windows\system32\DRIVERS\o2flash.exe
Faulting module path: unknown
Report Id: b57d98b4-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:29 PM	Application Error	1000	(100)	"Faulting application name: NwSapAutoWorkstationUpdateService.exe, version: 9.0.20.0, time stamp: 0x5084f9bb
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x1fb8
Faulting application start time: 0x01d3ab90ab1622c6
Faulting application path: C:\Program Files (x86)\SAP\SAPsetup\Setup\Updater\NwSapAutoWorkstationUpdateService.exe
Faulting module path: unknown
Report Id: b4c8e63c-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:28 PM	Application Error	1000	(100)	"Faulting application name: obexsrv.exe, version: 2.6.1212.296, time stamp: 0x50bc8884
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x1dd8
Faulting application start time: 0x01d3ab90a9f61c45
Faulting application path: C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
Faulting module path: unknown
Report Id: b43effb8-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:27 PM	Application Error	1000	(100)	"Faulting application name: mediasrv.exe, version: 2.6.1212.296, time stamp: 0x50bc883f
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x1c08
Faulting application start time: 0x01d3ab90a8a418de
Faulting application path: C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
Faulting module path: unknown
Report Id: b3a6d538-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:27 PM	Application Error	1000	(100)	"Faulting application name: devmonsrv.exe, version: 2.6.1212.300, time stamp: 0x50c99318
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0x12ec
Faulting application start time: 0x01d3ab90a8049cac
Faulting application path: C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
Faulting module path: unknown
Report Id: b3539dfa-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:22 PM	Application Error	1000	(100)	"Faulting application name: srvany.exe, version: 0.0.0.0, time stamp: 0x3ea0a111
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xf1c
Faulting application start time: 0x01d3ab902aefcdc6
Faulting application path: C:\Windows\SysWOW64\srvany.exe
Faulting module path: unknown
Report Id: b053a77c-1d67-11e8-b496-204747d02364"
Information	3/1/2018 9:16:21 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	3/1/2018 9:16:21 PM	Application Error	1000	(100)	"Faulting application name: mfeann.exe, version: 15.6.0.1551, time stamp: 0x58d4595a
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xd18
Faulting application start time: 0x01d3ab901fd0dffe
Faulting application path: C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
Faulting module path: unknown
Report Id: afce824c-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:20 PM	Application Error	1000	(100)	"Faulting application name: vstskmgr.exe, version: 8.8.0.1804, time stamp: 0x58db0988
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xc4c
Faulting application start time: 0x01d3ab9015e7651a
Faulting application path: C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
Faulting module path: unknown
Report Id: af826d0c-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:20 PM	Application Error	1000	(100)	"Faulting application name: MfeEpeHost.exe, version: 7.1.3.547, time stamp: 0x55758179
Faulting module name: MfeEpeEpoPlugin.dll, version: 7.1.3.547, time stamp: 0x557583e8
Exception code: 0xc0000409
Fault offset: 0x002f74ac
Faulting process id: 0xc28
Faulting application start time: 0x01d3ab90158cf0d0
Faulting application path: C:\Program Files\McAfee\Endpoint Encryption Agent\MfeEpeHost.exe
Faulting module path: C:\Program Files\McAfee\Endpoint Encryption Agent\MfeEpeEpoPlugin.dll
Report Id: af5c626c-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:20 PM	Application Error	1000	(100)	"Faulting application name: F5MachineCertService.exe, version: 7132.2017.404.2206, time stamp: 0x58e42041
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xa68
Faulting application start time: 0x01d3ab900f9be181
Faulting application path: C:\Windows\SysWOW64\F5MachineCertService.exe
Faulting module path: unknown
Report Id: af319678-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:19 PM	Application Error	1000	(100)	"Faulting application name: HipMgmt.exe, version: 8.0.0.4210, time stamp: 0x58db0356
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xa10
Faulting application start time: 0x01d3ab900d94f585
Faulting application path: C:\Program Files (x86)\McAfee\Host Intrusion Prevention\HipMgmt.exe
Faulting module path: unknown
Report Id: aed4dc92-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:18 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unhandled exception - wrote memory dump to C:\Windows\TEMP\cirratosrv(2013.1.3.24239)(2018-03-01)(21.16.17).dmp
"
Error	3/1/2018 9:16:16 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.2.0.147, time stamp: 0x5a30358a
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02b9749c
Faulting process id: 0xa1c
Faulting application start time: 0x01d3ab8fd69c2e31
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: unknown
Report Id: acc2a87c-1d67-11e8-b496-204747d02364"
Error	3/1/2018 9:16:15 PM	.NET Runtime	1026	None	Application: DeviceManagerApi.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 02B9749C

Warning	3/1/2018 9:15:41 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2168 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1536 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	3/1/2018 9:15:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	3/1/2018 9:15:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	3/1/2018 9:15:37 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	3/1/2018 9:14:39 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	3/1/2018 8:59:54 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/1/2018 8:59:33 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/1/2018 8:59:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	3/1/2018 8:57:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f4dc3ac-1d65-11e8-b496-204747d02364
Report Status: 0"
Warning	3/1/2018 8:24:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	3/1/2018 7:03:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	3/1/2018 6:24:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 5:53:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 5:52:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2018 4:27:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 4:10:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	3/1/2018 4:05:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/1/2018 4:05:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38989)(?)])(1 )(2 )]

"
Information	3/1/2018 4:05:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38989)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2018 4:05:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/1/2018 4:05:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2018 4:05:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/1/2018 3:57:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 250f4fda-1d3b-11e8-b496-204747d02364
Report Status: 0"
Warning	3/1/2018 2:42:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 1:52:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 1:52:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2018 1:08:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 12:15:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8818.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	3/1/2018 11:17:28 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	3/1/2018 11:16:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 11:12:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	3/1/2018 11:12:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39282)(?)])(1 )(2 )]

"
Information	3/1/2018 11:12:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39282)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2018 11:12:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	3/1/2018 11:12:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2018 11:12:24 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	3/1/2018 10:57:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3b485c5e-1d11-11e8-b496-204747d02364
Report Status: 0"
Information	3/1/2018 10:51:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2018 10:51:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:04Z. Reason: GVLK.
Information	3/1/2018 10:46:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2018 10:46:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2018 10:46:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2018 10:46:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	3/1/2018 10:12:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	3/1/2018 10:12:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	3/1/2018 9:52:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 9:52:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2018 9:27:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/1/2018 7:43:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	3/1/2018 6:00:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 5:57:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 51a13461-1ce7-11e8-b496-204747d02364
Report Status: 0"
Information	3/1/2018 5:52:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 5:52:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 5:52:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	3/1/2018 4:04:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 3:57:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2018 3:57:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:18Z. Reason: GVLK.
Information	3/1/2018 3:52:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2018 3:52:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2018 3:52:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2018 3:52:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	3/1/2018 3:49:33 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	3/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	3/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:43Z. Reason: GVLK.
Error	3/1/2018 3:39:12 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	3/1/2018 3:38:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	3/1/2018 3:38:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	3/1/2018 3:38:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	3/1/2018 3:38:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	3/1/2018 2:22:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	3/1/2018 1:52:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 1:52:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 1:51:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	3/1/2018 12:57:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 67f9d44d-1cbd-11e8-b496-204747d02364
Report Status: 0"
Warning	3/1/2018 12:26:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 11:42:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 11:42:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:23Z. Reason: GVLK.
Information	2/28/2018 11:37:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 11:37:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 11:37:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 11:37:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/28/2018 10:36:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 9:52:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:52:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:51:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:51:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/28/2018 9:26:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 9:21:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/28/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40113)(?)])(1 )(2 )]

"
Information	2/28/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40113)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 9:21:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/28/2018 9:21:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 9:21:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/28/2018 9:15:41 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/28/2018 9:04:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 7:57:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7e40681b-1c93-11e8-b496-204747d02364
Report Status: 0"
Warning	2/28/2018 7:13:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/28/2018 7:03:14 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/28/2018 5:52:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:52:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:51:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:51:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/28/2018 5:30:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/28/2018 5:15:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/28/2018 3:50:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 2:57:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 93b9299c-1c69-11e8-b496-204747d02364
Report Status: 0"
Information	2/28/2018 2:44:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/28/2018 2:44:51 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/28/2018 2:44:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/28/2018 2:44:36 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/28/2018 2:44:34 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 7, Compared: 20669, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/28/2018 2:42:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	2/28/2018 1:56:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 1:52:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:52:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:51:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:51:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 12:55:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8817.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/28/2018 12:10:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 11:03:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 11:03:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:54:22Z. Reason: GVLK.
Information	2/28/2018 10:58:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 10:58:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 10:58:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 10:58:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2018 10:29:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 10:29:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-03-07T04:53:45Z. Reason: GVLK.
Information	2/28/2018 10:24:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 10:24:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 10:24:44 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/02/28 04:54"
Information	2/28/2018 10:24:43 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/02/28 04:54, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	2/28/2018 10:23:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 10:19:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 10:19:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 10:19:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 10:19:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2018 9:57:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9d346f7-1c3f-11e8-b496-204747d02364
Report Status: 0"
Information	2/28/2018 9:52:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:51:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:51:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 9:50:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/28/2018 9:50:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/28/2018 8:24:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 7:25:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎28T01:55:47.080100900Z.
Information	2/28/2018 7:25:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎28T01:55:45.569949900Z.
Information	2/28/2018 7:25:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2097058\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 21700.
Information	2/28/2018 7:25:50 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎28T01:55:44.759868900Z.
Information	2/28/2018 7:25:50 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.52.32954. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	2/28/2018 7:25:50 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	2/28/2018 7:25:49 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	2/28/2018 7:25:47 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 7:25:47 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 7:25:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎28T01:55:47.080100900Z.
Information	2/28/2018 7:25:47 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 7:25:47 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 7:25:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎28T01:55:45.569949900Z.
Information	2/28/2018 7:25:44 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎28T01:55:44.759868900Z.
Information	2/28/2018 7:25:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2097058\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 21700.
Warning	2/28/2018 6:46:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 6:31:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 6:31:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:39Z. Reason: GVLK.
Information	2/28/2018 6:26:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 6:26:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 6:26:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 6:26:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/28/2018 5:51:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:51:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:51:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 5:51:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/28/2018 5:06:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 4:57:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0137d7c-1c15-11e8-b496-204747d02364
Report Status: 0"
Information	2/28/2018 4:55:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T23:25:30.794385200Z.
Information	2/28/2018 4:55:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T23:25:29.319385200Z.
Information	2/28/2018 4:55:34 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2096714\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 22988.
Information	2/28/2018 4:55:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T23:25:27.563385200Z.
Information	2/28/2018 4:55:33 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.52.32954. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	2/28/2018 4:55:33 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	2/28/2018 4:55:32 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	2/28/2018 4:55:30 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 4:55:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 4:55:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T23:25:30.794385200Z.
Information	2/28/2018 4:55:30 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 4:55:30 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 4:55:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T23:25:29.319385200Z.
Information	2/28/2018 4:55:27 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T23:25:27.563385200Z.
Information	2/28/2018 4:55:26 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2096714\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 22988.
Information	2/28/2018 4:31:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 4:31:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:05Z. Reason: GVLK.
Information	2/28/2018 4:26:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 4:26:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 4:26:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 4:26:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/28/2018 4:22:44 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/28/2018 4:13:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/28/2018 4:13:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:25Z. Reason: GVLK.
Error	2/28/2018 4:09:13 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/28/2018 4:08:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/28/2018 4:08:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/28/2018 4:08:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/28/2018 4:08:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/28/2018 3:26:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/28/2018 2:53:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T21:23:05.701385200Z.
Information	2/28/2018 2:53:16 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T21:23:00.425385200Z.
Information	2/28/2018 2:53:15 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T21:22:58.474385200Z.
Information	2/28/2018 2:53:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2096364\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17188.
Information	2/28/2018 2:53:15 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.52.32954. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	2/28/2018 2:53:15 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	2/28/2018 2:53:13 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	2/28/2018 2:53:05 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 2:53:05 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 2:53:05 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T21:23:05.701385200Z.
Information	2/28/2018 2:53:05 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/28/2018 2:53:05 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 15488) cannot be restarted - Application SID does not match Conductor SID..
Information	2/28/2018 2:53:00 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T21:23:00.425385200Z.
Information	2/28/2018 2:52:58 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T21:22:58.474385200Z.
Information	2/28/2018 2:52:57 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_2096364\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 17188.
Information	2/28/2018 1:51:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:51:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:51:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/28/2018 1:51:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/28/2018 1:31:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 11:57:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d631f8ec-1beb-11e8-b496-204747d02364
Report Status: 0"
Warning	2/27/2018 11:50:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 10:41:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/27/2018 10:21:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824265200_132425515520610208773403609261579977161.msi. Client Process Id: 21584.
Information	2/27/2018 10:21:18 PM	MsiInstaller	1029	None	Product: Adobe Refresh Manager. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	2/27/2018 10:21:18 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Type of System Restart: 2. Reason for Restart: 1.
Information	2/27/2018 10:21:18 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	2/27/2018 10:21:18 PM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	2/27/2018 10:21:11 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/27/2018 10:20:28 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/27/2018 10:17:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824265200_132425515520610208773403609261579977161.msi. Client Process Id: 21584.
Warning	2/27/2018 10:04:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 9:52:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 9:52:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:03Z. Reason: GVLK.
Information	2/27/2018 9:51:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 9:51:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 9:51:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/27/2018 9:51:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 9:47:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 9:47:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 9:47:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 9:46:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2018 9:43:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎27T16:07:07.259385200Z.
Information	2/27/2018 9:43:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 14604.
Information	2/27/2018 9:43:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	2/27/2018 9:43:12 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6 -- Configuration completed successfully.
Information	2/27/2018 9:43:12 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4074880. Installation success or error status: 0.
Information	2/27/2018 9:43:12 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6 - Update 'KB4074880' installed successfully.
Information	2/27/2018 9:40:09 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:09 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:08 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:08 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:07 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:06 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:05 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:40:04 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:39:53 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00005.log
Information	2/27/2018 9:39:51 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/27/2018 9:39:46 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/27/2018 9:39:46 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:39:42 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	2/27/2018 9:39:41 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00004.log
Information	2/27/2018 9:39:39 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/27/2018 9:39:36 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/27/2018 9:39:36 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:39:21 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/27/2018 9:39:20 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	2/27/2018 9:39:10 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	2/27/2018 9:38:59 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:38:58 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	2/27/2018 9:37:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎27T16:07:07.259385200Z.
Information	2/27/2018 9:36:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 14604.
Information	2/27/2018 9:36:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 9:36:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:58Z. Reason: GVLK.
Information	2/27/2018 9:30:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 9:30:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 9:30:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 9:30:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2018 9:26:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/27/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41553)(?)])(1 )(2 )]

"
Information	2/27/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41553)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 9:21:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/27/2018 9:21:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 9:21:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/27/2018 8:15:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/27/2018 7:03:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/27/2018 7:03:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/27/2018 6:57:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 6:57:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec20158c-1bc1-11e8-b496-204747d02364
Report Status: 0"
Information	2/27/2018 6:52:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/27/2018 6:52:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41702)(?)])(1 )(2 )]

"
Information	2/27/2018 6:52:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41702)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 6:52:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/27/2018 6:52:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 6:52:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/27/2018 6:42:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 6:37:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/27/2018 6:37:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41717)(?)])(1 )(2 )]

"
Information	2/27/2018 6:37:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41717)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 6:37:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/27/2018 6:37:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 6:37:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/27/2018 6:28:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 5:52:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 5:52:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:15Z. Reason: GVLK.
Information	2/27/2018 5:51:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 5:51:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/27/2018 5:51:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 5:47:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 5:47:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 5:47:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 5:47:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/27/2018 4:55:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/27/2018 3:03:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 1:57:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02615b3c-1b98-11e8-b496-204747d02364
Report Status: 0"
Information	2/27/2018 1:51:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2018 1:30:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 1:00:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8816.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/27/2018 11:52:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 9:57:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/27/2018 9:57:29 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/27/2018 9:52:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 9:50:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 9:50:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 8:57:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1897c61e-1b6e-11e8-b496-204747d02364
Report Status: 0"
Warning	2/27/2018 7:54:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/27/2018 6:15:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 5:50:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/27/2018 5:47:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 5:47:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:55Z. Reason: GVLK.
Information	2/27/2018 5:42:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 5:42:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 5:42:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 5:42:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/27/2018 4:37:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 4:04:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 4:04:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:32Z. Reason: GVLK.
Information	2/27/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 3:59:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 3:59:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2018 3:57:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2eddc7f0-1b44-11e8-b496-204747d02364
Report Status: 0"
Error	2/27/2018 3:56:30 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/27/2018 3:48:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 3:48:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:36Z. Reason: GVLK.
Error	2/27/2018 3:43:52 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/27/2018 3:43:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 3:43:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 3:43:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 3:43:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/27/2018 3:05:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 2:02:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/27/2018 2:02:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:15Z. Reason: GVLK.
Information	2/27/2018 1:57:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/27/2018 1:57:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/27/2018 1:57:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/27/2018 1:57:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/27/2018 1:50:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/27/2018 1:24:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/27/2018 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/26/2018 11:50:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 10:57:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44ef921a-1b1a-11e8-b496-204747d02364
Report Status: 0"
Warning	2/26/2018 10:01:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 9:50:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 9:26:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/26/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42993)(?)])(1 )(2 )]

"
Information	2/26/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42993)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/26/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 9:21:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/26/2018 9:05:40 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/26/2018 8:01:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/26/2018 7:03:09 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/26/2018 7:02:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/26/2018 6:20:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 5:57:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5af5ca9a-1af0-11e8-b496-204747d02364
Report Status: 0"
Information	2/26/2018 5:50:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 5:50:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2018 4:48:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 4:34:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/26/2018 4:33:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/26/2018 4:33:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/26/2018 4:28:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/26/2018 4:28:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43286)(?)])(1 )(2 )]

"
Information	2/26/2018 4:28:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43286)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 4:28:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/26/2018 4:28:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 4:28:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/26/2018 3:46:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 3:46:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:42Z. Reason: GVLK.
Information	2/26/2018 3:41:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2018 3:41:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 3:41:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 3:41:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/26/2018 2:58:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 1:50:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 1:50:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2018 12:59:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 12:57:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 70fdaa7a-1ac6-11e8-b496-204747d02364
Report Status: 0"
Information	2/26/2018 12:27:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8815.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/26/2018 11:26:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 10:45:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/26/2018 10:27:52 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/26/2018 9:50:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 9:49:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2018 9:45:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/26/2018 8:11:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 7:57:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86d95239-1a9c-11e8-b496-204747d02364
Report Status: 0"
Warning	2/26/2018 6:21:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 5:49:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 5:19:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 5:19:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:59Z. Reason: GVLK.
Information	2/26/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 5:14:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/26/2018 5:11:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/26/2018 4:58:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 4:58:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:18Z. Reason: GVLK.
Error	2/26/2018 4:53:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/26/2018 4:53:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2018 4:53:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 4:53:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 4:53:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/26/2018 4:40:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 3:59:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 3:59:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:30Z. Reason: GVLK.
Information	2/26/2018 3:54:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2018 3:54:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 3:54:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 3:54:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/26/2018 3:09:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/26/2018 3:09:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:44Z. Reason: GVLK.
Information	2/26/2018 3:04:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/26/2018 3:04:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/26/2018 3:04:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/26/2018 3:04:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/26/2018 2:59:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 2:57:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d1afe51-1a72-11e8-b496-204747d02364
Report Status: 0"
Information	2/26/2018 1:49:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/26/2018 1:49:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/26/2018 1:05:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/26/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/25/2018 11:11:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 11:00:12 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/25/2018 9:56:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b32d3be1-1a48-11e8-b496-204747d02364
Report Status: 0"
Information	2/25/2018 9:49:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 9:49:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/25/2018 9:28:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 9:26:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/25/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44433)(?)])(1 )(2 )]

"
Information	2/25/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44433)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/25/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/25/2018 7:43:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2018 5:59:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 5:49:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 5:49:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:54Z. Reason: GVLK.
Information	2/25/2018 5:49:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 5:49:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 5:44:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 5:44:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 5:44:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 5:44:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2018 4:56:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c92777f7-1a1e-11e8-b496-204747d02364
Report Status: 0"
Error	2/25/2018 4:33:42 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/25/2018 4:23:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2018 2:49:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 2:32:51 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/25/2018 2:32:51 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/25/2018 2:32:51 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/25/2018 2:32:11 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/25/2018 2:32:11 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/25/2018 2:31:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 20493, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/25/2018 2:30:33 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/25/2018 2:30:33 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/25/2018 1:49:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 1:48:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/25/2018 1:14:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 12:09:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8814.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/25/2018 11:56:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df472601-19f4-11e8-b496-204747d02364
Report Status: 0"
Warning	2/25/2018 11:34:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 10:51:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 10:51:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:59Z. Reason: GVLK.
Information	2/25/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 10:46:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 10:46:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 10:46:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2018 9:49:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 9:48:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/25/2018 9:39:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/25/2018 8:00:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 7:24:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/25/2018 7:24:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/25/2018 6:56:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f534ccf7-19ca-11e8-b496-204747d02364
Report Status: 0"
Warning	2/25/2018 6:02:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 5:49:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 5:48:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 5:05:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 5:05:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:13Z. Reason: GVLK.
Information	2/25/2018 5:00:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 5:00:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 5:00:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 5:00:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/25/2018 4:55:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/25/2018 4:46:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 4:46:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:16Z. Reason: GVLK.
Error	2/25/2018 4:41:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/25/2018 4:41:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 4:41:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 4:41:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 4:41:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/25/2018 4:23:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 3:07:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 3:07:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:56Z. Reason: GVLK.
Information	2/25/2018 3:02:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 3:02:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 3:02:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 3:02:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/25/2018 2:33:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 1:56:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0b543e99-19a1-11e8-b496-204747d02364
Report Status: 0"
Information	2/25/2018 1:49:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/25/2018 1:48:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	2/25/2018 12:38:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/25/2018 12:30:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/25/2018 12:30:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:45Z. Reason: GVLK.
Information	2/25/2018 12:25:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/25/2018 12:25:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/25/2018 12:25:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/25/2018 12:25:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/25/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/24/2018 10:43:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 9:48:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2018 9:48:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/24/2018 9:48:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2018 9:26:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/24/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/24/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45873)(?)])(1 )(2 )]

"
Information	2/24/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45873)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/24/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/24/2018 8:56:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 8:56:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 214e3037-1977-11e8-b496-204747d02364
Report Status: 0"
Information	2/24/2018 8:53:36 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/24/2018 8:53:35 PM	ESENT	102	General	Windows (15564) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/24/2018 8:48:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 10788.
Information	2/24/2018 8:48:27 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20038. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	2/24/2018 8:48:27 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	2/24/2018 8:48:27 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20038. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20038). Installation success or error status: 0.
Information	2/24/2018 8:48:27 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20038)' installed successfully.
Information	2/24/2018 8:48:05 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/24/2018 8:48:05 PM	ESENT	103	General	Windows (13768) Windows: The database engine stopped the instance (0).
Information	2/24/2018 8:48:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 10788.
Information	2/24/2018 8:47:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 14324.
Information	2/24/2018 8:47:54 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20038. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	2/24/2018 8:47:54 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	2/24/2018 8:47:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 14324.
Warning	2/24/2018 7:13:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 5:48:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2018 5:48:38 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/24/2018 5:48:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/24/2018 5:37:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 3:56:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3757bc82-194d-11e8-b496-204747d02364
Report Status: 0"
Warning	2/24/2018 3:44:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/24/2018 1:51:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 1:48:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2018 1:00:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8813.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/24/2018 12:17:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 11:29:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2018 11:29:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:48Z. Reason: GVLK.
Information	2/24/2018 11:24:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2018 11:24:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2018 11:24:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2018 11:24:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/24/2018 10:56:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4d6e89ce-1923-11e8-b496-204747d02364
Report Status: 0"
Information	2/24/2018 10:41:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/24/2018 10:17:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 9:48:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/24/2018 8:24:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/24/2018 6:50:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 5:56:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63935d9f-18f9-11e8-b496-204747d02364
Report Status: 0"
Information	2/24/2018 5:47:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/24/2018 5:09:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 4:13:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/24/2018 4:13:45 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/24/2018 3:26:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/24/2018 1:54:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/24/2018 1:47:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/24/2018 12:56:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79aabaa8-18cf-11e8-b496-204747d02364
Report Status: 0"
Information	2/24/2018 12:50:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/24/2018 12:50:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:53Z. Reason: GVLK.
Information	2/24/2018 12:45:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/24/2018 12:45:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/24/2018 12:45:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/24/2018 12:45:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/24/2018 12:08:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/23/2018 10:34:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 9:47:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2018 9:26:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/23/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/23/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47313)(?)])(1 )(2 )]

"
Information	2/23/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47313)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/23/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/23/2018 8:35:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 7:56:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8fceb391-18a5-11e8-b496-204747d02364
Report Status: 0"
Information	2/23/2018 6:47:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎02‎-‎23T13:14:09.555421100Z.
Error	2/23/2018 6:47:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/23/2018 6:44:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎02‎-‎23T13:14:09.555421100Z.
Warning	2/23/2018 6:44:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 5:47:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/23/2018 5:19:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/23/2018 5:14:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/23/2018 5:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47561)(?)])(1 )(2 )]

"
Information	2/23/2018 5:14:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47561)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2018 5:14:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/23/2018 5:14:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2018 5:14:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/23/2018 4:54:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/23/2018 4:32:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/23/2018 4:32:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/23/2018 3:16:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 2:56:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5cd8aff-187b-11e8-b496-204747d02364
Report Status: 0"
Information	2/23/2018 2:03:41 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/23/2018 1:46:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/23/2018 1:32:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 12:06:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8812.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/23/2018 11:32:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 10:44:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/23/2018 10:44:27 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/23/2018 10:37:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/23/2018 10:03:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/23/2018 10:03:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:30Z. Reason: GVLK.
Information	2/23/2018 10:01:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/23/2018 9:57:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/23/2018 9:57:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2018 9:57:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2018 9:57:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/23/2018 9:56:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bbde1288-1851-11e8-b496-204747d02364
Report Status: 0"
Information	2/23/2018 9:56:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/23/2018 9:56:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47998)(?)])(1 )(2 )]

"
Information	2/23/2018 9:56:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47998)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/23/2018 9:56:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/23/2018 9:56:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/23/2018 9:56:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/23/2018 9:49:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/23/2018 9:46:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	2/22/2018 8:30:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 7:02:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2018 6:48:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 5:27:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 5:27:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:54Z. Reason: GVLK.
Information	2/22/2018 5:22:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 5:22:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 5:22:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 5:22:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2018 4:58:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/22/2018 4:32:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/22/2018 4:15:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 88dc6878-17bd-11e8-b496-204747d02364
Report Status: 0"
Information	2/22/2018 3:08:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/22/2018 3:05:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 3:04:56 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 63, Deleted: 0, Modified: 0, Compared: 20345, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/22/2018 3:03:11 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/22/2018 3:03:10 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2215.
Information	2/22/2018 3:03:03 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 327

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1014

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	2/22/2018 3:02:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2018 3:02:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/22/2018 3:02:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49133)(?)])(1 )(2 )]

"
Information	2/22/2018 3:02:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49133)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 3:02:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2018 3:02:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 3:02:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/22/2018 3:01:59 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Warning	2/22/2018 1:32:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 12:15:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8811.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/22/2018 11:41:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 11:15:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9eba0f98-1793-11e8-b496-204747d02364
Report Status: 0"
Information	2/22/2018 10:26:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:26:12 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:26:12 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:25:59 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:25:39 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:25:30 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:25:30 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:25:30 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:25:16 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:24:56 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:24:50 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:24:50 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:24:50 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:24:37 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:24:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:24:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:24:11 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:24:11 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:24:00 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:23:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:23:35 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:23:35 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:23:35 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:23:26 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:23:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 10:23:03 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:22:54 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:22:54 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:22:54 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:22:45 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:22:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:22:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:22:12 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2215. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 1603.
Information	2/22/2018 10:22:12 AM	MsiInstaller	11729	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration failed.
Error	2/22/2018 10:22:02 AM	MsiInstaller	11303	None	Product: Office 16 Click-to-Run Extensibility Component -- Error 1303. The installer has insufficient privileges to access this directory: c:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	2/22/2018 10:20:50 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 13296.
Information	2/22/2018 10:20:46 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/22/2018 10:20:23 AM	ESENT	102	General	Windows (13768) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/22/2018 10:20:19 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/22/2018 10:20:19 AM	ESENT	103	General	Windows (6880) Windows: The database engine stopped the instance (0).
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:12 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:08 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:08 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	2/22/2018 10:20:08 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:08 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:20:08 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	2/22/2018 10:18:40 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Error	2/22/2018 10:17:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/22/2018 10:17:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/22/2018 10:17:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/22/2018 10:17:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49417)(?)])(1 )(2 )]

"
Information	2/22/2018 10:17:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49417)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 10:17:30 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	2/22/2018 10:17:30 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/22/2018 10:17:01 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	2/22/2018 10:17:01 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Skype for Business'.
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	2/22/2018 10:16:58 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	2/22/2018 10:16:57 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	2/22/2018 10:16:56 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	2/22/2018 10:16:55 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	2/22/2018 10:16:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2018 10:16:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 10:16:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	2/22/2018 10:16:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/22/2018 10:15:58 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	2/22/2018 10:15:35 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Information	2/22/2018 10:15:35 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Error	2/22/2018 10:15:35 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	2/22/2018 10:15:35 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	2/22/2018 10:15:35 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	2/22/2018 10:14:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎02‎-‎22T04:44:59.950460500Z.
Information	2/22/2018 10:13:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 10:13:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:13Z. Reason: GVLK.
Information	2/22/2018 10:08:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 10:08:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 10:08:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 10:08:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2018 9:53:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 9:43:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 9:43:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:13Z. Reason: GVLK.
Information	2/22/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 9:38:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 9:38:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/22/2018 9:29:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 9:29:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:13Z. Reason: GVLK.
Information	2/22/2018 9:29:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 9:26:03 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	2/22/2018 9:26:03 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	2/22/2018 9:23:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/22/2018 9:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/22/2018 9:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49471)(?)])(1 )(2 )]

"
Information	2/22/2018 9:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49471)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 9:23:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/22/2018 9:23:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 9:23:52 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/22/2018 9:23:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/22/2018 9:23:22 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/22/2018 9:23:14 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/22/2018 9:23:12 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/22/2018 9:23:11 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/22/2018 9:22:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/22/2018 9:22:56 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/22/2018 9:22:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/22/2018 9:22:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	2/22/2018 9:22:44 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 76 second(s) to handle the notification event (CreateSession).
Warning	2/22/2018 9:22:28 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	2/22/2018 9:21:45 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/22/2018 9:21:33 AM	ESENT	302	Logging/Recovery	Windows (6880) Windows: The database engine has successfully completed recovery steps.
Information	2/22/2018 9:21:29 AM	ESENT	301	Logging/Recovery	Windows (6880) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/22/2018 9:21:29 AM	ESENT	300	Logging/Recovery	Windows (6880) Windows: The database engine is initiating recovery steps.
Information	2/22/2018 9:21:29 AM	ESENT	102	General	Windows (6880) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/22/2018 9:21:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 9:21:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 9:21:27 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	2/22/2018 9:21:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (TabletPCPlatformInput-core)
License Id=4a411d7f-012a-e3e3-b139-5ffb9f4dce9c"
Information	2/22/2018 9:21:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	2/22/2018 9:21:26 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	2/22/2018 9:21:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 9:21:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/22/2018 9:21:04 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8810.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/22/2018 9:20:26 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:26 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/22/2018 9:20:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/22/2018 9:20:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/22/2018 9:20:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/22/2018 9:20:25 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/22/2018 9:20:24 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:24 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/22/2018 9:20:23 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/22/2018 9:20:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/22/2018 9:20:22 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:21 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/22/2018 9:20:20 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/22/2018 9:20:20 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/22/2018 9:20:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/22/2018 9:20:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/22/2018 9:20:15 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:15 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:15 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/22/2018 9:20:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3464 at 2/22/2018 9:07:36 AM (local) 2/22/2018 3:37:36 AM (UTC). This is an informational message only; no user action is required.
Information	2/22/2018 9:20:09 AM	Service1	0	None	Service started successfully.
Information	2/22/2018 9:20:06 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/22/2018 9:20:04 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/22/2018 9:20:04 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/22/2018 9:20:04 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/22/2018 9:20:04 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Error	2/22/2018 9:19:53 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/22/2018 9:19:52 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/22/2018 9:19:52 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/22/2018 9:19:49 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/22/2018 9:19:48 AM	PostgreSQL	0	None	"2018-02-22 09:19:48 IST LOG:  redirecting log output to logging collector process
2018-02-22 09:19:48 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/22/2018 9:19:44 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3724.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/22/2018 9:19:36 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/22/2018 9:18:15 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/22/2018 9:17:25 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/22/2018 9:16:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/22/2018 9:16:20 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/22/2018 9:16:21 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/22/2018 9:07:44 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/22/2018 9:07:36 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/22/2018 9:05:30 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 34 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 948 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 944 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 944 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 944 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 944 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 944 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1168 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/22/2018 9:05:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/22/2018 9:05:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/22/2018 9:05:26 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	2/22/2018 8:26:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 7:50:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/22/2018 7:50:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/22/2018 6:39:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 6:15:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5661752-1769-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/22/2018 5:07:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2018 5:06:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/22/2018 5:01:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 4:54:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 4:54:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:35Z. Reason: GVLK.
Information	2/22/2018 4:49:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 4:49:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 4:49:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 4:49:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/22/2018 4:46:30 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/22/2018 4:37:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/22/2018 4:37:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:58Z. Reason: GVLK.
Error	2/22/2018 4:33:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/22/2018 4:32:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/22/2018 4:32:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/22/2018 4:32:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/22/2018 4:32:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/22/2018 3:30:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 2:13:00 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/22/2018 2:12:12 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/22/2018 1:35:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/22/2018 1:15:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb845821-173f-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/22/2018 1:07:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2018 1:06:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/22/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/21/2018 11:42:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/21/2018 10:06:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 9:54:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2018 9:54:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:12Z. Reason: GVLK.
Information	2/21/2018 9:49:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2018 9:49:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 9:49:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2018 9:49:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2018 9:26:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/21/2018 9:21:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/21/2018 9:21:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50193)(?)])(1 )(2 )]

"
Information	2/21/2018 9:21:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50193)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 9:21:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/21/2018 9:21:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2018 9:21:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/21/2018 9:06:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2018 9:06:52 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/21/2018 9:06:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2018 8:35:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 8:15:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1c44907-1715-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/21/2018 6:39:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 5:06:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2018 5:06:35 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/21/2018 5:06:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2018 4:51:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/21/2018 4:32:50 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/21/2018 3:15:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7d8c69e-16eb-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/21/2018 3:01:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 2:21:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2018 2:21:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:50:21Z. Reason: GVLK.
Information	2/21/2018 2:16:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2018 2:16:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 2:16:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2018 2:16:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2018 1:28:08 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/21/2018 1:28:06 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	2/21/2018 1:19:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 1:06:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/21/2018 12:01:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8810.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/21/2018 11:40:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 11:38:50 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 20247, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/21/2018 11:37:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/21/2018 10:32:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/21/2018 10:31:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/21/2018 10:25:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2018 10:25:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-28T04:49:26Z. Reason: GVLK.
Information	2/21/2018 10:20:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 10:20:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 10:20:25 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/02/21 04:50"
Information	2/21/2018 10:20:24 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/02/21 04:50, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/21/2018 10:15:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e0bad8b-16c2-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/21/2018 10:15:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2018 10:15:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 10:15:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2018 10:15:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/21/2018 9:53:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 9:40:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/21/2018 9:06:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2018 7:53:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/21/2018 6:05:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 5:15:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2438b518-1698-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/21/2018 5:05:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2018 4:08:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/21/2018 2:22:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 2:05:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/21/2018 2:05:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:20Z. Reason: GVLK.
Information	2/21/2018 2:00:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/21/2018 2:00:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/21/2018 2:00:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/21/2018 2:00:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/21/2018 1:05:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/21/2018 12:50:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/21/2018 12:15:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3a769c16-166e-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/20/2018 11:57:50 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/20/2018 11:03:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 9:26:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/20/2018 9:21:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/20/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51633)(?)])(1 )(2 )]

"
Information	2/20/2018 9:21:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51633)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2018 9:21:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/20/2018 9:21:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2018 9:21:49 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/20/2018 9:18:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 9:05:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/20/2018 7:30:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 7:15:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 509133f1-1644-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/20/2018 5:40:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 5:05:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	2/20/2018 4:32:41 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/20/2018 4:00:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 2:15:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 66c281cf-161a-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/20/2018 2:12:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 1:05:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/20/2018 12:21:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 12:12:34 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8809.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/20/2018 10:49:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 10:11:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/20/2018 10:11:16 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/20/2018 10:11:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/20/2018 9:29:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2018 9:29:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:31Z. Reason: GVLK.
Information	2/20/2018 9:24:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2018 9:24:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2018 9:24:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2018 9:24:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/20/2018 9:21:59 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/20/2018 9:21:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2018 9:21:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:01Z. Reason: GVLK.
Information	2/20/2018 9:20:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/20/2018 9:16:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2018 9:16:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2018 9:16:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2018 9:16:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/20/2018 9:15:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/20/2018 9:15:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52359)(?)])(1 )(2 )]

"
Information	2/20/2018 9:15:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52359)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2018 9:15:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/20/2018 9:15:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2018 9:15:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/20/2018 9:15:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7ce48540-15f0-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/20/2018 9:14:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/20/2018 9:14:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/20/2018 9:13:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/20/2018 9:13:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:22Z. Reason: GVLK.
Error	2/20/2018 9:08:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/20/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/20/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/20/2018 9:08:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/20/2018 9:08:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/20/2018 9:07:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/20/2018 9:05:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	2/19/2018 6:53:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/19/2018 6:33:35 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/19/2018 5:50:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 40450f74-156f-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/19/2018 5:43:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 5:42:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 5:42:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/19/2018 5:16:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 5:04:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 5:04:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:22Z. Reason: GVLK.
Information	2/19/2018 4:59:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 4:59:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 4:59:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 4:59:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/19/2018 4:53:35 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/19/2018 4:41:02 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/19/2018 4:38:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 4:38:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:46Z. Reason: GVLK.
Information	2/19/2018 4:33:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 4:33:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 4:33:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 4:33:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/19/2018 4:32:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/19/2018 4:32:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/19/2018 3:43:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 2:22:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 2:22:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:12Z. Reason: GVLK.
Information	2/19/2018 2:17:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 2:17:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 2:17:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 2:17:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/19/2018 2:02:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 1:42:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 1:42:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 1:41:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 12:50:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 56825e7d-1545-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/19/2018 12:04:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 10:50:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 10:50:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:42Z. Reason: GVLK.
Information	2/19/2018 10:45:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 10:45:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 10:45:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 10:45:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/19/2018 10:20:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 10:04:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/19/2018 10:04:21 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/19/2018 10:04:19 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/19/2018 9:42:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 9:42:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 9:41:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/19/2018 8:19:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 7:50:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6cc4b992-151b-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/19/2018 6:20:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 5:42:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 5:41:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 4:44:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 4:44:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:55Z. Reason: GVLK.
Information	2/19/2018 4:39:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 4:39:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 4:39:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 4:39:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/19/2018 4:36:54 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	2/19/2018 4:30:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 4:28:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 4:28:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:07Z. Reason: GVLK.
Error	2/19/2018 4:23:27 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/19/2018 4:23:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 4:23:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 4:23:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 4:23:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/19/2018 2:50:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 82fe56a3-14f1-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/19/2018 2:30:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 1:42:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 1:41:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/19/2018 12:46:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/19/2018 12:46:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:31Z. Reason: GVLK.
Warning	2/19/2018 12:44:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/19/2018 12:41:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/19/2018 12:41:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/19/2018 12:41:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/19/2018 12:41:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/19/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/18/2018 10:51:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 9:50:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9931e16c-14c7-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/18/2018 9:42:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 9:41:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 9:41:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/18/2018 9:41:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 9:26:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/18/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54513)(?)])(1 )(2 )]

"
Information	2/18/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54513)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/18/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 9:21:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/18/2018 8:51:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/18/2018 6:53:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 5:42:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 5:41:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2018 5:14:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 4:50:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: af5d49ba-149d-11e8-a1e9-204747d02364
Report Status: 0"
Error	2/18/2018 4:32:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/18/2018 4:32:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/18/2018 3:15:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 1:41:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 1:41:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/18/2018 1:41:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2018 1:32:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 12:38:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8808.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/18/2018 12:30:19 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/18/2018 12:30:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/18/2018 12:30:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/18/2018 11:50:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c587870d-1473-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/18/2018 11:43:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 11:30:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 20089, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/18/2018 11:30:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/18/2018 11:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/18/2018 11:01:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 11:01:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:50Z. Reason: GVLK.
Information	2/18/2018 10:56:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 10:56:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 10:56:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 10:56:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/18/2018 10:07:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 9:41:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2018 8:32:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 6:50:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dbc9702a-1449-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/18/2018 6:46:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 5:41:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/18/2018 4:49:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 4:01:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 4:01:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:55Z. Reason: GVLK.
Information	2/18/2018 3:56:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 3:56:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 3:56:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 3:56:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/18/2018 3:53:47 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/18/2018 3:39:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 3:39:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:39Z. Reason: GVLK.
Error	2/18/2018 3:34:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/18/2018 3:34:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 3:34:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 3:34:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 3:34:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/18/2018 3:21:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 3:21:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:31Z. Reason: GVLK.
Information	2/18/2018 3:16:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 3:16:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 3:16:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 3:16:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/18/2018 2:55:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 1:50:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f227cb44-141f-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/18/2018 1:40:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/18/2018 1:35:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/18/2018 1:35:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/18/2018 1:20:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/18/2018 1:14:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 1:14:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:02Z. Reason: GVLK.
Information	2/18/2018 1:09:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 1:09:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 1:09:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 1:09:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/18/2018 12:57:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/18/2018 12:57:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:12Z. Reason: GVLK.
Information	2/18/2018 12:52:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/18/2018 12:52:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/18/2018 12:52:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/18/2018 12:52:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/18/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/17/2018 11:30:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2018 9:57:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 9:40:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 9:40:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 9:26:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/17/2018 9:21:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/17/2018 9:21:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55953)(?)])(1 )(2 )]

"
Information	2/17/2018 9:21:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55953)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2018 9:21:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/17/2018 9:21:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2018 9:21:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/17/2018 8:50:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 085f752d-13f6-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/17/2018 8:19:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2018 6:27:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 5:40:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 5:40:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2018 4:55:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/17/2018 4:32:05 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/17/2018 3:50:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1e9f8458-13cc-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/17/2018 3:20:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/17/2018 3:20:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:36Z. Reason: GVLK.
Information	2/17/2018 3:15:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/17/2018 3:15:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/17/2018 3:15:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/17/2018 3:15:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/17/2018 2:56:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 1:40:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 1:40:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 1:31:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/17/2018 1:30:45 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/17/2018 1:00:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 12:22:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8807.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/17/2018 11:02:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 10:50:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 34d67a7c-13a2-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/17/2018 9:40:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 9:40:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 9:40:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/17/2018 9:26:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2018 7:32:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2018 5:54:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 5:50:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b0e40e3-1378-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/17/2018 5:40:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 5:40:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/17/2018 4:16:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/17/2018 2:24:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/17/2018 1:40:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 1:40:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/17/2018 12:50:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 615be9e3-134e-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/17/2018 12:28:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 11:53:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 11:53:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:19Z. Reason: GVLK.
Information	2/16/2018 11:48:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2018 11:48:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 11:48:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 11:48:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/16/2018 10:27:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 9:40:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2018 9:40:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2018 9:26:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/16/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57393)(?)])(1 )(2 )]

"
Information	2/16/2018 9:21:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57393)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 9:21:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 8:30:04 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/16/2018 8:30:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	2/16/2018 8:28:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 8:01:56 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/16/2018 7:49:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 77abd93b-1324-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/16/2018 6:40:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 6:38:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 6:32:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/16/2018 6:32:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57562)(?)])(1 )(2 )]

"
Information	2/16/2018 6:32:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57562)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 6:32:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2018 6:32:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 6:32:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 5:40:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2018 5:39:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2018 4:39:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/16/2018 4:31:55 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/16/2018 4:31:55 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/16/2018 2:50:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 2:49:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8da16d90-12fa-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/16/2018 2:31:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 2:26:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/16/2018 2:26:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57808)(?)])(1 )(2 )]

"
Information	2/16/2018 2:26:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57808)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 2:26:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2018 2:26:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 2:26:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 1:40:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/16/2018 1:40:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/16/2018 1:39:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/16/2018 12:58:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 12:05:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8806.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/16/2018 11:23:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 10:25:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 10:25:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:18Z. Reason: GVLK.
Information	2/16/2018 10:20:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2018 10:20:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 10:20:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 10:20:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 10:14:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 10:14:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:09Z. Reason: GVLK.
Error	2/16/2018 10:11:15 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/16/2018 10:09:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2018 10:09:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 10:09:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 10:09:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 9:55:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 9:55:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:44Z. Reason: GVLK.
Information	2/16/2018 9:55:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 9:50:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2018 9:50:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 9:50:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 9:50:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 9:50:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/16/2018 9:50:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58084)(?)])(1 )(2 )]

"
Information	2/16/2018 9:50:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58084)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 9:50:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/16/2018 9:50:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 9:50:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/16/2018 9:49:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a3e44655-12d0-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/16/2018 9:49:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/16/2018 9:49:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:21Z. Reason: GVLK.
Error	2/16/2018 9:43:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/16/2018 9:43:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/16/2018 9:43:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/16/2018 9:43:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/16/2018 9:43:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/16/2018 9:42:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/16/2018 9:39:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/16/2018 9:39:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/16/2018 9:39:49 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/16/2018 9:39:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/15/2018 6:27:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 6:19:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2018 6:19:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/15/2018 4:39:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 4:37:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ecbb5b5-1240-11e8-a1e9-204747d02364
Report Status: 0"
Error	2/15/2018 4:31:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/15/2018 4:31:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/15/2018 2:54:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 2:19:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/15/2018 1:21:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 1:00:03 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/15/2018 12:59:57 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/15/2018 12:49:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 12:44:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/15/2018 12:44:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59350)(?)])(1 )(2 )]

"
Information	2/15/2018 12:44:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59350)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 12:44:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2018 12:44:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 12:44:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/15/2018 12:32:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 12:32:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:47Z. Reason: GVLK.
Information	2/15/2018 12:27:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2018 12:27:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 12:27:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 12:27:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2018 12:06:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8805.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/15/2018 11:40:46 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 2, Compared: 20007, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/15/2018 11:39:57 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	2/15/2018 11:37:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74f9e92b-1216-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/15/2018 11:27:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 10:24:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 10:19:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2018 10:19:15 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/15/2018 10:19:12 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 406

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	2/15/2018 10:19:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/15/2018 10:18:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/15/2018 10:18:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59496)(?)])(1 )(2 )]

"
Information	2/15/2018 10:18:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59496)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 10:18:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/15/2018 10:18:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 10:18:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/15/2018 9:46:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/15/2018 8:06:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 6:37:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b33ab1d-11ec-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/15/2018 6:32:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/15/2018 5:00:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 3:57:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 3:57:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:01Z. Reason: GVLK.
Information	2/15/2018 3:52:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2018 3:52:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 3:52:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 3:52:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/15/2018 3:49:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/15/2018 3:44:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 3:44:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:03Z. Reason: GVLK.
Error	2/15/2018 3:39:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/15/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 3:39:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/15/2018 3:15:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 2:37:12 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/15/2018 2:36:37 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/15/2018 1:39:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/15/2018 1:37:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a176505d-11c2-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/15/2018 12:14:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/15/2018 12:14:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:46:09Z. Reason: GVLK.
Information	2/15/2018 12:09:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/15/2018 12:09:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/15/2018 12:09:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/15/2018 12:09:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/15/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/15/2018 12:01:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2018 10:13:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 9:26:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60273)(?)])(1 )(2 )]

"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60273)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/14/2018 8:37:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b7b9591c-1198-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/14/2018 8:22:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/14/2018 8:20:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 8:17:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/14/2018 8:17:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60338)(?)])(1 )(2 )]

"
Information	2/14/2018 8:17:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60338)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 8:17:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/14/2018 8:17:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 8:17:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/14/2018 8:02:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 7:57:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/14/2018 7:57:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60358)(?)])(1 )(2 )]

"
Information	2/14/2018 7:57:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60358)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 7:57:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/14/2018 7:57:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 7:57:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/14/2018 7:53:25 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	2/14/2018 7:53:06 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/14/2018 7:53:05 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	2/14/2018 6:28:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 4:42:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2018 4:42:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/14/2018 4:38:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/14/2018 4:35:00 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:31:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:29:57 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:04:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:04:01 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:03:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:01:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:00:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 4:00:32 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 3:59:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 3:58:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/14/2018 3:57:06 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/14/2018 3:37:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cdf3c1e2-116e-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/14/2018 3:20:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 3:20:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:44Z. Reason: GVLK.
Information	2/14/2018 3:15:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2018 3:15:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 3:15:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 3:15:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/14/2018 2:43:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2018 1:10:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 12:42:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2018 12:02:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8804.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/14/2018 11:26:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 10:37:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e3eb2cb7-1144-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/14/2018 10:21:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 10:21:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-21T04:45:12Z. Reason: GVLK.
Information	2/14/2018 10:16:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 10:16:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 10:16:11 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/02/14 04:46"
Information	2/14/2018 10:16:11 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/02/14 04:46, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/14/2018 10:11:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2018 10:11:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 10:11:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 10:11:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/14/2018 9:48:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 8:41:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2018 8:41:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/14/2018 8:14:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/14/2018 6:14:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 5:45:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 5:45:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:07Z. Reason: GVLK.
Information	2/14/2018 5:40:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2018 5:40:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 5:40:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 5:40:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/14/2018 5:37:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fa4d11e6-111a-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 4:43:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:51Z. Reason: GVLK.
Information	2/14/2018 4:41:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2018 4:38:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2018 4:38:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 4:38:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 4:38:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/14/2018 4:35:57 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	2/14/2018 4:29:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 4:26:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/14/2018 4:26:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:54Z. Reason: GVLK.
Error	2/14/2018 4:22:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/14/2018 4:21:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/14/2018 4:21:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/14/2018 4:21:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/14/2018 4:21:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/14/2018 4:03:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/14/2018 4:02:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/14/2018 2:51:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 2:20:31 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/14/2018 2:17:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/14/2018 1:10:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/14/2018 12:41:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/14/2018 12:36:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 107f7614-10f1-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/14/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/13/2018 11:43:09 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/13/2018 11:43:09 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/13/2018 11:43:09 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/13/2018 11:43:09 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/13/2018 11:43:09 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/13/2018 11:29:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/13/2018 9:46:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 9:26:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/13/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61713)(?)])(1 )(2 )]

"
Information	2/13/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61713)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/13/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/13/2018 8:41:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2018 8:33:59 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/13/2018 8:33:58 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/13/2018 7:52:59 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/13/2018 7:52:58 PM	ESENT	102	General	Windows (14592) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	2/13/2018 7:52:09 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/13/2018 7:52:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15540.
Information	2/13/2018 7:52:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20036. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	2/13/2018 7:52:09 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	2/13/2018 7:52:09 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20036. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.011.20036). Installation success or error status: 0.
Information	2/13/2018 7:52:09 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.011.20036)' installed successfully.
Information	2/13/2018 7:52:08 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	2/13/2018 7:52:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/13/2018 7:51:43 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/13/2018 7:51:43 PM	ESENT	103	General	Windows (6476) Windows: The database engine stopped the instance (0).
Information	2/13/2018 7:51:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15540.
Information	2/13/2018 7:51:30 PM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE\MCSHIELD.EXE was blocked by rule Common Standard Protection:Prevent termination of McAfee processes.
Information	2/13/2018 7:51:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15540.
Information	2/13/2018 7:51:26 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.011.20036. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	2/13/2018 7:51:26 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	2/13/2018 7:51:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15540.
Warning	2/13/2018 7:48:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 7:47:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824261196_204946017547216341144765309360452432.msi. Client Process Id: 8436.
Information	2/13/2018 7:47:34 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	2/13/2018 7:47:34 PM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	2/13/2018 7:47:34 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/13/2018 7:47:32 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/13/2018 7:47:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824261196_204946017547216341144765309360452432.msi. Client Process Id: 8436.
Information	2/13/2018 7:36:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 26e037d9-10c7-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/13/2018 7:23:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 7:18:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/13/2018 7:18:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61836)(?)])(1 )(2 )]

"
Information	2/13/2018 7:18:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61836)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 7:18:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/13/2018 7:18:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 7:18:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/13/2018 7:14:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 7:14:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:04Z. Reason: GVLK.
Information	2/13/2018 7:09:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 7:09:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 7:09:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 7:09:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/13/2018 5:55:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/13/2018 4:47:51 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/13/2018 4:41:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2018 3:56:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 2:36:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d3a1b82-109d-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/13/2018 2:11:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 12:41:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2018 12:33:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8803.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Warning	2/13/2018 12:33:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 10:51:15 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	2/13/2018 10:51:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 10:50:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/13/2018 10:48:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 10:48:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:26Z. Reason: GVLK.
Information	2/13/2018 10:43:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 10:43:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 10:43:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 10:43:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2018 9:36:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5368f7f8-1073-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/13/2018 9:19:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 8:43:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/13/2018 8:41:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2018 7:48:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 6:35:23 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/13/2018 6:35:03 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	2/13/2018 5:54:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 5:46:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 5:46:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:13Z. Reason: GVLK.
Information	2/13/2018 5:41:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 5:41:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 5:41:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 5:41:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2018 4:41:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2018 4:36:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69bbfe17-1049-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/13/2018 4:11:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 3:28:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 3:28:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:02Z. Reason: GVLK.
Information	2/13/2018 3:23:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 3:23:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 3:23:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 3:23:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/13/2018 3:20:16 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/13/2018 3:13:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 3:13:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:35Z. Reason: GVLK.
Error	2/13/2018 3:08:53 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/13/2018 3:08:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 3:08:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 3:08:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 3:08:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/13/2018 2:31:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 1:07:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/13/2018 1:07:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:21Z. Reason: GVLK.
Information	2/13/2018 1:02:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/13/2018 1:02:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/13/2018 1:02:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/13/2018 1:02:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/13/2018 12:41:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/13/2018 12:41:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/13/2018 12:40:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/13/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	2/12/2018 11:41:51 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/12/2018 11:41:51 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/12/2018 11:41:51 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/12/2018 11:41:51 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/12/2018 11:41:51 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/12/2018 11:36:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7ff1a7e5-101f-11e8-a1e9-204747d02364
Report Status: 0"
Warning	2/12/2018 10:47:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 9:26:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63153)(?)])(1 )(2 )]

"
Information	2/12/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63153)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 9:21:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2018 9:21:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 9:21:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/12/2018 8:59:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 8:40:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2018 8:40:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/12/2018 8:40:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2018 7:09:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 6:36:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96454db2-0ff5-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/12/2018 6:35:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 6:30:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2018 6:30:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63325)(?)])(1 )(2 )]

"
Information	2/12/2018 6:30:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63325)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 6:30:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2018 6:30:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 6:30:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/12/2018 5:12:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/12/2018 4:47:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/12/2018 4:40:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2018 3:41:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/12/2018 1:58:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 1:36:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ac6f0ab0-0fcb-11e8-a1e9-204747d02364
Report Status: 0"
Information	2/12/2018 1:06:26 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/12/2018 1:06:24 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/12/2018 12:40:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2018 12:40:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/12/2018 12:21:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 12:20:37 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 12:15:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2018 12:15:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63699)(?)])(1 )(2 )]

"
Information	2/12/2018 12:15:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63699)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 12:15:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2018 12:15:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 12:15:36 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/12/2018 10:35:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 10:02:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8802.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/12/2018 10:00:07 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/12/2018 9:54:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 9:54:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:55Z. Reason: GVLK.
Information	2/12/2018 9:49:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 9:49:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 9:49:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 9:49:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 9:24:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 9:24:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:56Z. Reason: GVLK.
Information	2/12/2018 9:19:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 9:19:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 9:19:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 9:19:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 9:11:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 9:11:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:40Z. Reason: GVLK.
Information	2/12/2018 9:06:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 9:06:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 9:06:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 9:06:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/12/2018 9:02:10 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/12/2018 8:54:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 8:54:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:56Z. Reason: GVLK.
Information	2/12/2018 8:49:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 8:49:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 8:49:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 8:49:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 8:48:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 8:48:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:31Z. Reason: GVLK.
Information	2/12/2018 8:45:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/12/2018 8:43:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/12/2018 8:43:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 5, Deleted: 0, Modified: 2, Compared: 19852, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/12/2018 8:42:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 8:42:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 8:42:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 8:42:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 8:41:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/12/2018 8:41:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:41Z. Reason: GVLK.
Warning	2/12/2018 8:40:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/12/2018 8:40:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2018 8:40:36 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/12/2018 8:40:35 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 312

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	2/12/2018 8:40:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/12/2018 8:39:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2018 8:39:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63915)(?)])(1 )(2 )]

"
Information	2/12/2018 8:39:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63915)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 8:35:56 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	2/12/2018 8:35:14 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/12/2018 8:35:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/12/2018 8:35:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/12/2018 8:35:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63920)(?)])(1 )(2 )]

"
Information	2/12/2018 8:35:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63920)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 8:35:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/12/2018 8:35:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 8:35:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 8:35:00 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/12/2018 8:34:59 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/12/2018 8:34:58 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/12/2018 8:34:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/12/2018 8:34:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/12/2018 8:34:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/12/2018 8:34:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/12/2018 8:34:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/12/2018 8:34:38 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/12/2018 8:34:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/12/2018 8:34:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/12/2018 8:34:17 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8801.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/12/2018 8:33:57 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/12/2018 8:33:56 AM	ESENT	302	Logging/Recovery	Windows (6476) Windows: The database engine has successfully completed recovery steps.
Information	2/12/2018 8:33:55 AM	ESENT	301	Logging/Recovery	Windows (6476) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/12/2018 8:33:55 AM	ESENT	301	Logging/Recovery	Windows (6476) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00548.log.
Information	2/12/2018 8:33:55 AM	ESENT	300	Logging/Recovery	Windows (6476) Windows: The database engine is initiating recovery steps.
Information	2/12/2018 8:33:55 AM	ESENT	102	General	Windows (6476) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/12/2018 8:33:53 AM	Service1	0	None	Service started successfully.
Information	2/12/2018 8:33:48 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Error	2/12/2018 8:33:48 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/12/2018 8:33:48 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/12/2018 8:33:45 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/12/2018 8:33:44 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/12/2018 8:33:44 AM	PostgreSQL	0	None	"2018-02-12 08:33:44 IST LOG:  redirecting log output to logging collector process
2018-02-12 08:33:44 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/12/2018 8:33:44 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/12/2018 8:33:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:41 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/12/2018 8:33:41 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/12/2018 8:33:41 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/12/2018 8:33:40 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/12/2018 8:33:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/12/2018 8:33:38 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3368 at 2/11/2018 11:06:50 PM (local) 2/11/2018 5:36:50 PM (UTC). This is an informational message only; no user action is required.
Information	2/12/2018 8:33:37 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3464.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/12/2018 8:33:36 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/12/2018 8:33:35 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/12/2018 8:33:25 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/12/2018 8:33:20 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/11/2018 11:06:56 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/12/2018 8:33:20 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/12/2018 8:33:20 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/11/2018 11:06:50 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/11/2018 11:06:39 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 816 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1968 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/11/2018 11:06:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/11/2018 11:06:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/11/2018 11:06:38 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/11/2018 11:06:34 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/11/2018 9:54:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 9:54:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:25Z. Reason: GVLK.
Information	2/11/2018 9:49:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 9:49:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 9:49:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 9:49:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 9:32:19 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8801.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/11/2018 9:26:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 9:24:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 9:24:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:24Z. Reason: GVLK.
Information	2/11/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/11/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64593)(?)])(1 )(2 )]

"
Information	2/11/2018 9:21:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64593)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 9:21:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/11/2018 9:21:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 9:21:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 9:19:24 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 9:19:24 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 9:19:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 9:19:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 8:54:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 8:54:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:23Z. Reason: GVLK.
Information	2/11/2018 8:54:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a09b2497-0f3f-11e8-823b-204747d02364
Report Status: 0"
Information	2/11/2018 8:49:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 8:49:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 8:49:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 8:49:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 8:48:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 8:48:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:49Z. Reason: GVLK.
Information	2/11/2018 8:43:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 8:43:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 8:43:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 8:43:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 8:42:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 8:42:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:59Z. Reason: GVLK.
Information	2/11/2018 8:39:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 8:36:14 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/11/2018 8:34:47 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 8:34:45 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 8:34:44 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 8:34:43 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/11/2018 8:34:41 PM	ESENT	302	Logging/Recovery	Windows (8512) Windows: The database engine has successfully completed recovery steps.
Information	2/11/2018 8:34:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 8:34:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 8:34:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 8:34:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/11/2018 8:34:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64640)(?)])(1 )(2 )]

"
Information	2/11/2018 8:34:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64640)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 8:34:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/11/2018 8:34:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 8:34:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 8:34:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 8:34:37 PM	ESENT	301	Logging/Recovery	Windows (8512) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/11/2018 8:34:37 PM	ESENT	300	Logging/Recovery	Windows (8512) Windows: The database engine is initiating recovery steps.
Information	2/11/2018 8:34:36 PM	ESENT	102	General	Windows (8512) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/11/2018 8:34:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8800.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/11/2018 8:34:31 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	2/11/2018 8:34:22 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/11/2018 8:34:12 PM	Service1	0	None	Service started successfully.
Error	2/11/2018 8:34:07 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/11/2018 8:34:07 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/11/2018 8:34:05 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/11/2018 8:34:05 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/11/2018 8:34:05 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/11/2018 8:34:05 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/11/2018 8:34:05 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/11/2018 8:34:03 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/11/2018 8:34:02 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/11/2018 8:34:02 PM	PostgreSQL	0	None	"2018-02-11 20:34:02 IST LOG:  redirecting log output to logging collector process
2018-02-11 20:34:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/11/2018 8:34:02 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/11/2018 8:34:01 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/11/2018 8:34:00 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/11/2018 8:34:00 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/11/2018 8:33:59 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Warning	2/11/2018 8:33:58 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3456 at 2/11/2018 4:49:46 PM (local) 2/11/2018 11:19:46 AM (UTC). This is an informational message only; no user action is required.
Information	2/11/2018 8:33:58 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/11/2018 8:33:57 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/11/2018 8:33:57 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/11/2018 8:33:57 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/11/2018 8:33:57 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/11/2018 8:33:57 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3368.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/11/2018 8:33:56 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	2/11/2018 8:33:47 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 8:33:44 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/11/2018 8:33:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/11/2018 8:33:44 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/11/2018 4:49:52 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/11/2018 4:49:46 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/11/2018 4:49:46 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/11/2018 4:49:43 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 612 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1420 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/11/2018 4:49:42 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/11/2018 4:49:42 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/11/2018 4:49:42 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/11/2018 4:49:39 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/11/2018 4:49:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 4:49:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:14Z. Reason: GVLK.
Error	2/11/2018 4:47:39 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/11/2018 4:44:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 4:44:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 4:44:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 4:44:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 4:36:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 4:36:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:46Z. Reason: GVLK.
Error	2/11/2018 4:36:10 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/11/2018 4:34:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 4:31:01 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/11/2018 4:29:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8800.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/11/2018 4:29:31 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 4:29:30 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 4:29:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 4:29:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 4:29:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 4:29:29 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 4:29:27 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/11/2018 4:29:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/11/2018 4:29:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64885)(?)])(1 )(2 )]

"
Information	2/11/2018 4:29:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64885)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 4:29:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/11/2018 4:29:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 4:29:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 4:29:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 4:29:06 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/11/2018 4:29:01 PM	ESENT	302	Logging/Recovery	Windows (7328) Windows: The database engine has successfully completed recovery steps.
Information	2/11/2018 4:28:59 PM	ESENT	301	Logging/Recovery	Windows (7328) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/11/2018 4:28:59 PM	ESENT	300	Logging/Recovery	Windows (7328) Windows: The database engine is initiating recovery steps.
Information	2/11/2018 4:28:59 PM	ESENT	102	General	Windows (7328) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	2/11/2018 4:28:51 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/11/2018 4:28:37 PM	Service1	0	None	Service started successfully.
Error	2/11/2018 4:28:33 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/11/2018 4:28:33 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/11/2018 4:28:30 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/11/2018 4:28:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/11/2018 4:28:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/11/2018 4:28:30 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/11/2018 4:28:30 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/11/2018 4:28:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/11/2018 4:28:27 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/11/2018 4:28:25 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/11/2018 4:28:24 PM	PostgreSQL	0	None	"2018-02-11 16:28:24 IST LOG:  redirecting log output to logging collector process
2018-02-11 16:28:24 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/11/2018 4:28:24 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/11/2018 4:28:23 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/11/2018 4:28:21 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:21 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/11/2018 4:28:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/11/2018 4:28:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/11/2018 4:28:20 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3572 at 2/11/2018 3:48:29 PM (local) 2/11/2018 10:18:29 AM (UTC). This is an informational message only; no user action is required.
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/11/2018 4:28:18 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3456.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/11/2018 4:28:17 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/11/2018 4:28:09 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/11/2018 4:28:06 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 4:27:54 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/11/2018 4:27:55 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/11/2018 4:27:54 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/11/2018 4:09:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 4:09:02 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:01Z. Reason: GVLK.
Information	2/11/2018 3:59:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 3:59:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 3:59:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 3:59:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 3:56:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 3:56:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:55Z. Reason: GVLK.
Information	2/11/2018 3:54:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/11/2018 3:53:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a4dddc20-0f15-11e8-9bc0-204747d02364
Report Status: 0"
Information	2/11/2018 3:51:08 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/11/2018 3:49:40 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8800.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/11/2018 3:49:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/11/2018 3:49:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64925)(?)])(1 )(2 )]

"
Information	2/11/2018 3:49:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64925)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 3:49:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/11/2018 3:49:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 3:49:37 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 3:49:37 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 3:49:36 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 3:49:36 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/11/2018 3:49:18 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/11/2018 3:49:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/11/2018 3:49:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/11/2018 3:49:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/11/2018 3:49:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/11/2018 3:49:13 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/11/2018 3:49:12 PM	ESENT	302	Logging/Recovery	Windows (6972) Windows: The database engine has successfully completed recovery steps.
Information	2/11/2018 3:49:09 PM	ESENT	301	Logging/Recovery	Windows (6972) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/11/2018 3:49:01 PM	ESENT	301	Logging/Recovery	Windows (6972) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00547.log.
Information	2/11/2018 3:49:01 PM	ESENT	300	Logging/Recovery	Windows (6972) Windows: The database engine is initiating recovery steps.
Information	2/11/2018 3:49:01 PM	ESENT	102	General	Windows (6972) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/11/2018 3:49:00 PM	Service1	0	None	Service started successfully.
Error	2/11/2018 3:48:57 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/11/2018 3:48:51 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/11/2018 3:48:51 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/11/2018 3:48:44 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/11/2018 3:48:43 PM	PostgreSQL	0	None	"2018-02-11 15:48:43 IST LOG:  redirecting log output to logging collector process
2018-02-11 15:48:43 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/11/2018 3:48:41 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/11/2018 3:48:40 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/11/2018 3:48:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/11/2018 3:48:40 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/11/2018 3:48:40 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/11/2018 3:48:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/11/2018 3:48:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/11/2018 3:48:40 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/11/2018 3:48:33 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:33 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/11/2018 3:48:33 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/11/2018 3:48:33 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/11/2018 3:48:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/11/2018 3:48:32 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/11/2018 3:48:31 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3488 at 2/11/2018 1:31:13 AM (local) 2/10/2018 8:01:13 PM (UTC). This is an informational message only; no user action is required.
Information	2/11/2018 3:48:29 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/11/2018 3:48:27 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/11/2018 3:48:26 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/11/2018 3:48:26 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/11/2018 3:48:26 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/11/2018 3:48:26 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3572.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/11/2018 3:48:25 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/11/2018 3:48:09 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/11/2018 3:48:05 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/11/2018 3:47:53 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/11/2018 3:47:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/11/2018 3:47:54 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/11/2018 1:31:20 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/11/2018 1:31:13 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/11/2018 1:31:13 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/11/2018 1:31:11 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 420 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/11/2018 1:31:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/11/2018 1:31:10 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/11/2018 1:31:10 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/11/2018 1:31:06 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/11/2018 1:13:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/11/2018 12:27:52 AM	RasClient	20226	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	2/10/2018 10:52:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 10:09:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 05e43a5c-0e81-11e8-80cc-204747d02364
Report Status: 0"
Information	2/10/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66033)(?)])(1 )(2 )]

"
Information	2/10/2018 9:21:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66033)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/10/2018 9:06:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 8:06:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2018 8:06:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/10/2018 7:34:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/10/2018 7:31:49 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/10/2018 7:31:49 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/10/2018 7:31:49 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/10/2018 7:31:49 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/10/2018 7:31:49 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/10/2018 6:53:04 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 19875, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/10/2018 6:52:14 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/10/2018 6:52:13 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	2/10/2018 5:59:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 5:26:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 5:26:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:45Z. Reason: GVLK.
Information	2/10/2018 5:21:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2018 5:21:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 5:21:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 5:21:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/10/2018 5:09:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1370a22a-0e57-11e8-80cc-204747d02364
Report Status: 0"
Error	2/10/2018 4:36:10 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/10/2018 4:06:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2018 4:06:19 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/10/2018 4:06:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2018 4:06:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66348)(?)])(1 )(2 )]

"
Information	2/10/2018 4:06:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66348)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 4:06:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66348)(?)])(1 )(2 )]

"
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109548  Grace type=8.
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=5bb1c054-78c1-4edc-a5f5-4d988cb8aabb"
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=051836dc-1145-4ac9-998d-c664b96c5d79"
Information	2/10/2018 4:06:15 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/10/2018 4:06:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/10/2018 4:06:07 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 327

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	2/10/2018 4:03:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2018 4:03:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20271)(?)])(1 )(2 )]

"
Information	2/10/2018 4:03:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20271)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 4:03:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/10/2018 4:03:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 4:03:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/10/2018 3:59:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 2:57:40 PM	RasClient	20225	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.233.99
TunnelIpv6Address = None
Dial-in User = .
Information	2/10/2018 2:57:24 PM	RasClient	20224	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/10/2018 2:57:24 PM	RasClient	20223	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 2:57:24 PM	RasClient	20222	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 2:57:24 PM	RasClient	20221	None	CoId={E29FFB50-63D5-4A1D-8230-0FC92E140F11}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/10/2018 2:57:22 PM	RasClient	20226	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 828.
Information	2/10/2018 2:42:51 PM	RasClient	20225	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.233.99
TunnelIpv6Address = None
Dial-in User = .
Information	2/10/2018 2:42:49 PM	RasClient	20224	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/10/2018 2:42:49 PM	RasClient	20223	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 2:42:49 PM	RasClient	20222	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 2:42:49 PM	RasClient	20221	None	CoId={125DCF5F-63F2-4481-9C14-66A2C6BD3797}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/10/2018 2:42:47 PM	RasClient	20226	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 828.
Warning	2/10/2018 2:21:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 1:39:17 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/10/2018 1:28:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 1:28:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:06Z. Reason: GVLK.
Information	2/10/2018 1:23:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2018 1:23:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 1:23:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 1:23:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/10/2018 12:58:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 12:58:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:05Z. Reason: GVLK.
Information	2/10/2018 12:55:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8800.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/10/2018 12:53:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2018 12:53:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 12:53:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 12:53:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/10/2018 12:32:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/10/2018 12:28:23 PM	RasClient	20225	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.233.99
TunnelIpv6Address = None
Dial-in User = .
Information	2/10/2018 12:28:17 PM	RasClient	20224	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/10/2018 12:28:17 PM	RasClient	20223	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 12:28:17 PM	RasClient	20222	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/10/2018 12:28:17 PM	RasClient	20221	None	CoId={6A06E6DC-4D0A-4A1E-85A4-E8EEABA86DD7}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/10/2018 12:28:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 12:28:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:04Z. Reason: GVLK.
Information	2/10/2018 12:23:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2018 12:23:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 12:23:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 12:23:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/10/2018 12:21:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 12:21:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:27Z. Reason: GVLK.
Information	2/10/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/10/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20505)(?)])(1 )(2 )]

"
Information	2/10/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 12:08:35 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	2/10/2018 12:08:27 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {376484A8-B1E5-4A33-8DF8-E924965E78D2}
Error	2/10/2018 12:08:27 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {376484A8-B1E5-4A33-8DF8-E924965E78D2}
Error	2/10/2018 12:08:23 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/10/2018 12:08:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/10/2018 12:08:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20506)(?)])(1 )(2 )]

"
Information	2/10/2018 12:08:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20506)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 12:08:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/10/2018 12:08:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 12:08:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/10/2018 12:08:10 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/10/2018 12:08:09 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/10/2018 12:08:08 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/10/2018 12:08:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/10/2018 12:08:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/10/2018 12:08:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/10/2018 12:08:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/10/2018 12:07:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/10/2018 12:07:47 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/10/2018 12:07:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/10/2018 12:07:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/10/2018 12:06:41 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8799.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/10/2018 12:06:40 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/10/2018 12:06:38 PM	ESENT	302	Logging/Recovery	Windows (6500) Windows: The database engine has successfully completed recovery steps.
Information	2/10/2018 12:06:37 PM	ESENT	301	Logging/Recovery	Windows (6500) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/10/2018 12:06:37 PM	ESENT	300	Logging/Recovery	Windows (6500) Windows: The database engine is initiating recovery steps.
Information	2/10/2018 12:06:37 PM	ESENT	102	General	Windows (6500) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/10/2018 12:06:33 PM	Service1	0	None	Service started successfully.
Error	2/10/2018 12:06:28 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/10/2018 12:06:28 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/10/2018 12:06:24 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/10/2018 12:06:23 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/10/2018 12:06:23 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/10/2018 12:06:23 PM	PostgreSQL	0	None	"2018-02-10 12:06:23 IST LOG:  redirecting log output to logging collector process
2018-02-10 12:06:23 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/10/2018 12:06:22 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/10/2018 12:06:20 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:20 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/10/2018 12:06:20 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/10/2018 12:06:20 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/10/2018 12:06:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/10/2018 12:06:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/10/2018 12:06:18 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:18 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/10/2018 12:06:18 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/10/2018 12:06:18 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/10/2018 12:06:18 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/10/2018 12:06:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/10/2018 12:06:17 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/10/2018 12:06:16 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:16 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/10/2018 12:06:16 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/10/2018 12:06:16 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3420 at 2/9/2018 6:07:07 PM (local) 2/9/2018 12:37:07 PM (UTC). This is an informational message only; no user action is required.
Information	2/10/2018 12:06:16 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/10/2018 12:06:15 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/10/2018 12:06:15 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/10/2018 12:06:15 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/10/2018 12:06:15 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/10/2018 12:06:15 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3488.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/10/2018 12:06:14 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/10/2018 12:06:05 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/10/2018 12:05:58 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/10/2018 12:05:50 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/10/2018 12:05:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/10/2018 12:05:50 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/9/2018 6:07:23 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/9/2018 6:07:08 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/9/2018 6:07:07 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/9/2018 6:07:03 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 28 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1984 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/9/2018 6:07:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/9/2018 6:07:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/9/2018 6:07:02 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/9/2018 6:06:58 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/9/2018 6:05:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 6:05:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 6:05:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 6:05:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 5:57:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 5:52:10 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 531

Information	2/9/2018 5:52:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2018 5:51:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 5:51:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21603)(?)])(1 )(2 )]

"
Information	2/9/2018 5:51:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21603)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 5:51:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 5:51:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 5:51:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 5:40:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 5:40:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:35Z. Reason: GVLK.
Information	2/9/2018 5:35:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 5:35:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 5:35:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 5:35:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 5:28:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 5:28:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:13Z. Reason: GVLK.
Information	2/9/2018 5:25:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/9/2018 5:22:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2018 5:22:27 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/9/2018 5:20:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8799.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Error	2/9/2018 5:20:47 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {553458E3-FC3B-452E-9D2C-9B27CD998AF1}
Error	2/9/2018 5:20:47 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {553458E3-FC3B-452E-9D2C-9B27CD998AF1}
Information	2/9/2018 5:20:34 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 5:20:34 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 5:20:34 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 5:20:34 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/9/2018 5:20:33 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/9/2018 5:20:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 5:20:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 5:20:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 5:20:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 5:20:27 PM	ESENT	302	Logging/Recovery	Windows (7212) Windows: The database engine has successfully completed recovery steps.
Information	2/9/2018 5:20:26 PM	ESENT	301	Logging/Recovery	Windows (7212) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/9/2018 5:20:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 5:20:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21634)(?)])(1 )(2 )]

"
Information	2/9/2018 5:20:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21634)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 5:20:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 5:20:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 5:20:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 5:20:23 PM	ESENT	301	Logging/Recovery	Windows (7212) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00544.log.
Information	2/9/2018 5:20:23 PM	ESENT	300	Logging/Recovery	Windows (7212) Windows: The database engine is initiating recovery steps.
Information	2/9/2018 5:20:23 PM	ESENT	102	General	Windows (7212) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	2/9/2018 5:20:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/9/2018 5:20:03 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/9/2018 5:19:59 PM	Service1	0	None	Service started successfully.
Error	2/9/2018 5:19:54 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/9/2018 5:19:54 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/9/2018 5:19:52 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/9/2018 5:19:52 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/9/2018 5:19:51 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/9/2018 5:19:47 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/9/2018 5:19:46 PM	PostgreSQL	0	None	"2018-02-09 17:19:46 IST LOG:  redirecting log output to logging collector process
2018-02-09 17:19:46 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/9/2018 5:19:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/9/2018 5:19:46 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/9/2018 5:19:46 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/9/2018 5:19:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/9/2018 5:19:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/9/2018 5:19:45 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/9/2018 5:19:42 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3492 at 2/9/2018 9:47:43 AM (local) 2/9/2018 4:17:43 AM (UTC). This is an informational message only; no user action is required.
Information	2/9/2018 5:19:40 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/9/2018 5:19:39 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/9/2018 5:19:39 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/9/2018 5:19:39 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/9/2018 5:19:39 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/9/2018 5:19:39 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3420.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/9/2018 5:19:38 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/9/2018 5:19:30 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/9/2018 5:19:28 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 5:19:22 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/9/2018 5:19:22 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/9/2018 5:19:22 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/9/2018 5:17:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2018 5:17:42 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 15

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	2/9/2018 5:17:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 5:17:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21637)(?)])(1 )(2 )]

"
Information	2/9/2018 5:17:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21637)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 5:17:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 5:17:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 5:17:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	2/9/2018 4:36:07 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/9/2018 4:24:01 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 18174 milliseconds
Information	2/9/2018 4:17:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/9/2018 3:45:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2018 3:11:21 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 3:06:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 3:06:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21768)(?)])(1 )(2 )]

"
Information	2/9/2018 3:06:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21768)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 3:06:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 3:06:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 3:06:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 2:51:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8f6dc791-0d7a-11e8-ad8b-204747d02364
Report Status: 0"
Information	2/9/2018 2:21:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21818)(?)])(1 )(2 )]

"
Information	2/9/2018 2:16:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21818)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 2:16:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 2:16:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 2:16:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/9/2018 2:14:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2018 12:45:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 12:45:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:00Z. Reason: GVLK.
Information	2/9/2018 12:40:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 12:40:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 12:40:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 12:40:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 12:24:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 12:19:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 12:19:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21935)(?)])(1 )(2 )]

"
Information	2/9/2018 12:19:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21935)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/9/2018 12:18:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2018 12:17:51 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 18, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/9/2018 12:17:45 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	2/9/2018 12:17:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/9/2018 12:17:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 12:17:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21937)(?)])(1 )(2 )]

"
Information	2/9/2018 12:17:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 12:17:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 12:17:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 12:17:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 10:38:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 10:38:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:49Z. Reason: GVLK.
Information	2/9/2018 10:33:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 10:33:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 10:33:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 10:33:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 10:33:25 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8799.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/9/2018 10:08:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 10:08:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:46Z. Reason: GVLK.
Information	2/9/2018 10:03:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 10:03:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 10:03:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 10:03:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 10:03:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 10:03:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:35Z. Reason: GVLK.
Information	2/9/2018 9:57:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 9:57:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 9:57:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 9:57:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/9/2018 9:56:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/9/2018 9:56:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 9:56:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:00Z. Reason: GVLK.
Information	2/9/2018 9:54:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/9/2018 9:50:14 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	2/9/2018 9:49:42 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E63369B2-AC99-49FF-8611-5A8891BFE636}
Error	2/9/2018 9:49:42 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E63369B2-AC99-49FF-8611-5A8891BFE636}
Error	2/9/2018 9:49:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/9/2018 9:49:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/9/2018 9:49:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22085)(?)])(1 )(2 )]

"
Information	2/9/2018 9:49:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22085)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 9:49:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/9/2018 9:49:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 9:49:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 9:48:59 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8798.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/9/2018 9:48:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/9/2018 9:48:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/9/2018 9:48:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/9/2018 9:48:50 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 9:48:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/9/2018 9:48:47 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 9:48:47 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 9:48:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/9/2018 9:48:29 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/9/2018 9:48:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/9/2018 9:48:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/9/2018 9:48:27 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/9/2018 9:48:25 AM	ESENT	302	Logging/Recovery	Windows (5704) Windows: The database engine has successfully completed recovery steps.
Information	2/9/2018 9:48:24 AM	ESENT	301	Logging/Recovery	Windows (5704) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/9/2018 9:48:24 AM	ESENT	300	Logging/Recovery	Windows (5704) Windows: The database engine is initiating recovery steps.
Information	2/9/2018 9:48:24 AM	ESENT	102	General	Windows (5704) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/9/2018 9:48:11 AM	Service1	0	None	Service started successfully.
Error	2/9/2018 9:48:05 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/9/2018 9:48:05 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/9/2018 9:47:58 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/9/2018 9:47:57 AM	PostgreSQL	0	None	"2018-02-09 09:47:57 IST LOG:  redirecting log output to logging collector process
2018-02-09 09:47:57 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/9/2018 9:47:55 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/9/2018 9:47:54 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/9/2018 9:47:53 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/9/2018 9:47:48 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:48 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/9/2018 9:47:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/9/2018 9:47:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/9/2018 9:47:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/9/2018 9:47:47 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/9/2018 9:47:46 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3636 at 2/8/2018 5:28:11 PM (local) 2/8/2018 11:58:11 AM (UTC). This is an informational message only; no user action is required.
Information	2/9/2018 9:47:43 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/9/2018 9:47:41 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3492.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/9/2018 9:47:40 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/9/2018 9:47:37 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/9/2018 9:47:27 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/9/2018 9:47:22 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/8/2018 5:28:28 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/9/2018 9:47:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/9/2018 9:47:22 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/8/2018 5:28:11 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/8/2018 5:28:08 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 964 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/8/2018 5:28:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/8/2018 5:28:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/8/2018 5:28:07 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/8/2018 5:27:58 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/8/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 5:26:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 5:26:41 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 5:25:03 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 93

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	2/8/2018 5:25:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2018 5:24:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 5:24:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23070)(?)])(1 )(2 )]

"
Information	2/8/2018 5:24:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23070)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 5:24:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2018 5:24:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 5:24:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 5:20:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 5:20:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:08Z. Reason: GVLK.
Information	2/8/2018 5:17:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 5:14:19 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/8/2018 5:13:04 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 5:13:03 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 5:13:00 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 5:12:58 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/8/2018 5:12:45 PM	ESENT	302	Logging/Recovery	Windows (8536) Windows: The database engine has successfully completed recovery steps.
Information	2/8/2018 5:12:35 PM	ESENT	301	Logging/Recovery	Windows (8536) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/8/2018 5:12:35 PM	ESENT	300	Logging/Recovery	Windows (8536) Windows: The database engine is initiating recovery steps.
Information	2/8/2018 5:12:35 PM	ESENT	102	General	Windows (8536) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/8/2018 5:12:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 5:12:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23082)(?)])(1 )(2 )]

"
Information	2/8/2018 5:12:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23082)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 5:12:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2018 5:12:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 5:12:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 5:12:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 5:12:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 5:12:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 5:12:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 5:12:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8798.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Error	2/8/2018 5:11:49 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/8/2018 5:11:33 PM	Service1	0	None	Service started successfully.
Error	2/8/2018 5:11:26 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/8/2018 5:11:23 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/8/2018 5:10:55 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/8/2018 5:10:50 PM	PostgreSQL	0	None	"2018-02-08 17:10:50 IST LOG:  redirecting log output to logging collector process
2018-02-08 17:10:50 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/8/2018 5:10:49 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/8/2018 5:10:48 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/8/2018 5:10:47 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/8/2018 5:10:40 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/8/2018 5:10:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/8/2018 5:10:37 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/8/2018 5:10:37 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/8/2018 5:10:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/8/2018 5:10:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/8/2018 5:10:32 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:32 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/8/2018 5:10:31 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/8/2018 5:10:31 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/8/2018 5:10:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/8/2018 5:10:31 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:30 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/8/2018 5:10:29 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/8/2018 5:10:29 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/8/2018 5:10:29 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/8/2018 5:10:27 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3712 at 2/8/2018 5:01:06 PM (local) 2/8/2018 11:31:06 AM (UTC). This is an informational message only; no user action is required.
Information	2/8/2018 5:10:24 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/8/2018 5:10:24 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/8/2018 5:10:24 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/8/2018 5:10:24 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/8/2018 5:10:24 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3636.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/8/2018 5:10:20 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/8/2018 5:09:41 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/8/2018 5:09:32 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 5:09:17 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/8/2018 5:09:18 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/8/2018 5:09:17 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/8/2018 5:01:14 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/8/2018 5:01:06 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/8/2018 5:01:06 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/8/2018 5:00:52 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 28 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1988 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/8/2018 5:00:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/8/2018 5:00:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/8/2018 5:00:51 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/8/2018 3:56:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 805ed948-0cba-11e8-95fb-204747d02364
Report Status: 0"
Error	2/8/2018 3:55:14 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/8/2018 3:53:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 3:48:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 3:48:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23166)(?)])(1 )(2 )]

"
Information	2/8/2018 3:48:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23166)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/8/2018 3:48:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2018 3:47:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2018 3:47:35 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/8/2018 3:47:35 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	2/8/2018 3:47:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/8/2018 3:47:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 3:47:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23167)(?)])(1 )(2 )]

"
Information	2/8/2018 3:47:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23167)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 3:47:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2018 3:47:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 3:47:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/8/2018 1:26:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2018 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23385)(?)])(1 )(2 )]

"
Information	2/8/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 12:07:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8798.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/8/2018 11:49:20 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	2/8/2018 11:33:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2018 11:04:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 11:04:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:10Z. Reason: GVLK.
Information	2/8/2018 10:59:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 10:59:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 10:59:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 10:59:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 10:41:54 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/8/2018 10:34:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 10:34:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:07Z. Reason: GVLK.
Information	2/8/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 10:29:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 10:14:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 10:14:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:48Z. Reason: GVLK.
Information	2/8/2018 10:09:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 10:09:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 10:09:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 10:09:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/8/2018 10:07:34 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/8/2018 10:04:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 10:04:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:07Z. Reason: GVLK.
Information	2/8/2018 9:54:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 9:54:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 9:54:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 9:54:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 9:54:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/8/2018 9:54:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:56Z. Reason: GVLK.
Warning	2/8/2018 9:52:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/8/2018 9:50:52 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	2/8/2018 9:49:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/8/2018 9:49:12 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/8/2018 9:46:00 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/8/2018 9:44:46 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8797.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Error	2/8/2018 9:44:40 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7A3ED9CC-CBEA-4463-B8E5-9482CE382986}
Error	2/8/2018 9:44:40 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {7A3ED9CC-CBEA-4463-B8E5-9482CE382986}
Information	2/8/2018 9:44:37 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 9:44:36 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 9:44:36 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 9:44:35 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/8/2018 9:44:18 AM	ESENT	302	Logging/Recovery	Windows (7996) Windows: The database engine has successfully completed recovery steps.
Information	2/8/2018 9:44:17 AM	ESENT	301	Logging/Recovery	Windows (7996) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/8/2018 9:44:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/8/2018 9:44:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 9:44:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 9:44:13 AM	ESENT	301	Logging/Recovery	Windows (7996) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0053F.log.
Information	2/8/2018 9:44:13 AM	ESENT	300	Logging/Recovery	Windows (7996) Windows: The database engine is initiating recovery steps.
Information	2/8/2018 9:44:13 AM	ESENT	102	General	Windows (7996) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/8/2018 9:44:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/8/2018 9:44:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/8/2018 9:44:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23530)(?)])(1 )(2 )]

"
Information	2/8/2018 9:44:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23530)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/8/2018 9:44:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/8/2018 9:44:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/8/2018 9:44:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	2/8/2018 9:43:55 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/8/2018 9:43:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/8/2018 9:43:21 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/8/2018 9:43:21 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/8/2018 9:43:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/8/2018 9:43:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/8/2018 9:43:20 AM	Service1	0	None	Service started successfully.
Error	2/8/2018 9:43:15 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/8/2018 9:43:15 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/8/2018 9:43:11 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/8/2018 9:43:10 AM	PostgreSQL	0	None	"2018-02-08 09:43:10 IST LOG:  redirecting log output to logging collector process
2018-02-08 09:43:10 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/8/2018 9:43:10 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/8/2018 9:43:09 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/8/2018 9:43:08 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3760 at 2/8/2018 7:50:05 AM (local) 2/8/2018 2:20:05 AM (UTC). This is an informational message only; no user action is required.
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/8/2018 9:43:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3712.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/8/2018 9:43:07 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/8/2018 9:43:01 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/8/2018 9:42:52 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/8/2018 9:42:46 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/8/2018 7:50:12 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/8/2018 9:42:46 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/8/2018 9:42:46 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/8/2018 7:50:05 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/8/2018 7:50:05 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/8/2018 7:50:03 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 420 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/8/2018 7:50:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/8/2018 7:50:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/8/2018 7:50:02 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	2/7/2018 11:33:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 11:33:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 11:33:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 11:33:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 11:33:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/7/2018 9:05:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 9:05:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:18Z. Reason: GVLK.
Information	2/7/2018 9:00:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 9:00:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:00:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 9:00:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 8:45:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 8:45:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:41:08Z. Reason: GVLK.
Information	2/7/2018 8:40:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 073bed2f-0c19-11e8-8cb6-08002700381d
Report Status: 0"
Information	2/7/2018 8:40:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 8:40:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 8:40:08 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 8:40:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 8:38:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 8:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 8:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24321)(?)])(1 )(2 )]

"
Information	2/7/2018 8:33:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24321)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 8:33:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 8:33:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 8:33:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 7:19:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 7:19:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:21Z. Reason: GVLK.
Information	2/7/2018 7:14:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 7:14:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 7:14:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 7:14:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 7:07:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 7:07:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:20Z. Reason: GVLK.
Information	2/7/2018 7:05:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 7:01:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8797.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/7/2018 7:01:33 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	2/7/2018 7:00:30 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C5650903-25AB-4C12-A147-5D5DA37D0D61}
Error	2/7/2018 7:00:30 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C5650903-25AB-4C12-A147-5D5DA37D0D61}
Information	2/7/2018 7:00:09 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 7:00:08 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 7:00:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 7:00:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24414)(?)])(1 )(2 )]

"
Information	2/7/2018 7:00:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24414)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 7:00:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 7:00:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 7:00:04 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 7:00:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 6:59:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 6:59:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 6:59:55 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 6:59:45 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/7/2018 6:59:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/7/2018 6:59:42 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/7/2018 6:59:37 PM	ESENT	302	Logging/Recovery	Windows (6324) Windows: The database engine has successfully completed recovery steps.
Information	2/7/2018 6:59:33 PM	ESENT	301	Logging/Recovery	Windows (6324) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/7/2018 6:59:33 PM	ESENT	300	Logging/Recovery	Windows (6324) Windows: The database engine is initiating recovery steps.
Information	2/7/2018 6:59:33 PM	ESENT	102	General	Windows (6324) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	2/7/2018 6:59:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/7/2018 6:59:09 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/7/2018 6:59:09 PM	Service1	0	None	Service started successfully.
Information	2/7/2018 6:59:02 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/7/2018 6:58:57 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/7/2018 6:58:53 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/7/2018 6:58:52 PM	PostgreSQL	0	None	"2018-02-07 18:58:52 IST LOG:  redirecting log output to logging collector process
2018-02-07 18:58:52 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/7/2018 6:58:49 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/7/2018 6:58:49 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/7/2018 6:58:42 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/7/2018 6:58:42 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/7/2018 6:58:42 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/7/2018 6:58:41 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/7/2018 6:58:41 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/7/2018 6:58:37 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:37 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/7/2018 6:58:36 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/7/2018 6:58:36 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/7/2018 6:58:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/7/2018 6:58:36 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/7/2018 6:58:35 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/7/2018 6:58:32 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3720 at 2/7/2018 4:55:23 PM (local) 2/7/2018 11:25:23 AM (UTC). This is an informational message only; no user action is required.
Information	2/7/2018 6:58:30 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/7/2018 6:58:30 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/7/2018 6:58:30 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/7/2018 6:58:30 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/7/2018 6:58:30 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3760.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/7/2018 6:58:29 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/7/2018 6:58:07 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/7/2018 6:57:58 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 6:57:44 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/7/2018 6:57:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/7/2018 6:57:44 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/7/2018 4:55:40 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/7/2018 4:55:23 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Error	2/7/2018 4:55:14 PM	SceCli	1001	None	"Security policy cannot be propagated. Cannot access the template. Error code = 3.
	\\logon.ds.ge.com\sysvol\logon.ds.ge.com\Policies\{944fee05-2d40-4de0-8377-9b52ddd1a65f}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf."
Warning	2/7/2018 4:54:11 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 796 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1980 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/7/2018 4:54:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/7/2018 4:54:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/7/2018 4:54:10 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/7/2018 4:54:00 PM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 7394 milliseconds
Information	2/7/2018 4:53:56 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: Mtb12.exe.
Information	2/7/2018 4:24:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 4:24:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:47Z. Reason: GVLK.
Information	2/7/2018 4:19:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 4:19:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 4:19:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 4:19:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 3:54:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 3:49:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 3:49:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24605)(?)])(1 )(2 )]

"
Information	2/7/2018 3:49:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24605)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 3:49:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 3:49:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 3:49:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/7/2018 3:19:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2018 2:36:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8797.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : Generic.Tra!2b09f8c9e734 (ED)
Generic.Tra!cf816bb0c59e (ED)
"
Information	2/7/2018 2:33:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bda85bff-0be5-11e8-8037-204747d02364
Report Status: 0"
Information	2/7/2018 1:34:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/7/2018 1:22:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2018 12:35:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8797.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/7/2018 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]

"
Information	2/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	2/7/2018 11:41:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/7/2018 11:35:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2018 10:50:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 10:50:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:34Z. Reason: GVLK.
Information	2/7/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 10:45:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 10:38:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 10:33:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 10:33:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24921)(?)])(1 )(2 )]

"
Information	2/7/2018 10:33:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24921)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 10:33:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 10:33:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 10:33:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 10:20:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 10:20:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-14T04:40:34Z. Reason: GVLK.
Information	2/7/2018 10:11:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 10:11:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 10:11:09 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/02/07 04:41"
Information	2/7/2018 10:11:08 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/02/07 04:41, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	2/7/2018 10:05:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 10:05:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 10:05:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 10:05:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/7/2018 10:00:40 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/7/2018 9:50:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 9:50:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:34Z. Reason: GVLK.
Information	2/7/2018 9:45:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 9:45:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:45:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 9:45:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 9:44:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 9:44:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:38Z. Reason: GVLK.
Information	2/7/2018 9:41:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 7099, Deleted: 0, Modified: 46, Compared: 19749, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/7/2018 9:39:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 9:39:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:39:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 9:39:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 9:39:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 9:38:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/7/2018 9:38:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:06Z. Reason: GVLK.
Warning	2/7/2018 9:36:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/7/2018 9:34:44 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 5, Deleted: 0, Modified: 0, Compared: 18, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/7/2018 9:34:13 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/7/2018 9:34:09 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 374

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 219

Information	2/7/2018 9:34:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	2/7/2018 9:33:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/7/2018 9:33:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	2/7/2018 9:33:28 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	2/7/2018 9:33:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d3ce8160-0bbb-11e8-8037-204747d02364
Report Status: 0"
Error	2/7/2018 9:33:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/7/2018 9:33:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 9:33:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24981)(?)])(1 )(2 )]

"
Information	2/7/2018 9:33:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24981)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:32:19 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/7/2018 9:31:03 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8796.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	2/7/2018 9:30:39 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {A97E9820-9AAC-416A-8112-E4775FC0A706}
Error	2/7/2018 9:30:39 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {A97E9820-9AAC-416A-8112-E4775FC0A706}
Information	2/7/2018 9:30:37 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 9:30:37 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 9:30:36 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 9:30:35 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/7/2018 9:30:29 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/7/2018 9:30:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/7/2018 9:30:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:30:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 9:30:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/7/2018 9:30:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24984)(?)])(1 )(2 )]

"
Information	2/7/2018 9:30:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24984)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/7/2018 9:30:24 AM	ESENT	302	Logging/Recovery	Windows (7412) Windows: The database engine has successfully completed recovery steps.
Information	2/7/2018 9:30:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/7/2018 9:30:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/7/2018 9:30:24 AM	ESENT	301	Logging/Recovery	Windows (7412) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/7/2018 9:30:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 9:30:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/7/2018 9:30:21 AM	ESENT	301	Logging/Recovery	Windows (7412) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00498.log.
Information	2/7/2018 9:30:21 AM	ESENT	300	Logging/Recovery	Windows (7412) Windows: The database engine is initiating recovery steps.
Information	2/7/2018 9:30:21 AM	ESENT	102	General	Windows (7412) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Error	2/7/2018 9:30:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/7/2018 9:30:00 AM	Service1	0	None	Service started successfully.
Information	2/7/2018 9:29:54 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/7/2018 9:29:54 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/7/2018 9:29:54 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/7/2018 9:29:54 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/7/2018 9:29:54 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	2/7/2018 9:29:53 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/7/2018 9:29:53 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/7/2018 9:29:52 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/7/2018 9:29:51 AM	PostgreSQL	0	None	"2018-02-07 09:29:51 IST LOG:  redirecting log output to logging collector process
2018-02-07 09:29:51 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/7/2018 9:29:50 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/7/2018 9:29:50 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/7/2018 9:29:49 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/7/2018 9:29:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/7/2018 9:29:44 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3600 at 2/7/2018 8:14:11 AM (local) 2/7/2018 2:44:11 AM (UTC). This is an informational message only; no user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/7/2018 9:29:43 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3720.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/7/2018 9:29:42 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/7/2018 9:29:32 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/7/2018 9:29:24 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/7/2018 9:29:17 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/7/2018 9:29:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/7/2018 9:29:17 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/7/2018 8:14:17 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/7/2018 8:14:11 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/7/2018 8:14:11 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	2/7/2018 8:14:08 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/7/2018 8:14:08 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/7/2018 8:14:07 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/7/2018 8:14:04 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	2/7/2018 8:13:42 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 8:13:42 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 8:13:42 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 8:13:42 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/7/2018 8:13:42 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/6/2018 11:04:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 11:04:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:33Z. Reason: GVLK.
Information	2/6/2018 10:59:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 10:59:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 10:59:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 10:59:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/6/2018 10:29:17 PM	ESENT	508	Performance	"taskhost (4476) WebCacheLocal: A request to write to the file ""C:\Users\212558710\AppData\Local\Microsoft\Windows\WebCache\V01.log"" at offset 77824 (0x0000000000013000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (6938 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Information	2/6/2018 8:21:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 8:21:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:16Z. Reason: GVLK.
Information	2/6/2018 8:16:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 8:16:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 8:16:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 8:16:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 8:09:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 8:09:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:08Z. Reason: GVLK.
Information	2/6/2018 8:08:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 8:05:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f97d5812-0b4a-11e8-8d7d-204747d02364
Report Status: 0"
Information	2/6/2018 8:04:05 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	2/6/2018 8:03:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 8:03:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25790)(?)])(1 )(2 )]

"
Information	2/6/2018 8:03:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25790)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 8:03:45 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	2/6/2018 8:03:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 8:03:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25791)(?)])(1 )(2 )]

"
Information	2/6/2018 8:03:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25791)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 8:03:13 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/6/2018 8:01:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8796.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	2/6/2018 8:01:39 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {00EF8743-851A-4308-B494-FBB81D19948F}
Error	2/6/2018 8:01:39 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {00EF8743-851A-4308-B494-FBB81D19948F}
Information	2/6/2018 8:01:22 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/6/2018 8:01:22 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 8:01:22 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 8:01:22 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 8:01:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 8:01:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 8:01:21 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/6/2018 8:01:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 8:01:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 8:01:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25793)(?)])(1 )(2 )]

"
Information	2/6/2018 8:01:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25793)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 8:01:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 8:01:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 8:01:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 8:01:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 8:01:11 PM	ESENT	302	Logging/Recovery	Windows (7232) Windows: The database engine has successfully completed recovery steps.
Information	2/6/2018 8:01:11 PM	ESENT	301	Logging/Recovery	Windows (7232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/6/2018 8:01:10 PM	ESENT	301	Logging/Recovery	Windows (7232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00495.log.
Information	2/6/2018 8:01:09 PM	ESENT	300	Logging/Recovery	Windows (7232) Windows: The database engine is initiating recovery steps.
Information	2/6/2018 8:01:09 PM	ESENT	102	General	Windows (7232) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/6/2018 8:01:03 PM	Service1	0	None	Service started successfully.
Error	2/6/2018 8:01:02 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/6/2018 8:00:57 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/6/2018 8:00:57 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/6/2018 8:00:42 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/6/2018 8:00:41 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/6/2018 8:00:33 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/6/2018 8:00:32 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/6/2018 8:00:32 PM	PostgreSQL	0	None	"2018-02-06 20:00:32 IST LOG:  redirecting log output to logging collector process
2018-02-06 20:00:32 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/6/2018 8:00:31 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/6/2018 8:00:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/6/2018 8:00:28 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/6/2018 8:00:28 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/6/2018 8:00:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/6/2018 8:00:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/6/2018 8:00:24 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:24 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/6/2018 8:00:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/6/2018 8:00:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/6/2018 8:00:23 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/6/2018 8:00:22 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3548 at 2/6/2018 2:02:22 PM (local) 2/6/2018 8:32:22 AM (UTC). This is an informational message only; no user action is required.
Information	2/6/2018 8:00:20 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/6/2018 8:00:18 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3600.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/6/2018 8:00:17 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/6/2018 8:00:02 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/6/2018 7:59:58 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 7:59:47 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/6/2018 7:59:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/6/2018 7:59:47 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/6/2018 4:41:41 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/6/2018 4:41:41 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/6/2018 4:38:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 19532, Deleted: 0, Modified: 2, Compared: 19669, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/6/2018 4:33:12 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 4, Deleted: 0, Modified: 0, Compared: 11, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Warning	2/6/2018 4:00:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2018 3:22:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 3:22:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:57Z. Reason: GVLK.
Information	2/6/2018 3:17:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 3:17:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 3:17:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 3:17:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/6/2018 3:03:26 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 3:03:26 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 3:03:26 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 3:03:26 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/6/2018 2:52:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 2:52:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:57Z. Reason: GVLK.
Information	2/6/2018 2:47:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 2:47:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 2:47:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 2:47:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 2:30:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ff9c8ae-0b1c-11e8-934b-204747d02364
Report Status: 0"
Information	2/6/2018 2:23:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 2:23:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:41:00Z. Reason: GVLK.
Information	2/6/2018 2:21:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 2:18:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 2:18:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 2:18:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 2:17:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 2:16:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 2:16:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26138)(?)])(1 )(2 )]

"
Information	2/6/2018 2:16:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26138)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	2/6/2018 2:14:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2018 2:12:15 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 561

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 250

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 141

Information	2/6/2018 2:12:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2018 2:11:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 2:11:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26143)(?)])(1 )(2 )]

"
Information	2/6/2018 2:11:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26143)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 2:11:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 2:11:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 2:11:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 2:10:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 2:10:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:33Z. Reason: GVLK.
Information	2/6/2018 2:08:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 2:04:47 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/6/2018 2:03:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8796.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	2/6/2018 2:03:48 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {D5B6759E-6184-4A61-9F16-F23059B7B8FC}
Error	2/6/2018 2:03:48 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {D5B6759E-6184-4A61-9F16-F23059B7B8FC}
Error	2/6/2018 2:03:36 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/6/2018 2:03:34 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/6/2018 2:03:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 2:03:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26151)(?)])(1 )(2 )]

"
Information	2/6/2018 2:03:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26151)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 2:03:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 2:03:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 2:03:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 2:03:25 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 2:03:23 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 2:03:20 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 2:03:19 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/6/2018 2:03:11 PM	ESENT	302	Logging/Recovery	Windows (6348) Windows: The database engine has successfully completed recovery steps.
Information	2/6/2018 2:03:06 PM	ESENT	301	Logging/Recovery	Windows (6348) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/6/2018 2:03:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 2:03:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 2:03:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 2:03:04 PM	ESENT	301	Logging/Recovery	Windows (6348) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00373.log.
Information	2/6/2018 2:03:04 PM	ESENT	300	Logging/Recovery	Windows (6348) Windows: The database engine is initiating recovery steps.
Information	2/6/2018 2:03:04 PM	ESENT	102	General	Windows (6348) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/6/2018 2:03:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 2:02:41 PM	Service1	0	None	Service started successfully.
Error	2/6/2018 2:02:35 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/6/2018 2:02:35 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/6/2018 2:02:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/6/2018 2:02:33 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/6/2018 2:02:33 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/6/2018 2:02:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/6/2018 2:02:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/6/2018 2:02:32 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/6/2018 2:02:31 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/6/2018 2:02:28 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/6/2018 2:02:27 PM	PostgreSQL	0	None	"2018-02-06 14:02:27 IST LOG:  redirecting log output to logging collector process
2018-02-06 14:02:27 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/6/2018 2:02:27 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/6/2018 2:02:27 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/6/2018 2:02:26 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/6/2018 2:02:23 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3528 at 2/6/2018 9:25:56 AM (local) 2/6/2018 3:55:56 AM (UTC). This is an informational message only; no user action is required.
Information	2/6/2018 2:02:22 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/6/2018 2:02:21 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/6/2018 2:02:21 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/6/2018 2:02:21 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/6/2018 2:02:21 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/6/2018 2:02:21 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3548.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/6/2018 2:02:20 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/6/2018 2:02:11 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/6/2018 2:02:09 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 2:01:58 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/6/2018 2:01:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/6/2018 2:01:58 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/6/2018 12:15:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 12:15:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:16Z. Reason: GVLK.
Information	2/6/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 12:11:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8796.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/6/2018 12:10:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 12:10:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 12:10:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 12:10:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]

"
Information	2/6/2018 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 11:56:16 AM	GE Software	0	(1)	++Exit Code for the Install.exe installation script is: 0
Information	2/6/2018 11:56:15 AM	GE Software	0	(1)	++No Reboot requested by Minitab_12.23
Information	2/6/2018 11:56:10 AM	GE Software	0	(1)	Package Tracker MIF file created.
Information	2/6/2018 11:56:10 AM	GE Software	0	(1)	Updating Pactrack registry keys with minitab_12.23_v3
Information	2/6/2018 11:56:10 AM	GE Software	0	(1)	++This wrapper has been run 1 time(s) on this PC
Error	2/6/2018 11:56:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/6/2018 11:56:08 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	2/6/2018 11:56:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Options\Packages\Minitab_12.23\mt1223.msi. Client Process Id: 6272.
Information	2/6/2018 11:56:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎06T06:26:01.868265600Z.
Information	2/6/2018 11:56:08 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: MiniTab. Product Version: 12.23. Product Language: 1033. Manufacturer: Minitab, Inc.. Installation success or error status: 0.
Information	2/6/2018 11:56:08 AM	MsiInstaller	11707	None	Product: MiniTab -- Installation operation completed successfully.
Information	2/6/2018 11:56:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎06T06:26:01.868265600Z.
Information	2/6/2018 11:56:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Options\Packages\Minitab_12.23\mt1223.msi. Client Process Id: 6272.
Information	2/6/2018 11:55:58 AM	GE Software	0	(1)	++Pre-Rerequistie check skipped /NOCHECK option used.
Information	2/6/2018 11:55:58 AM	GE Software	0	(1)	++Installation Check - A User is currently logged into the system because the installation has detected that Explorer.exe is running.
Information	2/6/2018 11:55:55 AM	GE Software	0	(1)	++Calling the installer file named: C:\Windows\Options\Packages\Minitab_12.23\minitab_12.23_v3.exe with the following commandline: /P /IC /NOCHECK
Information	2/6/2018 11:55:52 AM	GE Software	0	(1)	++Source directory is: C:\Windows\Options\Packages\Minitab_12.23
Information	2/6/2018 11:55:52 AM	GE Software	0	(1)	++Passed the Disk Space Check.
Information	2/6/2018 11:55:52 AM	GE Software	0	(1)	++ This PC does not have a standard coreload with dual partitions. There is only a C drive!
Information	2/6/2018 11:55:51 AM	GE Software	0	(1)	++SYSDrive=C:\ and Temp is located here: C:\
Information	2/6/2018 11:55:49 AM	GE Software	0	(1)	++Passed the hardware Check. Actual Memory:4194303. Required:196608.
Information	2/6/2018 11:55:49 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	2/6/2018 11:55:49 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	2/6/2018 11:55:49 AM	GE Software	0	(1)	++No Install Check was performed.
Information	2/6/2018 11:55:49 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	2/6/2018 11:55:47 AM	GE Software	0	(1)	++ Minitab_12.23 was launched using the following Command line: /P /IC
Information	2/6/2018 11:55:47 AM	GE Software	0	(1)	++Installation Check - A User is currently logged into the system because the installation has detected that Explorer.exe is running.
Information	2/6/2018 11:55:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 11:51:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/6/2018 11:51:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:36Z. Reason: GVLK.
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26284)(?)])(1 )(2 )]

"
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26284)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 11:50:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/6/2018 11:42:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2018 11:41:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/6/2018 11:41:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	2/6/2018 11:40:51 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 11:40:51 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 11:40:51 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 11:40:51 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/6/2018 11:40:02 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/6/2018 9:30:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 361a8641-0af2-11e8-9a8e-204747d02364
Report Status: 0"
Warning	2/6/2018 9:29:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/6/2018 9:29:01 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/6/2018 9:28:45 AM	Outlook	29	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst is being re-pushed to the indexer for the following reason: Index reset (or catalog signature changed), re-push entire store.
Information	2/6/2018 9:28:45 AM	Outlook	31	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog rebuild.
Information	2/6/2018 9:28:44 AM	Outlook	31	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog rebuild.
Information	2/6/2018 9:28:42 AM	Outlook	31	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog rebuild.
Information	2/6/2018 9:28:42 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 593

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 499

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 515

Information	2/6/2018 9:28:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/6/2018 9:28:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	2/6/2018 9:27:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 9:27:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26427)(?)])(1 )(2 )]

"
Information	2/6/2018 9:27:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26427)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 9:27:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8794.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/6/2018 9:27:24 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 9:27:24 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 9:27:23 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 9:27:22 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/6/2018 9:27:14 AM	ESENT	302	Logging/Recovery	Windows (7048) Windows: The database engine has successfully completed recovery steps.
Information	2/6/2018 9:27:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/6/2018 9:27:05 AM	ESENT	301	Logging/Recovery	Windows (7048) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/6/2018 9:27:05 AM	ESENT	300	Logging/Recovery	Windows (7048) Windows: The database engine is initiating recovery steps.
Information	2/6/2018 9:27:05 AM	ESENT	102	General	Windows (7048) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/6/2018 9:26:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/6/2018 9:26:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 9:26:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 9:26:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/6/2018 9:26:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26427)(?)])(1 )(2 )]

"
Information	2/6/2018 9:26:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26427)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/6/2018 9:26:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/6/2018 9:26:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/6/2018 9:26:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/6/2018 9:26:55 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	2/6/2018 9:26:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/6/2018 9:26:44 AM	Service1	0	None	Service started successfully.
Error	2/6/2018 9:26:37 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/6/2018 9:26:37 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Error	2/6/2018 9:26:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/6/2018 9:26:24 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/6/2018 9:26:08 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/6/2018 9:26:07 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/6/2018 9:26:05 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/6/2018 9:26:02 AM	PostgreSQL	0	None	"2018-02-06 09:26:02 IST LOG:  redirecting log output to logging collector process
2018-02-06 09:26:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/6/2018 9:26:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/6/2018 9:26:02 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/6/2018 9:26:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/6/2018 9:26:02 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/6/2018 9:26:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/6/2018 9:26:02 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/6/2018 9:25:58 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3704 at 2/5/2018 9:31:30 AM (local) 2/5/2018 4:01:30 AM (UTC). This is an informational message only; no user action is required.
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/6/2018 9:25:56 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3528.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/6/2018 9:25:55 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/6/2018 9:25:45 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/6/2018 9:25:43 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/6/2018 9:25:34 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/6/2018 9:25:34 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/6/2018 9:25:34 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Tuesday, January 23, 2018 12:27:31 AM.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=Swedish Government Root Authority v1, O=Swedish Social Insurance Agency, C=SE> Sha1 thumbprint: <11E19BBC747B1AED0DB833C94CAC6C3F85BDEBDB>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <OU=RSA Security 2048 V3, O=RSA Security Inc> Sha1 thumbprint: <25019019CFFBD9991CB76825748D945F30939542>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AffirmTrust Networking, O=AffirmTrust, C=US> Sha1 thumbprint: <293621028B20ED02F566C532D1D6ED909F45002F>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=WellsSecure Public Root Certification Authority 01 G2, OU=Wells Fargo Bank NA, O=Wells Fargo WellsSecure, C=US> Sha1 thumbprint: <B42C86C957FD39200C45BBE376C08CD0F4D586DB>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AffirmTrust Premium ECC, O=AffirmTrust, C=US> Sha1 thumbprint: <B8236B002F1D16865301556C11A437CAEBFFC3BB>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AffirmTrust Premium, O=AffirmTrust, C=US> Sha1 thumbprint: <D8A6332CE0036FB185F6634F7D6A066526322827>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=WellsSecure Public Root Certificate Authority, OU=Wells Fargo Bank NA, O=Wells Fargo WellsSecure, C=US> Sha1 thumbprint: <E7B4F69D61EC9069DB7E90A7401A3CF47D4FE8EE>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=AffirmTrust Commercial, O=AffirmTrust, C=US> Sha1 thumbprint: <F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7>.
Information	2/5/2018 11:08:07 AM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=Security Communication EV RootCA1, O=""SECOM Trust Systems CO.,LTD."", C=JP> Sha1 thumbprint: <FEB8C432DCF9769ACEAE3DD8908FFD288665647D>."
Warning	2/5/2018 11:06:58 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	A server error occurred. Check that the server is available.  (HRESULT : 0x80041206) (0x80041206)
"
Warning	2/5/2018 11:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 11:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 11:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 11:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 11:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	2/5/2018 10:52:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2018 10:52:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:12Z. Reason: GVLK.
Information	2/5/2018 10:47:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2018 10:47:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2018 10:47:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2018 10:47:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/5/2018 10:22:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2018 10:22:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:11Z. Reason: GVLK.
Information	2/5/2018 10:17:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2018 10:17:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2018 10:17:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2018 10:17:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/5/2018 10:06:58 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	A server error occurred. Check that the server is available.  (HRESULT : 0x80041206) (0x80041206)
"
Warning	2/5/2018 10:04:56 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	A server error occurred. Check that the server is available.  (HRESULT : 0x80041206) (0x80041206)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <csc://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-18}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-1001}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <iehistory://{S-1-5-21-2236964256-1531681485-2456540299-500}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:09 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	No protocol handler is available. Install a protocol handler that can process this URL type.  (HRESULT : 0x80040d37) (0x80040d37)
"
Warning	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	No protocol handler is available. Install a protocol handler that can process this URL type.  (HRESULT : 0x80040d37) (0x80040d37)
"
Warning	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Warning	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	3023	Gatherer	"The update cannot be started because all of the content sources were excluded by site path rules, or removed from the index configuration.

Context: Windows Application, SystemIndex Catalog

Details:
	(HRESULT : 0x1) (0x00000001)
"
Warning	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX14://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	The specified address was excluded from the index. The site path rules may have to be modified to include this address.  (HRESULT : 0x80040d07) (0x80040d07)
"
Information	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	1005	Search service	The Windows Search Service has successfully created the new search index. 

Error	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	1019	Gatherer	"Windows Search Service failed to process the list of included and excluded locations with the error <30, 0x80040d07, ""ONEINDEX14://{S-1-5-21-3672398596-3227583511-885490141-1389459}/"">. 
"
Warning	2/5/2018 10:00:07 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context: Windows Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	2/5/2018 10:00:05 AM	ESENT	102	General	Windows (8456) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/5/2018 10:00:01 AM	Microsoft-Windows-Search	1004	Search service	The Windows Search service is creating the new search index {Reason: Index Corruption}. 

Error	2/5/2018 10:00:01 AM	Outlook	35	None	Failed to determine if the store is in the crawl scope (error=0x80070015).
Error	2/5/2018 10:00:01 AM	Outlook	34	None	Failed to get the Crawl Scope Manager with error=0x80070015.
Information	2/5/2018 10:00:01 AM	Microsoft-Windows-Search	1010	Search service	The Windows Search Service has successfully removed the old search index. 

Warning	2/5/2018 10:00:01 AM	Microsoft-Windows-Search	1008	Search service	The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}. 

Information	2/5/2018 9:52:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2018 9:52:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:10Z. Reason: GVLK.
Information	2/5/2018 9:48:03 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	2/5/2018 9:48:03 AM	ESENT	103	General	Windows (6792) Windows: The database engine stopped the instance (0).
Error	2/5/2018 9:48:02 AM	Microsoft-Windows-Search	7042	Search service	"The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

Details:
	The content index catalog is corrupt.   0xc0041801 (0xc0041801)
"
Error	2/5/2018 9:48:02 AM	Microsoft-Windows-Search	7040	Search service	"The search service has detected corrupted data files in the index {id=2350}. The service will attempt to automatically correct this problem by rebuilding the index.

Details:
	The content index catalog is corrupt.   0xc0041801 (0xc0041801)
"
Information	2/5/2018 9:47:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2018 9:47:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2018 9:47:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2018 9:47:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/5/2018 9:45:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/5/2018 9:40:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/5/2018 9:40:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:59Z. Reason: GVLK.
Information	2/5/2018 9:39:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/5/2018 9:34:13 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/5/2018 9:34:04 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8794.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	2/5/2018 9:34:00 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {499A5AFF-3953-4F52-ACF2-CA918F9C823B}
Error	2/5/2018 9:34:00 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {499A5AFF-3953-4F52-ACF2-CA918F9C823B}
Error	2/5/2018 9:33:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/5/2018 9:33:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/5/2018 9:33:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27861)(?)])(1 )(2 )]

"
Information	2/5/2018 9:33:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27861)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2018 9:33:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/5/2018 9:33:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2018 9:33:28 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/5/2018 9:33:27 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/5/2018 9:33:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/5/2018 9:33:18 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/5/2018 9:33:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/5/2018 9:33:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/5/2018 9:33:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/5/2018 9:32:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/5/2018 9:32:42 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	2/5/2018 9:32:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/5/2018 9:32:14 AM	ESENT	302	Logging/Recovery	Windows (6792) Windows: The database engine has successfully completed recovery steps.
Information	2/5/2018 9:32:13 AM	ESENT	301	Logging/Recovery	Windows (6792) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/5/2018 9:32:12 AM	ESENT	301	Logging/Recovery	Windows (6792) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS06E38.log.
Information	2/5/2018 9:32:11 AM	ESENT	301	Logging/Recovery	Windows (6792) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS06E37.log.
Information	2/5/2018 9:32:11 AM	ESENT	300	Logging/Recovery	Windows (6792) Windows: The database engine is initiating recovery steps.
Information	2/5/2018 9:32:11 AM	ESENT	102	General	Windows (6792) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/5/2018 9:32:10 AM	Service1	0	None	Service started successfully.
Error	2/5/2018 9:32:01 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/5/2018 9:32:01 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/5/2018 9:31:50 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/5/2018 9:31:49 AM	PostgreSQL	0	None	"2018-02-05 09:31:49 IST LOG:  redirecting log output to logging collector process
2018-02-05 09:31:49 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/5/2018 9:31:48 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/5/2018 9:31:46 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/5/2018 9:31:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/5/2018 9:31:45 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/5/2018 9:31:45 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/5/2018 9:31:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/5/2018 9:31:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/5/2018 9:31:43 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/5/2018 9:31:35 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:35 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/5/2018 9:31:35 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/5/2018 9:31:35 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/5/2018 9:31:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/5/2018 9:31:34 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/5/2018 9:31:33 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/5/2018 9:31:30 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3452 at 2/4/2018 10:54:22 PM (local) 2/4/2018 5:24:22 PM (UTC). This is an informational message only; no user action is required.
Information	2/5/2018 9:31:28 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/5/2018 9:31:27 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/5/2018 9:31:27 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/5/2018 9:31:27 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/5/2018 9:31:27 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3704.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/5/2018 9:31:26 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/5/2018 9:31:00 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/5/2018 9:30:55 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/5/2018 9:30:44 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/5/2018 9:30:44 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/5/2018 9:30:44 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/4/2018 10:54:44 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	2/4/2018 10:54:23 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/4/2018 10:54:22 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/4/2018 10:54:09 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 13 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2012 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/4/2018 10:54:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/4/2018 10:54:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/4/2018 10:54:08 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	2/4/2018 10:53:57 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	2/4/2018 10:53:54 PM	RasClient	20226	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	2/4/2018 10:53:48 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	2/4/2018 10:52:14 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: AcroRd32.exe.
Information	2/4/2018 10:38:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 10:33:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2018 10:33:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28521)(?)])(1 )(2 )]

"
Information	2/4/2018 10:33:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28521)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 10:32:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2018 10:32:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28522)(?)])(1 )(2 )]

"
Information	2/4/2018 10:32:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28522)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 10:32:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/4/2018 10:32:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 10:32:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 9:55:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:25:53.600225500Z.
Information	2/4/2018 9:55:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {93CC1063-02A1-4F25-A13A-C351A10D84DD}. Client Process Id: 6440.
Information	2/4/2018 9:55:56 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Services Hub. Product Version: 1.0.23107.00. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:55:56 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Services Hub -- Removal completed successfully.
Information	2/4/2018 9:55:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:25:53.600225500Z.
Information	2/4/2018 9:55:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:25:13.145180400Z.
Information	2/4/2018 9:55:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {93CC1063-02A1-4F25-A13A-C351A10D84DD}. Client Process Id: 6440.
Information	2/4/2018 9:55:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D1437F51-786A-4F57-A99C-F8E94FBA1BD8}. Client Process Id: 6440.
Information	2/4/2018 9:55:53 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Build Tools 14.0 (x86). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:55:53 PM	MsiInstaller	11724	None	Product: Microsoft Build Tools 14.0 (x86) -- Removal completed successfully.
Information	2/4/2018 9:55:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:25:13.145180400Z.
Information	2/4/2018 9:55:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:24:32.066072900Z.
Information	2/4/2018 9:55:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D1437F51-786A-4F57-A99C-F8E94FBA1BD8}. Client Process Id: 6440.
Information	2/4/2018 9:55:13 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {8C918E5B-E238-401F-9F6E-4FB84B024CA2}. Client Process Id: 6440.
Information	2/4/2018 9:55:13 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Build Tools 14.0 (amd64). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:55:13 PM	MsiInstaller	11724	None	Product: Microsoft Build Tools 14.0 (amd64) -- Removal completed successfully.
Information	2/4/2018 9:54:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:24:32.066072900Z.
Information	2/4/2018 9:54:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:22:36.491516600Z.
Information	2/4/2018 9:54:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {8C918E5B-E238-401F-9F6E-4FB84B024CA2}. Client Process Id: 6440.
Information	2/4/2018 9:54:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A7E88B38-6886-4474-9D85-A8ABE5FCD80E}. Client Process Id: 6440.
Information	2/4/2018 9:54:31 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Build Tools Language Resources 14.0 (x86). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:54:31 PM	MsiInstaller	11724	None	Product: Microsoft Build Tools Language Resources 14.0 (x86) -- Removal completed successfully.
Information	2/4/2018 9:52:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:22:36.491516600Z.
Information	2/4/2018 9:52:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:50.888956800Z.
Information	2/4/2018 9:52:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A7E88B38-6886-4474-9D85-A8ABE5FCD80E}. Client Process Id: 6440.
Information	2/4/2018 9:52:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4B7958F6-4943-4903-B379-9180DC8C2105}. Client Process Id: 6440.
Information	2/4/2018 9:52:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Build Tools Language Resources 14.0 (amd64). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:52:36 PM	MsiInstaller	11724	None	Product: Microsoft Build Tools Language Resources 14.0 (amd64) -- Removal completed successfully.
Information	2/4/2018 9:51:50 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:50.888956800Z.
Information	2/4/2018 9:51:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:45.427410700Z.
Information	2/4/2018 9:51:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4B7958F6-4943-4903-B379-9180DC8C2105}. Client Process Id: 6440.
Information	2/4/2018 9:51:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DF32E41C-24AD-4A87-B43A-B38553B1806E}. Client Process Id: 6440.
Information	2/4/2018 9:51:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual Studio 2015 Prerequisites. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:50 PM	MsiInstaller	11724	None	Product: Visual Studio 2015 Prerequisites -- Removal completed successfully.
Information	2/4/2018 9:51:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:45.427410700Z.
Information	2/4/2018 9:51:44 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:41.258993900Z.
Information	2/4/2018 9:51:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DF32E41C-24AD-4A87-B43A-B38553B1806E}. Client Process Id: 6440.
Information	2/4/2018 9:51:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {83B181F2-20B8-4F00-8E71-C66E951A8D4F}. Client Process Id: 6440.
Information	2/4/2018 9:51:44 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual Studio 2015 Prerequisites - ENU Language Pack. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:44 PM	MsiInstaller	11724	None	Product: Visual Studio 2015 Prerequisites - ENU Language Pack -- Removal completed successfully.
Information	2/4/2018 9:51:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:41.258993900Z.
Information	2/4/2018 9:51:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:37.582626300Z.
Information	2/4/2018 9:51:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {83B181F2-20B8-4F00-8E71-C66E951A8D4F}. Client Process Id: 6440.
Information	2/4/2018 9:51:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {732C5708-B3D0-3A93-B4F2-6BA5FCFC5BA1}. Client Process Id: 6440.
Information	2/4/2018 9:51:41 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Team Foundation Server 2015 Office Integration (x64). Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:41 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Team Foundation Server 2015 Office Integration (x64) -- Removal completed successfully.
Information	2/4/2018 9:51:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:37.582626300Z.
Information	2/4/2018 9:51:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:34.244292500Z.
Information	2/4/2018 9:51:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {732C5708-B3D0-3A93-B4F2-6BA5FCFC5BA1}. Client Process Id: 6440.
Information	2/4/2018 9:51:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5B7D3F8B-BDA8-382D-9581-18AA7F1E1358}. Client Process Id: 6440.
Information	2/4/2018 9:51:37 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Team Foundation Server 2015 Office Integration Language Pack (x64) - ENU. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:37 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Team Foundation Server 2015 Office Integration Language Pack (x64) - ENU -- Removal completed successfully.
Information	2/4/2018 9:51:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:34.244292500Z.
Information	2/4/2018 9:51:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:30.115879700Z.
Information	2/4/2018 9:51:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5B7D3F8B-BDA8-382D-9581-18AA7F1E1358}. Client Process Id: 6440.
Information	2/4/2018 9:51:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DE38EBD8-25AC-3026-BE14-6F829F7050A6}. Client Process Id: 6440.
Information	2/4/2018 9:51:34 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Team Foundation Server 2015 Storyboarding (x64). Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:34 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Team Foundation Server 2015 Storyboarding (x64) -- Removal completed successfully.
Information	2/4/2018 9:51:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:30.115879700Z.
Information	2/4/2018 9:51:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:25.167384900Z.
Information	2/4/2018 9:51:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DE38EBD8-25AC-3026-BE14-6F829F7050A6}. Client Process Id: 6440.
Information	2/4/2018 9:51:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {70FF76E1-4F3F-3475-A501-4F1E87D5A938}. Client Process Id: 6440.
Information	2/4/2018 9:51:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Team Foundation Server 2015 Storyboarding Language Pack (x64) - ENU. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:29 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Team Foundation Server 2015 Storyboarding Language Pack (x64) - ENU -- Removal completed successfully.
Information	2/4/2018 9:51:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:25.167384900Z.
Information	2/4/2018 9:51:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:17.068575100Z.
Information	2/4/2018 9:51:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {70FF76E1-4F3F-3475-A501-4F1E87D5A938}. Client Process Id: 6440.
Information	2/4/2018 9:51:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}. Client Process Id: 6440.
Information	2/4/2018 9:51:24 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.6 Targeting Pack. Product Version: 4.6.00081. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:24 PM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.6 Targeting Pack -- Removal completed successfully.
Information	2/4/2018 9:51:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:17.068575100Z.
Information	2/4/2018 9:51:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:21:13.028171100Z.
Information	2/4/2018 9:51:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}. Client Process Id: 6440.
Information	2/4/2018 9:51:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3D3CEBE6-40EA-4C48-97FD-73828281AB4A}. Client Process Id: 6440.
Information	2/4/2018 9:51:17 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.6 Targeting Pack (ENU). Product Version: 4.6.00081. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:17 PM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.6 Targeting Pack (ENU) -- Removal completed successfully.
Information	2/4/2018 9:51:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:21:13.028171100Z.
Information	2/4/2018 9:51:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:19:35.572426500Z.
Information	2/4/2018 9:51:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3D3CEBE6-40EA-4C48-97FD-73828281AB4A}. Client Process Id: 6440.
Information	2/4/2018 9:51:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {030A6785-C3A9-37DA-8530-444C320629FA}. Client Process Id: 6440.
Information	2/4/2018 9:51:12 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Shell (Minimum). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:51:12 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Shell (Minimum) -- Removal completed successfully.
Information	2/4/2018 9:49:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:19:35.572426500Z.
Information	2/4/2018 9:49:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:19:03.920261600Z.
Information	2/4/2018 9:49:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {030A6785-C3A9-37DA-8530-444C320629FA}. Client Process Id: 6440.
Information	2/4/2018 9:49:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4443D3F4-A231-35CC-8471-CB60F8A3FE3B}. Client Process Id: 6440.
Information	2/4/2018 9:49:34 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:49:34 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies -- Removal completed successfully.
Information	2/4/2018 9:49:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:19:03.920261600Z.
Information	2/4/2018 9:49:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:18:52.517121400Z.
Information	2/4/2018 9:49:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4443D3F4-A231-35CC-8471-CB60F8A3FE3B}. Client Process Id: 6440.
Information	2/4/2018 9:49:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {FC1F3422-0C94-3178-AD95-3EA889DF55AF}. Client Process Id: 6440.
Information	2/4/2018 9:49:01 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Devenv. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:49:01 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Devenv -- Removal completed successfully.
Information	2/4/2018 9:48:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:18:52.517121400Z.
Information	2/4/2018 9:48:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:18:31.408010700Z.
Information	2/4/2018 9:48:51 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {FC1F3422-0C94-3178-AD95-3EA889DF55AF}. Client Process Id: 6440.
Information	2/4/2018 9:48:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {7FF53256-7BAF-3EFA-91B4-DB65F37EB5E9}. Client Process Id: 6440.
Information	2/4/2018 9:48:51 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Shell (Minimum) Resources. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:48:51 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Shell (Minimum) Resources -- Removal completed successfully.
Information	2/4/2018 9:48:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:18:31.408010700Z.
Information	2/4/2018 9:48:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:18:19.504820500Z.
Information	2/4/2018 9:48:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {7FF53256-7BAF-3EFA-91B4-DB65F37EB5E9}. Client Process Id: 6440.
Information	2/4/2018 9:48:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {173D2989-6B09-3A90-8819-A53E43F99818}. Client Process Id: 6440.
Information	2/4/2018 9:48:31 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Devenv Resources. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:48:31 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Devenv Resources -- Removal completed successfully.
Information	2/4/2018 9:48:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:18:19.504820500Z.
Information	2/4/2018 9:48:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:18:07.314601600Z.
Information	2/4/2018 9:48:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {173D2989-6B09-3A90-8819-A53E43F99818}. Client Process Id: 6440.
Information	2/4/2018 9:48:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {599702AA-91EB-38C1-B994-CDE35C57E007}. Client Process Id: 6440.
Information	2/4/2018 9:48:19 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 VsGraphics Helper Dependencies. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:48:19 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 VsGraphics Helper Dependencies -- Removal completed successfully.
Information	2/4/2018 9:48:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:18:07.314601600Z.
Information	2/4/2018 9:48:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:11:08.004674800Z.
Information	2/4/2018 9:48:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {599702AA-91EB-38C1-B994-CDE35C57E007}. Client Process Id: 6440.
Information	2/4/2018 9:48:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DE064F60-6522-3310-9665-B5E3E78B3638}. Client Process Id: 6440.
Information	2/4/2018 9:48:05 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Community 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:48:05 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Community 2015 -- Removal completed successfully.
Warning	2/4/2018 9:43:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/4/2018 9:42:12 PM	HlpCtntMgr	1003	(1)	Help Content Manager exited with error: NoBooksToUninstall
Information	2/4/2018 9:41:56 PM	HlpCtntMgr	1010	(1)	Content will be uninstalled with the following arguments: /silent /operation uninstall /catalogname VisualStudio14 /locale en-us /locationPath C:\ProgramData\Microsoft\HelpLibrary2\Catalogs\VisualStudio14\
Information	2/4/2018 9:41:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:11:08.004674800Z.
Information	2/4/2018 9:41:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:08:46.061481900Z.
Information	2/4/2018 9:41:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DE064F60-6522-3310-9665-B5E3E78B3638}. Client Process Id: 6440.
Information	2/4/2018 9:41:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5C4DD346-D2B9-3B7B-9320-A90049D5E48B}. Client Process Id: 6440.
Information	2/4/2018 9:41:01 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Community 2015 - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:41:01 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Community 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:38:46 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:08:46.061481900Z.
Information	2/4/2018 9:38:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:08:34.311307000Z.
Information	2/4/2018 9:38:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5C4DD346-D2B9-3B7B-9320-A90049D5E48B}. Client Process Id: 6440.
Information	2/4/2018 9:38:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {67A74EC1-A89D-3553-B38D-D17D4991CD2F}. Client Process Id: 6440.
Information	2/4/2018 9:38:42 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 SDK - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:38:42 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 SDK - ENU -- Removal completed successfully.
Information	2/4/2018 9:38:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:08:34.311307000Z.
Information	2/4/2018 9:38:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:07:43.303206700Z.
Information	2/4/2018 9:38:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {67A74EC1-A89D-3553-B38D-D17D4991CD2F}. Client Process Id: 6440.
Information	2/4/2018 9:38:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {12B68AD4-A9C9-3330-BFAE-BFCCDDB96660}. Client Process Id: 6440.
Information	2/4/2018 9:38:33 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Professional 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:38:33 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Professional 2015 -- Removal completed successfully.
Information	2/4/2018 9:37:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:07:43.303206700Z.
Information	2/4/2018 9:37:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:07:33.851261600Z.
Information	2/4/2018 9:37:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {12B68AD4-A9C9-3330-BFAE-BFCCDDB96660}. Client Process Id: 6440.
Information	2/4/2018 9:37:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4983E758-4064-3D74-BB77-75C3F86C34B3}. Client Process Id: 6440.
Information	2/4/2018 9:37:42 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Professional 2015 - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:37:42 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Professional 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:37:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:07:33.851261600Z.
Information	2/4/2018 9:37:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:05:13.953273200Z.
Information	2/4/2018 9:37:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4983E758-4064-3D74-BB77-75C3F86C34B3}. Client Process Id: 6440.
Information	2/4/2018 9:37:32 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {66D86CBC-EFCD-3502-A249-F91F775427F8}. Client Process Id: 6440.
Information	2/4/2018 9:37:32 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Premium 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:37:32 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Premium 2015 -- Removal completed successfully.
Information	2/4/2018 9:35:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:05:13.953273200Z.
Information	2/4/2018 9:35:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:04:51.477025800Z.
Information	2/4/2018 9:35:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {66D86CBC-EFCD-3502-A249-F91F775427F8}. Client Process Id: 6440.
Information	2/4/2018 9:35:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D91B7764-7CE2-3557-B977-E5B8E035C201}. Client Process Id: 6440.
Information	2/4/2018 9:35:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Premium 2015 - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:35:11 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Premium 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:34:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:04:51.477025800Z.
Information	2/4/2018 9:34:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:03:39.810859900Z.
Information	2/4/2018 9:34:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D91B7764-7CE2-3557-B977-E5B8E035C201}. Client Process Id: 6440.
Information	2/4/2018 9:34:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {14D1CABE-2B5A-3AED-B3A7-42315D062965}. Client Process Id: 6440.
Information	2/4/2018 9:34:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Enterprise 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:34:50 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Enterprise 2015 -- Removal completed successfully.
Information	2/4/2018 9:33:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:03:39.810859900Z.
Information	2/4/2018 9:33:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:03:25.986477600Z.
Information	2/4/2018 9:33:39 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {14D1CABE-2B5A-3AED-B3A7-42315D062965}. Client Process Id: 6440.
Information	2/4/2018 9:33:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BA2C0FAC-AF64-3E17-B21E-3C746F77CE07}. Client Process Id: 6440.
Information	2/4/2018 9:33:39 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Enterprise 2015 - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:33:39 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Enterprise 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:33:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:03:25.986477600Z.
Information	2/4/2018 9:33:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:02:51.146994000Z.
Information	2/4/2018 9:33:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BA2C0FAC-AF64-3E17-B21E-3C746F77CE07}. Client Process Id: 6440.
Information	2/4/2018 9:33:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}. Client Process Id: 6440.
Information	2/4/2018 9:33:23 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4 Multi-Targeting Pack. Product Version: 4.0.30319. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:33:23 PM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4 Multi-Targeting Pack -- Removal completed successfully.
Information	2/4/2018 9:32:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:02:51.146994000Z.
Information	2/4/2018 9:32:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:02:38.760755500Z.
Information	2/4/2018 9:32:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}. Client Process Id: 6440.
Information	2/4/2018 9:32:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E5628C7D-AF4C-36EE-8EA3-CCA584355DC8}. Client Process Id: 6440.
Information	2/4/2018 9:32:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ Compiler/Tools X86 Base Package. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:32:50 PM	MsiInstaller	11724	None	Product: Visual C++ Compiler/Tools X86 Base Package -- Removal completed successfully.
Information	2/4/2018 9:32:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:02:38.760755500Z.
Information	2/4/2018 9:32:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:02:28.147694300Z.
Information	2/4/2018 9:32:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E5628C7D-AF4C-36EE-8EA3-CCA584355DC8}. Client Process Id: 6440.
Information	2/4/2018 9:32:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {80025584-1880-35C4-AF00-D315726DD3B0}. Client Process Id: 6440.
Information	2/4/2018 9:32:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ Compiler/Tools X86 Base Package. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:32:38 PM	MsiInstaller	11724	None	Product: Visual C++ Compiler/Tools X86 Base Package -- Removal completed successfully.
Information	2/4/2018 9:32:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:02:28.147694300Z.
Information	2/4/2018 9:32:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:02:06.963576100Z.
Information	2/4/2018 9:32:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {80025584-1880-35C4-AF00-D315726DD3B0}. Client Process Id: 6440.
Information	2/4/2018 9:32:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {24D8C6FB-19E6-3E96-A94F-D4FCE4CBC6D0}. Client Process Id: 6440.
Information	2/4/2018 9:32:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ Library PGO X86 Package. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:32:27 PM	MsiInstaller	11724	None	Product: Visual C++ Library PGO X86 Package -- Removal completed successfully.
Information	2/4/2018 9:32:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:02:06.963576100Z.
Information	2/4/2018 9:32:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:01:58.757755600Z.
Information	2/4/2018 9:32:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {24D8C6FB-19E6-3E96-A94F-D4FCE4CBC6D0}. Client Process Id: 6440.
Information	2/4/2018 9:32:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {1A6302B8-FD7B-32F9-ACC1-7C0B776D21A2}. Client Process Id: 6440.
Information	2/4/2018 9:32:05 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Common Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:32:05 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Common Package -- Removal completed successfully.
Information	2/4/2018 9:31:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:01:58.757755600Z.
Information	2/4/2018 9:31:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:00:49.163796900Z.
Information	2/4/2018 9:31:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {1A6302B8-FD7B-32F9-ACC1-7C0B776D21A2}. Client Process Id: 6440.
Information	2/4/2018 9:31:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B4455386-EEC8-3ADB-B63B-F10F108D04A9}. Client Process Id: 6440.
Information	2/4/2018 9:31:57 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Base Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:31:57 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Base Package -- Removal completed successfully.
Information	2/4/2018 9:30:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:00:49.163796900Z.
Information	2/4/2018 9:30:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:00:33.179198600Z.
Information	2/4/2018 9:30:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B4455386-EEC8-3ADB-B63B-F10F108D04A9}. Client Process Id: 6440.
Information	2/4/2018 9:30:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {2079BC7F-41D0-3CE8-BB24-D1DC292DE4C8}. Client Process Id: 6440.
Information	2/4/2018 9:30:48 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Debugger Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:30:48 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Debugger Package -- Removal completed successfully.
Information	2/4/2018 9:30:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:00:33.179198600Z.
Information	2/4/2018 9:30:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:00:16.324513300Z.
Information	2/4/2018 9:30:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {2079BC7F-41D0-3CE8-BB24-D1DC292DE4C8}. Client Process Id: 6440.
Information	2/4/2018 9:30:32 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {55168F96-0BEA-3A05-95C7-D31D211D707E}. Client Process Id: 6440.
Information	2/4/2018 9:30:32 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE x64 Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:30:32 PM	MsiInstaller	11724	None	Product: Visual C++ IDE x64 Package -- Removal completed successfully.
Information	2/4/2018 9:30:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:00:16.324513300Z.
Information	2/4/2018 9:30:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T16:00:01.482029200Z.
Information	2/4/2018 9:30:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {55168F96-0BEA-3A05-95C7-D31D211D707E}. Client Process Id: 6440.
Information	2/4/2018 9:30:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {8A56053B-10D9-333C-802F-FD804C4D6D35}. Client Process Id: 6440.
Information	2/4/2018 9:30:16 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ MSBuild ARM Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:30:16 PM	MsiInstaller	11724	None	Product: Visual C++ MSBuild ARM Package -- Removal completed successfully.
Information	2/4/2018 9:30:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T16:00:01.482029200Z.
Information	2/4/2018 9:29:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:59:39.561837400Z.
Information	2/4/2018 9:30:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {8A56053B-10D9-333C-802F-FD804C4D6D35}. Client Process Id: 6440.
Information	2/4/2018 9:29:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {384BAE4F-6233-3E67-99A3-87268642493D}. Client Process Id: 6440.
Information	2/4/2018 9:29:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ MSBuild Base Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:29:59 PM	MsiInstaller	11724	None	Product: Visual C++ MSBuild Base Package -- Removal completed successfully.
Information	2/4/2018 9:29:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:59:39.561837400Z.
Information	2/4/2018 9:29:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:59:29.335814900Z.
Information	2/4/2018 9:29:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {384BAE4F-6233-3E67-99A3-87268642493D}. Client Process Id: 6440.
Information	2/4/2018 9:29:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {62A6BB84-126D-3132-A4F2-B250BFB9AB3F}. Client Process Id: 6440.
Information	2/4/2018 9:29:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ MSBuild X64 Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:29:38 PM	MsiInstaller	11724	None	Product: Visual C++ MSBuild X64 Package -- Removal completed successfully.
Information	2/4/2018 9:29:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:59:29.335814900Z.
Information	2/4/2018 9:29:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:59:16.806562100Z.
Information	2/4/2018 9:29:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {62A6BB84-126D-3132-A4F2-B250BFB9AB3F}. Client Process Id: 6440.
Information	2/4/2018 9:29:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5F867E41-0322-3590-B09E-B2D318CEBBF1}. Client Process Id: 6440.
Information	2/4/2018 9:29:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ MSBuild X86 Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:29:28 PM	MsiInstaller	11724	None	Product: Visual C++ MSBuild X86 Package -- Removal completed successfully.
Information	2/4/2018 9:29:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:59:16.806562100Z.
Information	2/4/2018 9:29:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:59:03.639245500Z.
Information	2/4/2018 9:29:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5F867E41-0322-3590-B09E-B2D318CEBBF1}. Client Process Id: 6440.
Information	2/4/2018 9:29:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3C0FA0FD-3422-3D08-B1F9-BF34BE7DE12B}. Client Process Id: 6440.
Information	2/4/2018 9:29:16 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Base Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:29:16 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Base Package -- Removal completed successfully.
Information	2/4/2018 9:29:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:59:03.639245500Z.
Information	2/4/2018 9:29:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:52.125094200Z.
Information	2/4/2018 9:29:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3C0FA0FD-3422-3D08-B1F9-BF34BE7DE12B}. Client Process Id: 6440.
Information	2/4/2018 9:29:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {743FC372-B1A2-3A5A-BF20-E2AF24435685}. Client Process Id: 6440.
Information	2/4/2018 9:29:02 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Professional Core Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:29:02 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Professional Core Package -- Removal completed successfully.
Information	2/4/2018 9:28:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:52.125094200Z.
Information	2/4/2018 9:28:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:43.336215400Z.
Information	2/4/2018 9:28:51 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {743FC372-B1A2-3A5A-BF20-E2AF24435685}. Client Process Id: 6440.
Information	2/4/2018 9:28:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9E40E17C-E055-3955-8D8D-DD15A9CAA250}. Client Process Id: 6440.
Information	2/4/2018 9:28:51 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ Compiler/Tools X86 Base Resource Package. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:51 PM	MsiInstaller	11724	None	Product: Visual C++ Compiler/Tools X86 Base Resource Package -- Removal completed successfully.
Information	2/4/2018 9:28:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:43.336215400Z.
Information	2/4/2018 9:28:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:33.961278000Z.
Information	2/4/2018 9:28:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9E40E17C-E055-3955-8D8D-DD15A9CAA250}. Client Process Id: 6440.
Information	2/4/2018 9:28:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4FB6F27D-8B6C-3433-B447-25FCA242985F}. Client Process Id: 6440.
Information	2/4/2018 9:28:42 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ Compiler/Tools X86 Base Resource Package. Product Version: 14.0.23026. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:42 PM	MsiInstaller	11724	None	Product: Visual C++ Compiler/Tools X86 Base Resource Package -- Removal completed successfully.
Information	2/4/2018 9:28:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:33.961278000Z.
Information	2/4/2018 9:28:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:24.643346300Z.
Information	2/4/2018 9:28:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4FB6F27D-8B6C-3433-B447-25FCA242985F}. Client Process Id: 6440.
Information	2/4/2018 9:28:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C74AF26E-5E70-30CA-AC13-FA13A8D3BAC9}. Client Process Id: 6440.
Information	2/4/2018 9:28:33 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Common Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:33 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Common Resource Package -- Removal completed successfully.
Information	2/4/2018 9:28:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:24.643346300Z.
Information	2/4/2018 9:28:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:10.240906200Z.
Information	2/4/2018 9:28:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C74AF26E-5E70-30CA-AC13-FA13A8D3BAC9}. Client Process Id: 6440.
Information	2/4/2018 9:28:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D3FE4937-CB7C-3FE3-8521-7643B86E6AAA}. Client Process Id: 6440.
Information	2/4/2018 9:28:24 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Base Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:24 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Base Resource Package -- Removal completed successfully.
Information	2/4/2018 9:28:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:10.240906200Z.
Information	2/4/2018 9:28:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:58:00.536935900Z.
Information	2/4/2018 9:28:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D3FE4937-CB7C-3FE3-8521-7643B86E6AAA}. Client Process Id: 6440.
Information	2/4/2018 9:28:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {37F52A5D-1940-3CEC-AD6A-36C7EA3C3554}. Client Process Id: 6440.
Information	2/4/2018 9:28:09 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Debugger Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:09 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Debugger Resource Package -- Removal completed successfully.
Information	2/4/2018 9:28:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:58:00.536935900Z.
Information	2/4/2018 9:28:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:57:47.102592600Z.
Information	2/4/2018 9:28:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {37F52A5D-1940-3CEC-AD6A-36C7EA3C3554}. Client Process Id: 6440.
Information	2/4/2018 9:28:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5A4D001F-645A-303A-BD3A-39A2EE60F022}. Client Process Id: 6440.
Information	2/4/2018 9:28:00 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ MSBuild Base Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:28:00 PM	MsiInstaller	11724	None	Product: Visual C++ MSBuild Base Resource Package -- Removal completed successfully.
Information	2/4/2018 9:27:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:57:47.102592600Z.
Information	2/4/2018 9:27:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:57:35.488431300Z.
Information	2/4/2018 9:27:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5A4D001F-645A-303A-BD3A-39A2EE60F022}. Client Process Id: 6440.
Information	2/4/2018 9:27:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E6D09370-D4B1-3421-A0F6-45DF6999EBED}. Client Process Id: 6440.
Information	2/4/2018 9:27:46 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Base Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:27:46 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Base Resource Package -- Removal completed successfully.
Information	2/4/2018 9:27:35 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:57:35.488431300Z.
Information	2/4/2018 9:27:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:56:39.703853400Z.
Information	2/4/2018 9:27:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E6D09370-D4B1-3421-A0F6-45DF6999EBED}. Client Process Id: 6440.
Information	2/4/2018 9:27:35 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5C0F50FF-52F8-31E5-842D-7882941FAD39}. Client Process Id: 6440.
Information	2/4/2018 9:27:35 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Visual C++ IDE Core Professional Plus Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:27:35 PM	MsiInstaller	11724	None	Product: Visual C++ IDE Core Professional Plus Resource Package -- Removal completed successfully.
Information	2/4/2018 9:26:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:56:39.703853400Z.
Information	2/4/2018 9:26:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:56:14.676350900Z.
Information	2/4/2018 9:26:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5C0F50FF-52F8-31E5-842D-7882941FAD39}. Client Process Id: 6440.
Information	2/4/2018 9:26:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {12D99739-FFD3-3761-8AA6-F929E0FE407E}. Client Process Id: 6440.
Information	2/4/2018 9:26:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Multi-Device Hybrid Apps using C# - Templates - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:26:38 PM	MsiInstaller	11724	None	Product: Multi-Device Hybrid Apps using C# - Templates - ENU -- Removal completed successfully.
Information	2/4/2018 9:26:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:56:14.676350900Z.
Information	2/4/2018 9:26:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:55:44.166300200Z.
Information	2/4/2018 9:26:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {12D99739-FFD3-3761-8AA6-F929E0FE407E}. Client Process Id: 6440.
Information	2/4/2018 9:26:14 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DEAC33A4-FB05-32C6-8AAD-7FB26A8767E6}. Client Process Id: 6440.
Information	2/4/2018 9:26:14 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Phone SDK 8.0 Assemblies for Visual Studio 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:26:14 PM	MsiInstaller	11724	None	Product: Windows Phone SDK 8.0 Assemblies for Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:25:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:55:44.166300200Z.
Information	2/4/2018 9:25:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:55:12.873171200Z.
Information	2/4/2018 9:25:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DEAC33A4-FB05-32C6-8AAD-7FB26A8767E6}. Client Process Id: 6440.
Information	2/4/2018 9:25:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {1066AB1A-C1E7-384E-9A1F-39D2C25471BD}. Client Process Id: 6440.
Information	2/4/2018 9:25:43 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Designer. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:25:43 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Designer -- Removal completed successfully.
Information	2/4/2018 9:25:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:55:12.873171200Z.
Information	2/4/2018 9:25:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:55:06.403524300Z.
Information	2/4/2018 9:25:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {1066AB1A-C1E7-384E-9A1F-39D2C25471BD}. Client Process Id: 6440.
Information	2/4/2018 9:25:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E2E81BA0-07B8-36E7-B860-822059039AE4}. Client Process Id: 6440.
Information	2/4/2018 9:25:12 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Designer - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:25:12 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Designer - ENU -- Removal completed successfully.
Information	2/4/2018 9:25:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:55:06.403524300Z.
Information	2/4/2018 9:25:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:54:58.929777000Z.
Information	2/4/2018 9:25:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E2E81BA0-07B8-36E7-B860-822059039AE4}. Client Process Id: 6440.
Information	2/4/2018 9:25:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {700FCCBE-AC0B-39BD-91C7-089459AFFCA6}. Client Process Id: 6440.
Information	2/4/2018 9:25:06 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Blend for Visual Studio 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:25:06 PM	MsiInstaller	11724	None	Product: Microsoft Blend for Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:24:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:54:58.929777000Z.
Information	2/4/2018 9:24:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:54:51.033987500Z.
Information	2/4/2018 9:24:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {700FCCBE-AC0B-39BD-91C7-089459AFFCA6}. Client Process Id: 6440.
Information	2/4/2018 9:24:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6C1BF658-4F11-34A1-8941-6A7C7F2B8817}. Client Process Id: 6440.
Information	2/4/2018 9:24:58 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Blend for Visual Studio 2015 - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:24:58 PM	MsiInstaller	11724	None	Product: Microsoft Blend for Visual Studio 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:24:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:54:51.033987500Z.
Information	2/4/2018 9:24:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:54:08.082679900Z.
Information	2/4/2018 9:24:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6C1BF658-4F11-34A1-8941-6A7C7F2B8817}. Client Process Id: 6440.
Information	2/4/2018 9:24:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {37E53780-3944-4A6A-842F-727128E8616E}. Client Process Id: 6440.
Information	2/4/2018 9:24:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Blend for Visual Studio SDK for .NET 4.5. Product Version: 3.0.40218.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:24:50 PM	MsiInstaller	11724	None	Product: Blend for Visual Studio SDK for .NET 4.5 -- Removal completed successfully.
Information	2/4/2018 9:24:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:54:08.082679900Z.
Information	2/4/2018 9:23:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {37E53780-3944-4A6A-842F-727128E8616E}. Client Process Id: 6440.
Information	2/4/2018 9:23:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {246124C5-600E-44F2-8E09-940E27DB1D01}. Client Process Id: 6440.
Information	2/4/2018 9:23:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:52:14.322679900Z.
Information	2/4/2018 9:23:56 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft VisualStudio JavaScript Project System. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:23:56 PM	MsiInstaller	11724	None	Product: Microsoft VisualStudio JavaScript Project System -- Removal completed successfully.
Information	2/4/2018 9:22:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:52:14.322679900Z.
Information	2/4/2018 9:22:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:51:16.034679900Z.
Information	2/4/2018 9:22:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {246124C5-600E-44F2-8E09-940E27DB1D01}. Client Process Id: 6440.
Information	2/4/2018 9:22:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {98495159-3149-4678-A995-DFF1A02F7DCB}. Client Process Id: 6440.
Information	2/4/2018 9:22:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft VisualStudio JavaScript Language Service. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:22:11 PM	MsiInstaller	11724	None	Product: Microsoft VisualStudio JavaScript Language Service -- Removal completed successfully.
Information	2/4/2018 9:21:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:51:16.034679900Z.
Information	2/4/2018 9:21:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:50:40.227679900Z.
Information	2/4/2018 9:21:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {98495159-3149-4678-A995-DFF1A02F7DCB}. Client Process Id: 6440.
Information	2/4/2018 9:21:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9B3A1C97-A361-463E-8817-444F9F88CDFE}. Client Process Id: 6440.
Information	2/4/2018 9:21:12 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Expression Blend SDK for .NET 4. Product Version: 2.0.20525.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:21:12 PM	MsiInstaller	11724	None	Product: Microsoft Expression Blend SDK for .NET 4 -- Removal completed successfully.
Information	2/4/2018 9:20:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:50:40.227679900Z.
Information	2/4/2018 9:20:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:50:28.224679900Z.
Information	2/4/2018 9:20:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9B3A1C97-A361-463E-8817-444F9F88CDFE}. Client Process Id: 6440.
Information	2/4/2018 9:20:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3BDC2F21-C038-48E2-AFFC-EFE7A49BE75B}. Client Process Id: 6440.
Information	2/4/2018 9:20:40 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Performance Debugger Web Views. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:20:40 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Performance Debugger Web Views -- Removal completed successfully.
Information	2/4/2018 9:20:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:50:28.224679900Z.
Information	2/4/2018 9:20:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:50:15.248679900Z.
Information	2/4/2018 9:20:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3BDC2F21-C038-48E2-AFFC-EFE7A49BE75B}. Client Process Id: 6440.
Information	2/4/2018 9:20:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {FCC6E820-B5DB-454E-96E3-B6182DDEEC8D}. Client Process Id: 6440.
Information	2/4/2018 9:20:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Performance Collection Tools. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:20:28 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Performance Collection Tools -- Removal completed successfully.
Information	2/4/2018 9:20:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:50:15.248679900Z.
Information	2/4/2018 9:20:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:50:07.145679900Z.
Information	2/4/2018 9:20:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {FCC6E820-B5DB-454E-96E3-B6182DDEEC8D}. Client Process Id: 6440.
Information	2/4/2018 9:20:14 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3AE40040-2F48-4617-9228-49E999738BDB}. Client Process Id: 6440.
Information	2/4/2018 9:20:14 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Performance Collection Tools - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:20:14 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Performance Collection Tools - ENU -- Removal completed successfully.
Information	2/4/2018 9:20:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:50:07.145679900Z.
Information	2/4/2018 9:20:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:41:37.305679900Z.
Information	2/4/2018 9:20:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3AE40040-2F48-4617-9228-49E999738BDB}. Client Process Id: 6440.
Information	2/4/2018 9:20:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {1A8A9739-BAD7-491F-B5B9-A79A2B965422}. Client Process Id: 6440.
Information	2/4/2018 9:20:06 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Entity Framework 6.1.3 Tools  for Visual Studio 2015. Product Version: 14.0.40302.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:20:06 PM	MsiInstaller	11724	None	Product: Entity Framework 6.1.3 Tools  for Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:11:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:41:37.305679900Z.
Information	2/4/2018 9:11:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:41:28.298679900Z.
Information	2/4/2018 9:11:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {1A8A9739-BAD7-491F-B5B9-A79A2B965422}. Client Process Id: 6440.
Information	2/4/2018 9:11:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}. Client Process Id: 6440.
Information	2/4/2018 9:11:37 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: WCF Data Services 5.6.4 Runtime. Product Version: 5.6.62175.4. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:11:37 PM	MsiInstaller	11724	None	Product: WCF Data Services 5.6.4 Runtime -- Removal completed successfully.
Information	2/4/2018 9:11:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:41:28.298679900Z.
Information	2/4/2018 9:11:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:41:14.991679900Z.
Information	2/4/2018 9:11:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}. Client Process Id: 6440.
Information	2/4/2018 9:11:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {0A3B508E-5638-4471-BCC9-954E1868CB86}. Client Process Id: 6440.
Information	2/4/2018 9:11:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: WCF Data Services Tools for Microsoft Visual Studio 2015. Product Version: 5.6.62175.4. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:11:27 PM	MsiInstaller	11724	None	Product: WCF Data Services Tools for Microsoft Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:11:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:41:14.991679900Z.
Information	2/4/2018 9:11:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:40:29.454679900Z.
Information	2/4/2018 9:11:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {0A3B508E-5638-4471-BCC9-954E1868CB86}. Client Process Id: 6440.
Information	2/4/2018 9:11:14 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {2FB312D3-E28F-3094-B6ED-47000F25D193}. Client Process Id: 6440.
Information	2/4/2018 9:11:14 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft NuGet - Visual Studio 2015. Product Version: 3.0.60624.657. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:11:14 PM	MsiInstaller	11724	None	Product: Microsoft NuGet - Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:10:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:40:29.454679900Z.
Information	2/4/2018 9:10:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:40:01.217679900Z.
Information	2/4/2018 9:10:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {2FB312D3-E28F-3094-B6ED-47000F25D193}. Client Process Id: 6440.
Information	2/4/2018 9:10:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {1B87EE82-EB1D-442C-90A3-D86B08E9B7A1}. Client Process Id: 6440.
Information	2/4/2018 9:10:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio Connected Services. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:10:29 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio Connected Services -- Removal completed successfully.
Information	2/4/2018 9:10:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:40:01.217679900Z.
Information	2/4/2018 9:09:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:39:47.751679900Z.
Information	2/4/2018 9:09:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {1B87EE82-EB1D-442C-90A3-D86B08E9B7A1}. Client Process Id: 6440.
Information	2/4/2018 9:09:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}. Client Process Id: 6440.
Information	2/4/2018 9:09:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Azure AD Authentication Connected Service. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:09:59 PM	MsiInstaller	11724	None	Product: Azure AD Authentication Connected Service -- Removal completed successfully.
Information	2/4/2018 9:09:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:39:47.751679900Z.
Information	2/4/2018 9:09:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:39:34.298679900Z.
Information	2/4/2018 9:09:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}. Client Process Id: 6440.
Information	2/4/2018 9:09:45 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A4495E4F-5218-48FB-8AD2-F3076011B9E1}. Client Process Id: 6440.
Information	2/4/2018 9:09:45 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Azure Mobile Services Connected Service. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:09:45 PM	MsiInstaller	11724	None	Product: Microsoft Azure Mobile Services Connected Service -- Removal completed successfully.
Information	2/4/2018 9:09:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:39:34.298679900Z.
Information	2/4/2018 9:09:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:39:09.333415300Z.
Information	2/4/2018 9:09:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A4495E4F-5218-48FB-8AD2-F3076011B9E1}. Client Process Id: 6440.
Information	2/4/2018 9:09:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C6A4A3DF-5A1E-4825-8D38-E5B00C196B31}. Client Process Id: 6440.
Information	2/4/2018 9:09:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Azure Storage Connected Service. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:09:29 PM	MsiInstaller	11724	None	Product: Microsoft Azure Storage Connected Service -- Removal completed successfully.
Information	2/4/2018 9:09:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:39:09.333415300Z.
Information	2/4/2018 9:09:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:37:51.429999100Z.
Information	2/4/2018 9:09:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C6A4A3DF-5A1E-4825-8D38-E5B00C196B31}. Client Process Id: 6440.
Information	2/4/2018 9:09:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D1E9367F-5F7C-4019-96B7-45967FD60DB4}. Client Process Id: 6440.
Information	2/4/2018 9:09:06 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft.VisualStudio.Office365. Product Version: 1.0.0.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:09:06 PM	MsiInstaller	11724	None	Product: Microsoft.VisualStudio.Office365 -- Removal completed successfully.
Information	2/4/2018 9:07:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:37:51.429999100Z.
Information	2/4/2018 9:07:44 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:37:01.358015500Z.
Information	2/4/2018 9:07:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D1E9367F-5F7C-4019-96B7-45967FD60DB4}. Client Process Id: 6440.
Information	2/4/2018 9:07:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9F429DF7-F8DD-4980-9673-E6DACA012F6C}. Client Process Id: 6440.
Information	2/4/2018 9:07:44 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Application Insights Tools for Visual Studio 2015. Product Version: 3.3. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:07:44 PM	MsiInstaller	11724	None	Product: Application Insights Tools for Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:07:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:37:01.358015500Z.
Information	2/4/2018 9:06:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9F429DF7-F8DD-4980-9673-E6DACA012F6C}. Client Process Id: 6440.
Information	2/4/2018 9:06:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:36:43.141659500Z.
Information	2/4/2018 9:06:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {DCAD89A6-1B28-4C9E-81E4-A3101703CAD5}. Client Process Id: 6440.
Information	2/4/2018 9:06:54 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Windows Diagnostic Tools. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:06:54 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Windows Diagnostic Tools -- Removal completed successfully.
Information	2/4/2018 9:06:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:36:43.141659500Z.
Information	2/4/2018 9:06:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:36:29.365415300Z.
Information	2/4/2018 9:06:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {DCAD89A6-1B28-4C9E-81E4-A3101703CAD5}. Client Process Id: 6440.
Information	2/4/2018 9:06:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C70B8F90-5AEA-4938-BA56-AFD05ECF3075}. Client Process Id: 6440.
Information	2/4/2018 9:06:42 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Application Timeline. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:06:42 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Application Timeline -- Removal completed successfully.
Information	2/4/2018 9:06:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:36:29.365415300Z.
Information	2/4/2018 9:06:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:36:19.172454300Z.
Information	2/4/2018 9:06:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C70B8F90-5AEA-4938-BA56-AFD05ECF3075}. Client Process Id: 6440.
Information	2/4/2018 9:06:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A36A0728-3557-407E-A25C-2F8EDE6EC858}. Client Process Id: 6440.
Information	2/4/2018 9:06:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Visual Diagnostics. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:06:29 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Visual Diagnostics -- Removal completed successfully.
Information	2/4/2018 9:06:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:36:19.172454300Z.
Information	2/4/2018 9:06:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:36:10.070275100Z.
Information	2/4/2018 9:06:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A36A0728-3557-407E-A25C-2F8EDE6EC858}. Client Process Id: 6440.
Information	2/4/2018 9:06:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {C9DF9BC6-B08D-4547-BD97-F2BBBCC370FB}. Client Process Id: 6440.
Information	2/4/2018 9:06:18 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Windows Diagnostic Tools - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:06:18 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Windows Diagnostic Tools - ENU -- Removal completed successfully.
Information	2/4/2018 9:06:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:36:10.070275100Z.
Information	2/4/2018 9:06:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:35:59.586372300Z.
Information	2/4/2018 9:06:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {C9DF9BC6-B08D-4547-BD97-F2BBBCC370FB}. Client Process Id: 6440.
Information	2/4/2018 9:06:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {2881AB98-8978-4C01-87FD-30DF4631FA88}. Client Process Id: 6440.
Information	2/4/2018 9:06:09 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Application Timeline - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:06:09 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Application Timeline - ENU -- Removal completed successfully.
Information	2/4/2018 9:05:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:35:59.586372300Z.
Information	2/4/2018 9:05:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:35:53.508588100Z.
Information	2/4/2018 9:05:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {2881AB98-8978-4C01-87FD-30DF4631FA88}. Client Process Id: 6440.
Information	2/4/2018 9:05:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CA6344FA-570D-4F9E-88F0-C88D919A680B}. Client Process Id: 6440.
Information	2/4/2018 9:05:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 XAML Visual Diagnostics - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:05:59 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 XAML Visual Diagnostics - ENU -- Removal completed successfully.
Information	2/4/2018 9:05:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:35:53.508588100Z.
Information	2/4/2018 9:05:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:35:37.649760500Z.
Information	2/4/2018 9:05:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CA6344FA-570D-4F9E-88F0-C88D919A680B}. Client Process Id: 6440.
Information	2/4/2018 9:05:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9EABBFE1-7EED-47D9-8FB8-21D7E4808057}. Client Process Id: 6440.
Information	2/4/2018 9:05:53 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Test Tools for Microsoft Visual Studio 2015. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:05:53 PM	MsiInstaller	11724	None	Product: Test Tools for Microsoft Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:05:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:35:37.649760500Z.
Information	2/4/2018 9:05:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:35:29.236443500Z.
Information	2/4/2018 9:05:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9EABBFE1-7EED-47D9-8FB8-21D7E4808057}. Client Process Id: 6440.
Information	2/4/2018 9:05:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {E41854EE-D8A6-4E03-B42D-E0006C24A306}. Client Process Id: 6440.
Information	2/4/2018 9:05:37 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Test Tools Language Pack - ENU. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:05:37 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Test Tools Language Pack - ENU -- Removal completed successfully.
Information	2/4/2018 9:05:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:35:29.236443500Z.
Information	2/4/2018 9:05:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:35:14.463398700Z.
Information	2/4/2018 9:05:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {E41854EE-D8A6-4E03-B42D-E0006C24A306}. Client Process Id: 6440.
Information	2/4/2018 9:05:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CE37CE67-2660-30EE-805B-78829CC3554B}. Client Process Id: 6440.
Information	2/4/2018 9:05:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Agents for Visual Studio 2015 Preview. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:05:28 PM	MsiInstaller	11724	None	Product: Microsoft Agents for Visual Studio 2015 Preview -- Removal completed successfully.
Information	2/4/2018 9:05:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:35:14.463398700Z.
Information	2/4/2018 9:05:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:34:39.203452100Z.
Information	2/4/2018 9:05:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CE37CE67-2660-30EE-805B-78829CC3554B}. Client Process Id: 6440.
Information	2/4/2018 9:05:13 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B57097EF-5F38-348C-8081-4D0F0B78757E}. Client Process Id: 6440.
Information	2/4/2018 9:05:13 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Agents for Visual Studio 2015 Preview - ENU. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:05:13 PM	MsiInstaller	11724	None	Product: Microsoft Agents for Visual Studio 2015 Preview - ENU -- Removal completed successfully.
Information	2/4/2018 9:04:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:34:39.203452100Z.
Information	2/4/2018 9:04:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:33:19.626831500Z.
Information	2/4/2018 9:04:39 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B57097EF-5F38-348C-8081-4D0F0B78757E}. Client Process Id: 6440.
Information	2/4/2018 9:04:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {791295AE-3B0A-3222-9E69-26C8C106E8D1}. Client Process Id: 6440.
Information	2/4/2018 9:04:39 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Team Explorer for Microsoft Visual Studio 2015. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:04:39 PM	MsiInstaller	11724	None	Product: Team Explorer for Microsoft Visual Studio 2015 -- Removal completed successfully.
Information	2/4/2018 9:03:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:33:19.626831500Z.
Information	2/4/2018 9:03:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:33:00.637932800Z.
Information	2/4/2018 9:03:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {791295AE-3B0A-3222-9E69-26C8C106E8D1}. Client Process Id: 6440.
Information	2/4/2018 9:03:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {02138196-59F1-3672-9FB9-BF868075952E}. Client Process Id: 6440.
Information	2/4/2018 9:03:19 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Team Explorer Language Pack - ENU. Product Version: 14.0.23102. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:03:19 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Team Explorer Language Pack - ENU -- Removal completed successfully.
Information	2/4/2018 9:03:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:33:00.637932800Z.
Information	2/4/2018 9:03:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:30:45.196390000Z.
Information	2/4/2018 9:03:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {02138196-59F1-3672-9FB9-BF868075952E}. Client Process Id: 6440.
Information	2/4/2018 9:03:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {61A70737-1FE8-E16A-8791-5C8D54990F5B}. Client Process Id: 6440.
Information	2/4/2018 9:03:00 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft ASP.NET Web Frameworks and Tools - Visual Studio 2015 - ENU. Product Version: 5.2.30624.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:03:00 PM	MsiInstaller	11724	None	Product: Microsoft ASP.NET Web Frameworks and Tools - Visual Studio 2015 - ENU -- Removal completed successfully.
Information	2/4/2018 9:00:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:30:45.196390000Z.
Information	2/4/2018 9:00:44 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:30:11.524023100Z.
Information	2/4/2018 9:00:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {61A70737-1FE8-E16A-8791-5C8D54990F5B}. Client Process Id: 6440.
Information	2/4/2018 9:00:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A00EC54A-CE16-4CF6-A14A-5CF81A1FE03F}. Client Process Id: 6440.
Information	2/4/2018 9:00:44 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Azure Mobile Services SDK V2.0. Product Version: 2.0.20908.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:00:44 PM	MsiInstaller	11724	None	Product: Microsoft Azure Mobile Services SDK V2.0 -- Removal completed successfully.
Information	2/4/2018 9:00:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:30:11.524023100Z.
Information	2/4/2018 9:00:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:30:04.413312100Z.
Information	2/4/2018 9:00:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A00EC54A-CE16-4CF6-A14A-5CF81A1FE03F}. Client Process Id: 6440.
Information	2/4/2018 9:00:10 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5536AAD4-740A-4577-843D-4281D3F30726}. Client Process Id: 6440.
Information	2/4/2018 9:00:10 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Azure Mobile Services Tools for Visual Studio - v1.4. Product Version: 1.4.30611.1601. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 9:00:10 PM	MsiInstaller	11724	None	Product: Microsoft Azure Mobile Services Tools for Visual Studio - v1.4 -- Removal completed successfully.
Information	2/4/2018 9:00:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:30:04.413312100Z.
Information	2/4/2018 9:00:04 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:58.819753400Z.
Information	2/4/2018 9:00:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5536AAD4-740A-4577-843D-4281D3F30726}. Client Process Id: 6440.
Information	2/4/2018 9:00:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9890DF1A-10E9-4236-94B1-1EFAA4099F13}. Client Process Id: 6440.
Information	2/4/2018 9:00:04 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Dotfuscator and Analytics Community Edition 5.18.1. Product Version: 5.18.1.2898. Product Language: 1033. Manufacturer: PreEmptive Solutions. Removal success or error status: 0.
Information	2/4/2018 9:00:04 PM	MsiInstaller	11724	None	Product: Dotfuscator and Analytics Community Edition 5.18.1 -- Removal completed successfully.
Information	2/4/2018 8:58:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:58.819753400Z.
Information	2/4/2018 8:58:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:45.046376200Z.
Information	2/4/2018 8:58:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9890DF1A-10E9-4236-94B1-1EFAA4099F13}. Client Process Id: 6440.
Information	2/4/2018 8:58:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}. Client Process Id: 6440.
Information	2/4/2018 8:58:57 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: PreEmptive Analytics Visual Studio Components. Product Version: 1.2.5134.1. Product Language: 1033. Manufacturer: PreEmptive Solutions. Removal success or error status: 0.
Information	2/4/2018 8:58:57 PM	MsiInstaller	11724	None	Product: PreEmptive Analytics Visual Studio Components -- Removal completed successfully.
Information	2/4/2018 8:58:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:45.046376200Z.
Information	2/4/2018 8:58:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}. Client Process Id: 6440.
Information	2/4/2018 8:58:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:36.818553500Z.
Information	2/4/2018 8:58:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {42AF2A8C-6EBB-3D2E-9BF1-6135379FBABC}. Client Process Id: 6440.
Information	2/4/2018 8:58:43 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Espc Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:43 PM	MsiInstaller	11724	None	Product: Windows Espc Package -- Removal completed successfully.
Information	2/4/2018 8:58:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:36.818553500Z.
Information	2/4/2018 8:58:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:28.153687100Z.
Information	2/4/2018 8:58:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {42AF2A8C-6EBB-3D2E-9BF1-6135379FBABC}. Client Process Id: 6440.
Information	2/4/2018 8:58:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {FC94D188-1E08-3707-9D23-F41178D44664}. Client Process Id: 6440.
Information	2/4/2018 8:58:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Espc Resource Package. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:36 PM	MsiInstaller	11724	None	Product: Windows Espc Resource Package -- Removal completed successfully.
Information	2/4/2018 8:58:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:28.153687100Z.
Information	2/4/2018 8:58:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:21.319003700Z.
Information	2/4/2018 8:58:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {FC94D188-1E08-3707-9D23-F41178D44664}. Client Process Id: 6440.
Information	2/4/2018 8:58:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1}. Client Process Id: 6440.
Information	2/4/2018 8:58:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit DirectX x64 Remote. Product Version: 8.100.25984. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:27 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit DirectX x64 Remote -- Removal completed successfully.
Information	2/4/2018 8:58:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:21.319003700Z.
Information	2/4/2018 8:58:21 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:11.028974800Z.
Information	2/4/2018 8:58:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1}. Client Process Id: 6440.
Information	2/4/2018 8:58:21 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A1CB8286-CFB3-A985-D799-721A0F2A27F3}. Client Process Id: 6440.
Information	2/4/2018 8:58:21 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit DirectX x86 Remote. Product Version: 8.100.25984. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:21 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit DirectX x86 Remote -- Removal completed successfully.
Information	2/4/2018 8:58:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:11.028974800Z.
Information	2/4/2018 8:58:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎02‎-‎04T15:28:00.955967600Z.
Information	2/4/2018 8:58:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:28:00.366908700Z.
Information	2/4/2018 8:58:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A1CB8286-CFB3-A985-D799-721A0F2A27F3}. Client Process Id: 6440.
Information	2/4/2018 8:58:10 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {96F4525A-470D-F15C-796E-58D9988C3E5F}. Client Process Id: 6440.
Information	2/4/2018 8:58:10 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit for Windows Store Apps DirectX x64 Remote. Product Version: 8.100.26936. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:10 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit for Windows Store Apps DirectX x64 Remote -- Removal completed successfully.
Information	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎02‎-‎04T15:28:00.955967600Z.
Information	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 7532) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\System32\dwm.exe' (pid 5644) cannot be restarted - Application SID does not match Conductor SID..
Information	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:28:00.366908700Z.
Information	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎02‎-‎04T15:27:42.478120000Z.
Information	2/4/2018 8:58:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:27:41.486020800Z.
Information	2/4/2018 8:58:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {96F4525A-470D-F15C-796E-58D9988C3E5F}. Client Process Id: 6440.
Information	2/4/2018 8:58:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {56AD3004-0B49-967F-F682-B05650B61A78}. Client Process Id: 6440.
Information	2/4/2018 8:58:00 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit for Windows Store Apps DirectX x86 Remote. Product Version: 8.100.26936. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:58:00 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit for Windows Store Apps DirectX x86 Remote -- Removal completed successfully.
Information	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎02‎-‎04T15:27:42.478120000Z.
Information	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe' (pid 12440) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Internet Explorer\iexplore.exe' (pid 9780) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\F5 VPN\f5fpclientW.exe' (pid 9596) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 9332) cannot be restarted - Application SID does not match Conductor SID..
Warning	2/4/2018 8:57:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 7568) cannot be restarted - Application SID does not match Conductor SID..
Information	2/4/2018 8:57:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:27:41.486020800Z.
Information	2/4/2018 8:57:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:27:36.147487000Z.
Information	2/4/2018 8:57:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {56AD3004-0B49-967F-F682-B05650B61A78}. Client Process Id: 6440.
Information	2/4/2018 8:57:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B74B199A-EDD4-B657-E055-327D454402D2}. Client Process Id: 6440.
Information	2/4/2018 8:57:41 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit DirectX x64 Remote. Product Version: 8.59.29989. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:57:41 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit DirectX x64 Remote -- Removal completed successfully.
Information	2/4/2018 8:57:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:27:36.147487000Z.
Information	2/4/2018 8:57:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:27:23.639236300Z.
Information	2/4/2018 8:57:35 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B74B199A-EDD4-B657-E055-327D454402D2}. Client Process Id: 6440.
Information	2/4/2018 8:57:35 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {A6030DAD-1600-F767-C8DD-C722ADFE8FBC}. Client Process Id: 6440.
Information	2/4/2018 8:57:35 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Windows Software Development Kit DirectX x86 Remote. Product Version: 8.59.29989. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:57:35 PM	MsiInstaller	11724	None	Product: Windows Software Development Kit DirectX x86 Remote -- Removal completed successfully.
Information	2/4/2018 8:57:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:27:23.639236300Z.
Information	2/4/2018 8:57:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:26:33.332206100Z.
Information	2/4/2018 8:57:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {A6030DAD-1600-F767-C8DD-C722ADFE8FBC}. Client Process Id: 6440.
Information	2/4/2018 8:57:22 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B5915D37-0637-4A26-A3AA-C5DC9F856370}. Client Process Id: 6440.
Information	2/4/2018 8:57:22 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.6 SDK. Product Version: 4.6.00081. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:57:22 PM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.6 SDK -- Removal completed successfully.
Information	2/4/2018 8:56:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:26:33.332206100Z.
Information	2/4/2018 8:56:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:25:30.593932900Z.
Information	2/4/2018 8:56:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B5915D37-0637-4A26-A3AA-C5DC9F856370}. Client Process Id: 6440.
Information	2/4/2018 8:56:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {19A5926D-66E1-46FC-854D-163AA10A52D3}. Client Process Id: 6440.
Information	2/4/2018 8:56:33 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft .NET Framework 4.5.1 SDK. Product Version: 4.5.51641. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:56:33 PM	MsiInstaller	11724	None	Product: Microsoft .NET Framework 4.5.1 SDK -- Removal completed successfully.
Information	2/4/2018 8:55:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:25:30.593932900Z.
Information	2/4/2018 8:55:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:23:15.978472700Z.
Information	2/4/2018 8:55:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {19A5926D-66E1-46FC-854D-163AA10A52D3}. Client Process Id: 6440.
Information	2/4/2018 8:55:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {1690CE56-2231-4E59-9006-A0876D949EA8}. Client Process Id: 6440.
Information	2/4/2018 8:55:30 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name:  Tools for .Net 3.5. Product Version: 3.11.50727. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:55:30 PM	MsiInstaller	11724	None	Product:  Tools for .Net 3.5 -- Removal completed successfully.
Information	2/4/2018 8:53:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:23:15.978472700Z.
Information	2/4/2018 8:53:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:22:53.912266300Z.
Information	2/4/2018 8:53:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {1690CE56-2231-4E59-9006-A0876D949EA8}. Client Process Id: 6440.
Information	2/4/2018 8:53:15 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {14F4ED5C-AE31-4111-BDBB-EE62CA295CC8}. Client Process Id: 6440.
Information	2/4/2018 8:53:15 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - x86. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:53:15 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - x86 -- Removal completed successfully.
Information	2/4/2018 8:52:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:22:53.912266300Z.
Information	2/4/2018 8:52:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:22:28.247700100Z.
Information	2/4/2018 8:52:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {14F4ED5C-AE31-4111-BDBB-EE62CA295CC8}. Client Process Id: 6440.
Information	2/4/2018 8:52:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D4989E74-FBEF-41D8-BBD5-1ABF944C31EE}. Client Process Id: 6440.
Information	2/4/2018 8:52:46 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - amd64. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:52:46 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - amd64 -- Removal completed successfully.
Information	2/4/2018 8:52:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:22:28.247700100Z.
Information	2/4/2018 8:52:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:22:05.593434900Z.
Information	2/4/2018 8:52:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D4989E74-FBEF-41D8-BBD5-1ABF944C31EE}. Client Process Id: 6440.
Information	2/4/2018 8:52:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {09F18A53-B4AC-4B87-A782-5D22AA02C8A2}. Client Process Id: 6440.
Information	2/4/2018 8:52:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Profiling Tools. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:52:27 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Profiling Tools -- Removal completed successfully.
Information	2/4/2018 8:52:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:22:05.593434900Z.
Information	2/4/2018 8:52:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:21:28.727748700Z.
Information	2/4/2018 8:52:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {09F18A53-B4AC-4B87-A782-5D22AA02C8A2}. Client Process Id: 6440.
Information	2/4/2018 8:52:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CBA11DAA-A427-4292-A9E4-760263E0D2B9}. Client Process Id: 6440.
Information	2/4/2018 8:52:05 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - x86. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:52:05 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - x86 -- Removal completed successfully.
Information	2/4/2018 8:51:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:21:28.727748700Z.
Information	2/4/2018 8:51:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:21:16.985574600Z.
Information	2/4/2018 8:51:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CBA11DAA-A427-4292-A9E4-760263E0D2B9}. Client Process Id: 6440.
Information	2/4/2018 8:51:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {62D2E847-606F-49FB-A38B-F9D5AA936331}. Client Process Id: 6440.
Information	2/4/2018 8:51:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - amd64. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:51:28 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - amd64 -- Removal completed successfully.
Information	2/4/2018 8:51:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:21:16.985574600Z.
Information	2/4/2018 8:51:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:21:07.190595200Z.
Information	2/4/2018 8:51:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {62D2E847-606F-49FB-A38B-F9D5AA936331}. Client Process Id: 6440.
Information	2/4/2018 8:51:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9194A7D4-9FAC-41E5-A98C-C40D457D5D48}. Client Process Id: 6440.
Information	2/4/2018 8:51:16 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - x86. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:51:16 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - x86 -- Removal completed successfully.
Information	2/4/2018 8:51:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:21:07.190595200Z.
Information	2/4/2018 8:51:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9194A7D4-9FAC-41E5-A98C-C40D457D5D48}. Client Process Id: 6440.
Information	2/4/2018 8:51:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:20:54.535329800Z.
Information	2/4/2018 8:51:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BBAA137F-CE8A-4A38-A251-C90A228098EB}. Client Process Id: 6440.
Information	2/4/2018 8:51:06 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Diagnostic Tools - amd64. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:51:06 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Diagnostic Tools - amd64 -- Removal completed successfully.
Information	2/4/2018 8:50:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:20:54.535329800Z.
Information	2/4/2018 8:50:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:19:57.464623300Z.
Information	2/4/2018 8:50:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BBAA137F-CE8A-4A38-A251-C90A228098EB}. Client Process Id: 6440.
Information	2/4/2018 8:50:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5B47029B-1E62-30FF-906E-694851C22782}. Client Process Id: 6440.
Information	2/4/2018 8:50:53 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Roslyn Language Services - x86. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:50:53 PM	MsiInstaller	11724	None	Product: Roslyn Language Services - x86 -- Removal completed successfully.
Information	2/4/2018 8:49:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:19:57.464623300Z.
Information	2/4/2018 8:49:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:19:50.110888000Z.
Information	2/4/2018 8:49:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5B47029B-1E62-30FF-906E-694851C22782}. Client Process Id: 6440.
Information	2/4/2018 8:49:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6C1985E7-E1C5-3A95-86EF-2C62465F15C3}. Client Process Id: 6440.
Information	2/4/2018 8:49:56 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Roslyn Language Services - x86. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:49:56 PM	MsiInstaller	11724	None	Product: Roslyn Language Services - x86 -- Removal completed successfully.
Information	2/4/2018 8:49:50 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:19:50.110888000Z.
Information	2/4/2018 8:49:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6C1985E7-E1C5-3A95-86EF-2C62465F15C3}. Client Process Id: 6440.
Information	2/4/2018 8:44:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:14:12.127093000Z.
Information	2/4/2018 8:44:36 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {9E14EF9B-ABCA-4187-A467-8B167B503679}. Client Process Id: 6440.
Information	2/4/2018 8:44:36 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 IntelliTrace (x86). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:44:36 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 IntelliTrace (x86) -- Removal completed successfully.
Information	2/4/2018 8:44:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:14:12.127093000Z.
Information	2/4/2018 8:44:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:14:00.810961500Z.
Information	2/4/2018 8:44:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {9E14EF9B-ABCA-4187-A467-8B167B503679}. Client Process Id: 6440.
Information	2/4/2018 8:44:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {43916E1E-22EA-4884-8D8C-5E99CE058A11}. Client Process Id: 6440.
Information	2/4/2018 8:44:12 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 IntelliTrace (x64). Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:44:12 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 IntelliTrace (x64) -- Removal completed successfully.
Information	2/4/2018 8:44:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:14:00.810961500Z.
Information	2/4/2018 8:43:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:13:17.161597000Z.
Information	2/4/2018 8:43:55 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {43916E1E-22EA-4884-8D8C-5E99CE058A11}. Client Process Id: 6440.
Information	2/4/2018 8:43:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CE80ADBA-2DBA-4AD5-B4DF-E924059C483C}. Client Process Id: 6440.
Information	2/4/2018 8:43:55 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 IntelliTrace Front End. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:43:55 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 IntelliTrace Front End -- Removal completed successfully.
Information	2/4/2018 8:43:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:13:17.161597000Z.
Information	2/4/2018 8:43:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:10:08.886771400Z.
Information	2/4/2018 8:43:16 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CE80ADBA-2DBA-4AD5-B4DF-E924059C483C}. Client Process Id: 6440.
Information	2/4/2018 8:43:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {65B3169E-F3E2-4752-B0F8-D0FCDC61D287}. Client Process Id: 6440.
Information	2/4/2018 8:43:16 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Preparation. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:43:16 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Preparation -- Removal completed successfully.
Information	2/4/2018 8:40:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:10:08.886771400Z.
Information	2/4/2018 8:40:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:07:24.515335900Z.
Information	2/4/2018 8:40:08 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {65B3169E-F3E2-4752-B0F8-D0FCDC61D287}. Client Process Id: 6440.
Information	2/4/2018 8:40:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {93A31A4A-197C-43F0-9687-7FFC47C33D44}. Client Process Id: 6440.
Information	2/4/2018 8:40:08 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Preparation. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:40:08 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Preparation -- Removal completed successfully.
Information	2/4/2018 8:37:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:07:24.515335900Z.
Information	2/4/2018 8:37:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎02‎-‎04T15:04:19.151801400Z.
Information	2/4/2018 8:37:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {93A31A4A-197C-43F0-9687-7FFC47C33D44}. Client Process Id: 6440.
Information	2/4/2018 8:37:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {919C67A9-2DE8-4929-A910-CB85E009B5CB}. Client Process Id: 6440.
Information	2/4/2018 8:37:23 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Microsoft Visual Studio 2015 Preparation. Product Version: 14.0.23107. Product Language: 1033. Manufacturer: Microsoft Corporation. Removal success or error status: 0.
Information	2/4/2018 8:37:23 PM	MsiInstaller	11724	None	Product: Microsoft Visual Studio 2015 Preparation -- Removal completed successfully.
Information	2/4/2018 8:34:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎02‎-‎04T15:04:19.151801400Z.
Information	2/4/2018 8:34:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {919C67A9-2DE8-4929-A910-CB85E009B5CB}. Client Process Id: 6440.
Warning	2/4/2018 7:51:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2018 7:43:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9809c4c9-09b5-11e8-9eec-204747d02364
Report Status: 0"
Information	2/4/2018 7:36:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2018 7:35:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/4/2018 6:04:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/4/2018 4:06:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2018 3:35:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2018 3:35:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/4/2018 3:35:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/4/2018 3:34:48 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	2/4/2018 2:43:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a55a9002-098b-11e8-9eec-204747d02364
Report Status: 0"
Information	2/4/2018 2:17:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 2:17:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:49Z. Reason: GVLK.
Information	2/4/2018 2:12:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 2:12:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 2:12:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 2:12:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/4/2018 2:11:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	2/4/2018 1:58:52 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/4/2018 12:50:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 12:50:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:30Z. Reason: GVLK.
Information	2/4/2018 12:45:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 12:45:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 12:45:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 12:45:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/4/2018 12:37:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2018 12:20:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 12:20:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:30Z. Reason: GVLK.
Information	2/4/2018 12:15:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 12:15:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 12:15:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 12:15:29 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]

"
Information	2/4/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/4/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 12:02:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 12:02:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:38Z. Reason: GVLK.
Information	2/4/2018 11:57:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 11:57:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 11:57:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 11:57:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/4/2018 11:54:17 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/4/2018 11:50:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 11:50:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:30Z. Reason: GVLK.
Information	2/4/2018 11:45:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 11:45:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 11:45:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 11:45:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 11:40:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 11:38:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 19610, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/4/2018 11:38:02 AM	RasClient	20225	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.226.112
TunnelIpv6Address = None
Dial-in User = .
Information	2/4/2018 11:37:57 AM	RasClient	20224	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/4/2018 11:37:57 AM	RasClient	20223	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/4/2018 11:37:57 AM	RasClient	20222	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/4/2018 11:37:57 AM	RasClient	20221	None	CoId={C2970197-FF26-4FF8-8D91-E2D409F86E1C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/4/2018 11:37:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 11:37:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:11Z. Reason: GVLK.
Information	2/4/2018 11:35:45 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	2/4/2018 11:35:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 2, Deleted: 0, Modified: 0, Compared: 15, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Warning	2/4/2018 11:35:27 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x80d40819). If this error continues, contact Microsoft Support.
Information	2/4/2018 11:35:20 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 93

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 171

Information	2/4/2018 11:35:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/4/2018 11:34:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	2/4/2018 11:34:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2018 11:34:49 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29180)(?)])(1 )(2 )]

"
Information	2/4/2018 11:34:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29180)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	2/4/2018 11:32:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/4/2018 11:31:25 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5E19FD45-57AC-4F58-A3A0-FBF3E42CCA79}
Error	2/4/2018 11:31:25 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5E19FD45-57AC-4F58-A3A0-FBF3E42CCA79}
Error	2/4/2018 11:31:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/4/2018 11:31:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	2/4/2018 11:31:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/4/2018 11:31:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29183)(?)])(1 )(2 )]

"
Information	2/4/2018 11:31:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29183)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 11:31:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/4/2018 11:31:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 11:31:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 11:30:52 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/4/2018 11:30:44 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/4/2018 11:30:42 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/4/2018 11:30:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 11:30:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 11:30:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 11:30:41 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/4/2018 11:30:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/4/2018 11:30:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/4/2018 11:30:12 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/4/2018 11:30:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/4/2018 11:30:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/4/2018 11:28:54 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8794.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/4/2018 11:28:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/4/2018 11:28:47 AM	ESENT	302	Logging/Recovery	Windows (6568) Windows: The database engine has successfully completed recovery steps.
Information	2/4/2018 11:28:47 AM	ESENT	301	Logging/Recovery	Windows (6568) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/4/2018 11:28:41 AM	ESENT	301	Logging/Recovery	Windows (6568) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS06C22.log.
Information	2/4/2018 11:28:41 AM	ESENT	300	Logging/Recovery	Windows (6568) Windows: The database engine is initiating recovery steps.
Information	2/4/2018 11:28:41 AM	ESENT	102	General	Windows (6568) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/4/2018 11:28:37 AM	Service1	0	None	Service started successfully.
Error	2/4/2018 11:28:32 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/4/2018 11:28:32 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/4/2018 11:28:30 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/4/2018 11:28:29 AM	PostgreSQL	0	None	Server started and accepting connections

Information	2/4/2018 11:28:26 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:26 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/4/2018 11:28:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/4/2018 11:28:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/4/2018 11:28:25 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3472 at 2/3/2018 5:18:39 PM (local) 2/3/2018 11:48:39 AM (UTC). This is an informational message only; no user action is required.
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/4/2018 11:28:24 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/4/2018 11:28:23 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/4/2018 11:28:23 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/4/2018 11:28:23 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/4/2018 11:28:23 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/4/2018 11:28:23 AM	PostgreSQL	0	None	"2018-02-04 11:28:23 IST LOG:  redirecting log output to logging collector process
2018-02-04 11:28:23 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/4/2018 11:28:23 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/4/2018 11:28:22 AM	PostgreSQL	0	None	Waiting for server startup...

Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3452.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/4/2018 11:28:14 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/4/2018 11:28:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/4/2018 11:28:08 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/4/2018 11:28:02 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/4/2018 11:28:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/4/2018 11:28:02 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/4/2018 10:04:15 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8794.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/4/2018 9:48:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/4/2018 9:48:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:41:02Z. Reason: GVLK.
Information	2/4/2018 9:43:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b30a8ab0-0961-11e8-88bb-204747d02364
Report Status: 0"
Information	2/4/2018 9:43:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/4/2018 9:43:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/4/2018 9:43:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/4/2018 9:43:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/4/2018 9:37:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/4/2018 9:34:18 AM	RasClient	20225	None	CoId={D72D7263-6BDF-4343-9D97-623665988555}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.243.146
TunnelIpv6Address = None
Dial-in User = .
Information	2/4/2018 9:34:13 AM	RasClient	20224	None	CoId={D72D7263-6BDF-4343-9D97-623665988555}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/4/2018 9:34:13 AM	RasClient	20223	None	CoId={D72D7263-6BDF-4343-9D97-623665988555}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/4/2018 9:34:13 AM	RasClient	20222	None	CoId={D72D7263-6BDF-4343-9D97-623665988555}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/4/2018 9:34:13 AM	RasClient	20221	None	CoId={D72D7263-6BDF-4343-9D97-623665988555}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/4/2018 9:33:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	2/4/2018 9:32:47 AM	ESENT	508	Performance	"taskhost (5152) WebCacheLocal: A request to write to the file ""C:\Users\212558710\AppData\Local\Microsoft\Windows\WebCache\V01.log"" at offset 151552 (0x0000000000025000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (34484 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Error	2/3/2018 11:58:02 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x2d32302d
Faulting process id: 0x2c7c
Faulting application start time: 0x01d39d145954d7e9
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: f7238b12-090f-11e8-88bb-204747d02364"
Error	2/3/2018 11:58:01 PM	RasClient	20227	None	CoId={E9CAB40E-4465-4803-A0F4-76BC8301C4DB}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	2/3/2018 11:58:01 PM	RasClient	20221	None	CoId={E9CAB40E-4465-4803-A0F4-76BC8301C4DB}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	2/3/2018 11:58:01 PM	RasClient	20227	None	CoId={FDA7E301-7E77-4641-B75C-1A5AAFA1D688}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	2/3/2018 11:58:01 PM	RasClient	20221	None	CoId={FDA7E301-7E77-4641-B75C-1A5AAFA1D688}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/3/2018 11:57:58 PM	RasClient	20226	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	2/3/2018 11:46:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5c457e70-090e-11e8-88bb-204747d02364
Report Status: 0"
Warning	2/3/2018 11:01:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2018 10:58:51 PM	RasClient	20225	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.246.62
TunnelIpv6Address = None
Dial-in User = .
Information	2/3/2018 10:58:49 PM	RasClient	20224	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/3/2018 10:58:49 PM	RasClient	20223	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 10:58:49 PM	RasClient	20222	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 10:58:48 PM	RasClient	20221	None	CoId={E2F398DC-BBA3-43BE-A354-D4B279F9EF71}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/3/2018 10:56:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Error	2/3/2018 10:56:31 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0aefb02c
Faulting process id: 0x114c
Faulting application start time: 0x01d39ce5ad774a2c
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: 5f400463-0907-11e8-88bb-204747d02364"
Error	2/3/2018 6:50:38 PM	RasClient	20227	None	CoId={C4D27FA0-E59E-499A-B316-9E87EA3CA3FC}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	2/3/2018 6:50:38 PM	RasClient	20221	None	CoId={C4D27FA0-E59E-499A-B316-9E87EA3CA3FC}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	2/3/2018 6:50:38 PM	RasClient	20227	None	CoId={B8536443-1FAB-4916-B8A9-EF8019CFA943}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	2/3/2018 6:50:38 PM	RasClient	20221	None	CoId={B8536443-1FAB-4916-B8A9-EF8019CFA943}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/3/2018 6:50:35 PM	RasClient	20226	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	2/3/2018 6:46:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69fee90e-08e4-11e8-88bb-204747d02364
Report Status: 0"
Information	2/3/2018 6:40:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 6:40:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:58Z. Reason: GVLK.
Information	2/3/2018 6:35:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 6:35:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254400)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 6:35:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 6:35:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 6:10:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 6:10:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:57Z. Reason: GVLK.
Information	2/3/2018 6:05:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 6:05:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 6:05:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 6:05:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 5:40:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 5:40:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:58Z. Reason: GVLK.
Information	2/3/2018 5:35:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 5:35:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 5:35:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 5:35:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 5:32:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	2/3/2018 5:28:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2018 5:27:09 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/3/2018 5:27:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 5:27:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:08Z. Reason: GVLK.
Information	2/3/2018 5:27:04 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 406

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 188

Information	2/3/2018 5:27:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/3/2018 5:25:59 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	2/3/2018 5:25:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 5:25:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30268)(?)])(1 )(2 )]

"
Information	2/3/2018 5:25:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30268)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 5:25:00 PM	RasClient	20225	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.235.149
TunnelIpv6Address = None
Dial-in User = .
Information	2/3/2018 5:24:57 PM	RasClient	20224	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/3/2018 5:24:57 PM	RasClient	20223	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 5:24:57 PM	RasClient	20222	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 5:24:57 PM	RasClient	20221	None	CoId={4E9EA64D-4C9B-4450-870E-B1CEFF5A84D4}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	2/3/2018 5:21:50 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E7FA6054-C083-4AA3-8C7A-DF3DAEE552DA}
Error	2/3/2018 5:21:50 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E7FA6054-C083-4AA3-8C7A-DF3DAEE552DA}
Error	2/3/2018 5:21:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/3/2018 5:21:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 5:21:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30273)(?)])(1 )(2 )]

"
Information	2/3/2018 5:21:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30273)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 5:21:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2018 5:21:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 5:21:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 5:21:19 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/3/2018 5:21:13 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 5:21:13 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 5:21:11 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 5:21:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 5:21:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 5:21:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 5:20:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 5:20:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/3/2018 5:20:37 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/3/2018 5:20:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/3/2018 5:20:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/3/2018 5:20:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8793.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/3/2018 5:19:50 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	2/3/2018 5:19:26 PM	ESENT	302	Logging/Recovery	Windows (7024) Windows: The database engine has successfully completed recovery steps.
Information	2/3/2018 5:19:24 PM	ESENT	301	Logging/Recovery	Windows (7024) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/3/2018 5:19:18 PM	ESENT	301	Logging/Recovery	Windows (7024) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS06C20.log.
Information	2/3/2018 5:19:18 PM	ESENT	300	Logging/Recovery	Windows (7024) Windows: The database engine is initiating recovery steps.
Information	2/3/2018 5:19:17 PM	ESENT	102	General	Windows (7024) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/3/2018 5:19:07 PM	Service1	0	None	Service started successfully.
Error	2/3/2018 5:19:02 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/3/2018 5:19:02 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/3/2018 5:18:58 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/3/2018 5:18:54 PM	PostgreSQL	0	None	"2018-02-03 17:18:54 IST LOG:  redirecting log output to logging collector process
2018-02-03 17:18:54 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/3/2018 5:18:53 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	2/3/2018 5:18:53 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/3/2018 5:18:53 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/3/2018 5:18:51 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/3/2018 5:18:44 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:43 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/3/2018 5:18:42 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/3/2018 5:18:42 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/3/2018 5:18:42 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/3/2018 5:18:41 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:41 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:41 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/3/2018 5:18:40 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/3/2018 5:18:40 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:39 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/3/2018 5:18:39 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/3/2018 5:18:39 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3668 at 2/3/2018 1:35:18 PM (local) 2/3/2018 8:05:18 AM (UTC). This is an informational message only; no user action is required.
Information	2/3/2018 5:18:39 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/3/2018 5:18:38 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3472.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/3/2018 5:18:37 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/3/2018 5:18:29 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/3/2018 5:18:25 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 5:18:15 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/3/2018 5:18:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/3/2018 5:18:15 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	2/3/2018 3:19:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/3/2018 2:56:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 2:56:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:22Z. Reason: GVLK.
Information	2/3/2018 2:51:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 2:51:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:51:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 2:51:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 2:35:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8793.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/3/2018 2:35:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 2:30:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30444)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:30:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30444)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:30:00 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	2/3/2018 2:30:00 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	2/3/2018 2:30:00 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	2/3/2018 2:29:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2018 2:29:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 2:29:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 2:26:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 2:26:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:21Z. Reason: GVLK.
Information	2/3/2018 2:21:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 2:21:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:21:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 2:21:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 2:08:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 2:03:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 2:03:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30471)(?)])(1 )(2 )]

"
Information	2/3/2018 2:03:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30471)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:02:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 2:02:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30472)(?)])(1 )(2 )]

"
Information	2/3/2018 2:02:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30472)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 2:02:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2018 2:02:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 2:02:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 1:59:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	2/3/2018 1:58:41 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/3/2018 1:56:24 PM	RasClient	20225	None	CoId={9F031658-62A6-4201-9B0D-D90253AF0146}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.242.209
TunnelIpv6Address = None
Dial-in User = .
Information	2/3/2018 1:56:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 1:56:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:20Z. Reason: GVLK.
Information	2/3/2018 1:56:19 PM	RasClient	20224	None	CoId={9F031658-62A6-4201-9B0D-D90253AF0146}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	2/3/2018 1:56:19 PM	RasClient	20223	None	CoId={9F031658-62A6-4201-9B0D-D90253AF0146}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 1:56:19 PM	RasClient	20222	None	CoId={9F031658-62A6-4201-9B0D-D90253AF0146}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	2/3/2018 1:56:19 PM	RasClient	20221	None	CoId={9F031658-62A6-4201-9B0D-D90253AF0146}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	2/3/2018 1:51:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 1:51:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:51:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 1:51:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 1:50:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 1:50:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:16Z. Reason: GVLK.
Error	2/3/2018 1:48:49 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	2/3/2018 1:48:49 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {0A0DCDFF-63E8-499C-9CCC-131F04BC911D}
Information	2/3/2018 1:47:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 1:47:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30487)(?)])(1 )(2 )]

"
Information	2/3/2018 1:47:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30487)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:46:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 77bb83ed-08ba-11e8-8e9a-204747d02364
Report Status: 0"
Error	2/3/2018 1:45:54 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {639B25D8-1215-4237-98C7-17CA486231AD}
Information	2/3/2018 1:45:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 1:45:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:45:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 1:45:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 1:44:56 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 46

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 63

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	2/3/2018 1:44:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	2/3/2018 1:44:43 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/3/2018 1:44:43 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:41Z. Reason: GVLK.
Information	2/3/2018 1:39:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 1:39:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30494)(?)])(1 )(2 )]

"
Information	2/3/2018 1:39:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30494)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:38:56 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	2/3/2018 1:37:57 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 1:37:55 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 1:37:53 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 1:37:51 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	2/3/2018 1:37:45 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E51C2C92-2EE9-44A5-8352-BF82C3A3D327}
Error	2/3/2018 1:37:45 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E51C2C92-2EE9-44A5-8352-BF82C3A3D327}
Information	2/3/2018 1:37:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/3/2018 1:37:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:37:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 1:37:21 PM	ESENT	302	Logging/Recovery	Windows (7292) Windows: The database engine has successfully completed recovery steps.
Information	2/3/2018 1:37:19 PM	ESENT	301	Logging/Recovery	Windows (7292) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	2/3/2018 1:37:10 PM	ESENT	301	Logging/Recovery	Windows (7292) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS06C1B.log.
Information	2/3/2018 1:37:10 PM	ESENT	300	Logging/Recovery	Windows (7292) Windows: The database engine is initiating recovery steps.
Information	2/3/2018 1:37:09 PM	ESENT	102	General	Windows (7292) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	2/3/2018 1:37:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 1:37:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/3/2018 1:37:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30497)(?)])(1 )(2 )]

"
Information	2/3/2018 1:36:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30497)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/3/2018 1:36:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/3/2018 1:36:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/3/2018 1:36:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	2/3/2018 1:36:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8791.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	2/3/2018 1:36:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/3/2018 1:36:23 PM	Service1	0	None	Service started successfully.
Error	2/3/2018 1:36:18 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	2/3/2018 1:36:04 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	2/3/2018 1:36:04 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	2/3/2018 1:35:51 PM	PostgreSQL	0	None	Server started and accepting connections

Information	2/3/2018 1:35:42 PM	PostgreSQL	0	None	"2018-02-03 13:35:42 IST LOG:  redirecting log output to logging collector process
2018-02-03 13:35:42 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	2/3/2018 1:35:39 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	2/3/2018 1:35:39 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	2/3/2018 1:35:38 PM	PostgreSQL	0	None	Waiting for server startup...

Information	2/3/2018 1:35:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	2/3/2018 1:35:31 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	2/3/2018 1:35:31 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	2/3/2018 1:35:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	2/3/2018 1:35:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	2/3/2018 1:35:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	2/3/2018 1:35:23 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	2/3/2018 1:35:22 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:21 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	2/3/2018 1:35:21 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	2/3/2018 1:35:21 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	2/3/2018 1:35:21 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	2/3/2018 1:35:19 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:19 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3700 at 2/1/2018 9:12:28 PM (local) 2/1/2018 3:42:28 PM (UTC). This is an informational message only; no user action is required.
Information	2/3/2018 1:35:18 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	2/3/2018 1:35:16 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3668.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	2/3/2018 1:35:15 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	2/3/2018 1:34:33 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	2/3/2018 1:34:26 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	2/3/2018 1:34:12 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	2/3/2018 1:34:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	2/3/2018 1:34:12 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	2/1/2018 9:12:36 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	2/1/2018 9:12:28 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	2/1/2018 9:11:59 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2492 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1640 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	2/1/2018 9:11:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	2/1/2018 9:11:49 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	2/1/2018 9:11:49 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	2/1/2018 8:58:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 8:44:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 8:44:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 7:52:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 7:52:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:07Z. Reason: GVLK.
Information	2/1/2018 7:47:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 7:47:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 7:47:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 7:47:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2018 7:03:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/1/2018 5:18:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 4:44:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 4:44:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 4:41:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 98689d9c-0740-11e8-bcba-204747d02364
Report Status: 0"
Warning	2/1/2018 3:23:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	2/1/2018 1:31:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 1:13:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 1:13:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:41:02Z. Reason: GVLK.
Information	2/1/2018 1:07:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 1:07:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 1:07:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 1:07:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/1/2018 12:44:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 12:44:03 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	2/1/2018 12:43:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 12:20:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8791.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	2/1/2018 12:14:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	2/1/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]

"
Information	2/1/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 12:09:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	2/1/2018 12:09:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 12:09:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	2/1/2018 11:55:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 11:41:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ae5bedb3-0716-11e8-bcba-204747d02364
Report Status: 0"
Warning	2/1/2018 10:02:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 9:54:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	2/1/2018 9:53:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	2/1/2018 9:53:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	2/1/2018 9:51:44 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/1/2018 9:30:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/1/2018 9:30:13 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	2/1/2018 8:43:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 8:40:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 8:40:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:41Z. Reason: GVLK.
Information	2/1/2018 8:35:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 8:35:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 8:35:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 8:35:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/1/2018 8:31:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/1/2018 8:31:22 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 19543, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	2/1/2018 8:30:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	2/1/2018 8:30:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	2/1/2018 8:05:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 6:41:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c4a359d8-06ec-11e8-bcba-204747d02364
Report Status: 0"
Warning	2/1/2018 6:24:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 4:43:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 4:43:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	2/1/2018 4:30:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 3:48:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 3:48:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:44Z. Reason: GVLK.
Information	2/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 3:43:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	2/1/2018 3:33:04 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	2/1/2018 3:23:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 3:23:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:05Z. Reason: GVLK.
Error	2/1/2018 3:18:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	2/1/2018 3:18:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 3:18:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 3:18:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 3:18:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	2/1/2018 2:32:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 2:09:40 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	2/1/2018 2:09:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	2/1/2018 1:41:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dae8357e-06c2-11e8-bcba-204747d02364
Report Status: 0"
Information	2/1/2018 12:43:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 12:43:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	2/1/2018 12:35:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	2/1/2018 12:35:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:37Z. Reason: GVLK.
Warning	2/1/2018 12:34:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	2/1/2018 12:30:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	2/1/2018 12:30:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	2/1/2018 12:30:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	2/1/2018 12:30:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	2/1/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/31/2018 10:49:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/31/2018 9:03:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 8:43:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2018 8:43:25 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/31/2018 8:43:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2018 8:40:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f1411c87-0698-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/31/2018 7:04:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 6:10:03 PM	PostgreSQL	0	None	Server started and accepting connections

Information	1/31/2018 6:10:02 PM	PostgreSQL	0	None	"2018-01-31 18:10:02 IST LOG:  redirecting log output to logging collector process
2018-01-31 18:10:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/31/2018 6:10:02 PM	PostgreSQL	0	None	Waiting for server startup...

Warning	1/31/2018 5:24:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 4:43:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2018 4:37:42 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:37:40 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:35:51 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:35:36 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:35:13 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:35:09 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:35:02 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:34:53 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:34:36 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:34:20 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:33:10 PM	HHCTRL	1904	None	"The description for Event ID 1904 from source HHCTRL cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

about:blank
http://go.microsoft.com/fwlink?LinkID=45840
"
Information	1/31/2018 4:00:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2018 4:00:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:16Z. Reason: GVLK.
Information	1/31/2018 3:56:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎31T10:24:45.448989300Z.
Information	1/31/2018 3:56:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {73F18524-3266-4C9D-BAEB-F73A2B6E113F}. Client Process Id: 11912.
Information	1/31/2018 3:56:05 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Enterprise Architect. Product Version: 12.1.1229.13. Product Language: 1033. Manufacturer: Sparx Systems. Removal success or error status: 0.
Information	1/31/2018 3:56:05 PM	MsiInstaller	11724	None	Product: Enterprise Architect -- Removal completed successfully.
Information	1/31/2018 3:55:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2018 3:55:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 3:55:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2018 3:55:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2018 3:54:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎31T10:24:45.448989300Z.
Information	1/31/2018 3:54:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {73F18524-3266-4C9D-BAEB-F73A2B6E113F}. Client Process Id: 11912.
Information	1/31/2018 3:40:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 074b2ac5-066f-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/31/2018 3:32:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/31/2018 1:32:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 12:43:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2018 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/31/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/31/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]

"
Information	1/31/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/31/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2018 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/31/2018 12:04:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8790.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	1/31/2018 11:50:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/31/2018 11:49:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 10:48:26 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/31/2018 10:48:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/31/2018 10:48:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/31/2018 10:40:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ceff96c-0645-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/31/2018 10:17:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 10:16:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2018 10:16:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-02-07T04:40:06Z. Reason: GVLK.
Information	1/31/2018 10:11:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 10:11:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 10:11:05 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/01/31 04:41"
Information	1/31/2018 10:11:04 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/01/31 04:41, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/31/2018 10:06:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2018 10:06:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 10:06:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2018 10:06:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/31/2018 9:51:46 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/31/2018 8:44:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 8:42:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2018 7:04:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 5:40:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 333654ff-061b-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/31/2018 5:11:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 4:42:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/31/2018 3:30:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 3:28:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/31/2018 3:28:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:01Z. Reason: GVLK.
Information	1/31/2018 3:23:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/31/2018 3:23:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/31/2018 3:23:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/31/2018 3:23:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/31/2018 3:03:51 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/31/2018 3:03:14 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	1/31/2018 1:47:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/31/2018 12:42:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/31/2018 12:40:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 49810d3e-05f1-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/30/2018 11:54:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/30/2018 10:03:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 8:41:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2018 8:06:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 7:40:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5fbf4f76-05c7-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/30/2018 6:17:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 4:41:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/30/2018 4:21:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 2:40:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 75fe32e1-059d-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/30/2018 2:34:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 1:27:21 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/30/2018 12:55:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 12:46:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/30/2018 12:41:11 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 31

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	1/30/2018 12:41:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/30/2018 12:40:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/30/2018 12:40:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36314)(?)])(1 )(2 )]

"
Information	1/30/2018 12:40:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36314)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2018 12:40:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/30/2018 12:40:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2018 12:40:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/30/2018 12:29:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8789.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/30/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/30/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/30/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]

"
Information	1/30/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2018 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/30/2018 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/30/2018 11:16:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/30/2018 9:58:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/30/2018 9:53:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/30/2018 9:53:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36481)(?)])(1 )(2 )]

"
Information	1/30/2018 9:53:23 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36481)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2018 9:53:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/30/2018 9:53:22 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 0

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 2715

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Error	1/30/2018 9:51:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/30/2018 9:47:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/30/2018 9:47:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:38Z. Reason: GVLK.
Information	1/30/2018 9:41:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/30/2018 9:41:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/30/2018 9:41:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/30/2018 9:41:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/30/2018 9:40:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c559bd3-0573-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/30/2018 9:32:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 8:05:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 8:00:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 8:00:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37314)(?)])(1 )(2 )]

"
Information	1/29/2018 8:00:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37314)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 8:00:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 8:00:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 8:00:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/29/2018 7:33:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 7:02:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e157ba94-04f8-11e8-bcba-204747d02364
Report Status: 0"
Warning	1/29/2018 5:58:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 5:18:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/29/2018 4:18:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/29/2018 2:23:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 2:02:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7ba6662-04ce-11e8-bcba-204747d02364
Report Status: 0"
Information	1/29/2018 1:40:48 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/29/2018 1:18:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2018 12:48:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8788.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Warning	1/29/2018 12:35:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]

"
Information	1/29/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 11:20:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 11:20:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:32Z. Reason: GVLK.
Information	1/29/2018 11:15:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2018 11:15:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 11:15:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 11:15:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/29/2018 10:45:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/29/2018 9:51:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/29/2018 9:34:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8431.2110.
Information	1/29/2018 9:34:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	1/29/2018 9:29:51 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	1/29/2018 9:29:51 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	1/29/2018 9:29:51 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/29/2018 9:29:51 AM	ESENT	102	General	Windows (7368) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/29/2018 9:29:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 9:28:03 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/29/2018 9:28:03 AM	ESENT	103	General	Windows (7924) Windows: The database engine stopped the instance (0).
Information	1/29/2018 9:24:27 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9956.
Information	1/29/2018 9:24:27 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8431.2153. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:24:27 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	1/29/2018 9:24:27 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/29/2018 9:24:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37950)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:24:26 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/29/2018 9:24:26 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/29/2018 9:24:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:24:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 9:24:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:24:24 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 9:23:58 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:58 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:58 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.8326.2076. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:23:58 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	1/29/2018 9:23:52 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:52 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:52 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2153. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:23:52 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/29/2018 9:23:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:48 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:48 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8431.2153. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:23:48 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/29/2018 9:23:42 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:41 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:41 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2153. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:23:41 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/29/2018 9:23:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 9:23:18 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9956.
Information	1/29/2018 9:23:18 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8431.2153. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/29/2018 9:23:18 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/29/2018 9:21:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9956.
Warning	1/29/2018 9:20:33 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x80370005). If this error continues, contact Microsoft Support.
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:19:48 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:19:46 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:19:46 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/29/2018 9:18:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 9:18:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:23Z. Reason: GVLK.
Information	1/29/2018 9:18:40 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 5601

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	1/29/2018 9:18:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/29/2018 9:18:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37956)(?)])(1 )(2 )]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37956)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37956)(?)])(1 )(2 )]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37956)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37956)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/29/2018 9:18:10 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/29/2018 9:17:52 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Microsoft Outlook'.
Information	1/29/2018 9:17:52 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	1/29/2018 9:17:52 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Skype for Business'.
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0cece9e9-9c75-408d-ac2c-b71387dddeec"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=44672911-6ce9-486c-8577-69e37929b45b"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fb6ae405-d9cb-4c48-8b34-9e2d48f0b2d7"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=f02b6312-9f65-47b1-b0c3-d0ec55736443"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a4dc4f5d-f06c-4f45-8fa9-0c5a6711e382"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f6074c19-976e-456e-adae-fd04f300b90d"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=abf9465e-246c-45fe-87e9-c7a05f27ffdb"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7000ea7e-ae84-4b49-9808-e16daec0e016"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c5b2af3a-f7ac-47a4-9656-093bad159a28"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=117e1536-1cab-4c72-8bed-0763302f75b2"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b87942b5-e66a-4c6e-a447-d3fe009c9ffe"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=d80946da-3bee-4085-b13b-f4fd50728886"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=06f16fa6-a734-491a-99e4-9aa85e32f493"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=b539daa3-3f56-4dee-ad44-6a16e0d539a8"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b463c144-5a80-4fe4-b0ff-91f65e998ddf"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=71f0965f-5737-46aa-b140-29bea4ace37d"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=01f89e86-f5f4-4951-b76c-0e3dca637794"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=221b5a73-7a9c-4f94-ad78-c7552356f191"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=462f38b0-936c-433f-be0a-b794ff1c8522"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=3e9e93ab-5d51-4735-bb42-12c1aea6a4b4"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=099a9f25-188c-4bb4-9805-cd64d34437fd"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=01358142-16c3-4a15-b7a1-e78e168eaaaa"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=3861125b-2a98-4097-b6f6-a37f88d30f09"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2a345af4-5461-458a-ae8f-138c8bd22669"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bc224e7b-84a4-4d55-9b6b-5d0053919fd4"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3fb54752-36ca-4264-b437-b55a12bf0d58"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ff87d898-6d1f-42ad-a2a4-d680319e184f"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=bd5f34b6-9712-4a1a-84b8-59afe4d071e4"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=b0f8114d-311a-4ada-9e77-5bdfb9d31714"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bed6d602-c47e-43d1-ae32-4457b2d0878f"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fd745dc4-b2d6-4f63-a241-067bdcd60a97"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e781683e-e32d-4740-95ba-37419a245551"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=7e39c211-c7e6-412f-a7c3-6d1b581f5a1e"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=14831533-43f0-45c3-839e-fb1b62799b78"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ce8b0559-43fa-416a-8930-f1272c3a9a40"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=4a5011de-81ee-491e-b9cf-82f75689f6cc"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e21c2eb5-4229-48ec-8e3d-6ef3396c4fc6"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=620ecb65-ff53-4146-9fcb-c0ec551f2f6b"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=551a3e85-365c-4e60-8496-c31a0f2dfd8c"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=49fd5545-0ebc-407c-ae78-5644903cdc0a"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bed7fed-1871-4ab7-9d76-86fef07b5ea8"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=02977a1b-630f-4e6e-88ab-255ec99a57bb"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5ac08db2-f91f-4c99-9f41-822cff1c51ce"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=d656a05d-c688-46c4-b509-91d02cb140cf"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b7b671f1-9aff-4cd3-8780-9a54fdb48028"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=aad900f2-4364-4be5-ad24-8a721ea24682"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=22ec52a1-6cd4-419b-b059-685f3d4fcbe1"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=dd255181-594c-48ca-9f5b-9ee99313c554"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f2a23fe-1d1f-4432-a8a3-f91e11b2f72e"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=24e2a915-c345-4004-b37d-bf72048f801a"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=eb6401ea-359d-4324-a415-b788828d7570"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3dfe5cc6-919f-4274-898f-4dddb8bc8901"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=5b300dd9-bfe1-4851-93a6-7d54ff317d8f"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=25c0173e-e4ce-44e5-be03-ea4aaea4acab"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d985dd13-c22b-4bf5-a61d-fc2e55097ae2"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=5cb7cbaf-cf27-439c-94d7-e6b6327f0463"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=995bacb4-4ad5-412a-bd58-fd46ab0c7a64"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=43eb82c8-ea4f-4b17-99ac-b308634a6fa3"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=c9c4572d-cbcf-4e11-bbaa-9c8f8d6b17d9"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fd3725a1-2059-4578-a0f0-9a7466f85627"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	1/29/2018 9:17:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	1/29/2018 9:17:45 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	1/29/2018 9:17:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 9:17:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:17:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/29/2018 9:17:41 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/29/2018 9:16:54 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	1/29/2018 9:13:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2018 9:13:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:13:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:13:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 9:11:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Information	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Error	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Microsoft Outlook'.
Information	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	1/29/2018 9:07:53 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Skype for Business' could not be shut down.
Information	1/29/2018 9:07:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 9:07:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:28Z. Reason: GVLK.
Information	1/29/2018 9:07:00 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎29T03:37:00.175495000Z.
Information	1/29/2018 9:06:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 9:06:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37968)(?)])(1 )(2 )]

"
Information	1/29/2018 9:06:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37968)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:05:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 1110, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/29/2018 9:04:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2018 9:04:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/29/2018 9:04:35 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/29/2018 9:04:34 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 484

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1451

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 3791

Information	1/29/2018 9:04:13 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/29/2018 9:04:12 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/29/2018 9:03:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/29/2018 9:02:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 9:02:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37971)(?)])(1 )(2 )]

"
Information	1/29/2018 9:02:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37971)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:02:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0dee9886-04a5-11e8-bcba-204747d02364
Report Status: 0"
Information	1/29/2018 9:01:43 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	1/29/2018 9:01:05 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {FAD7C6E1-9947-494C-AECC-717F75C5DC18}
Error	1/29/2018 9:01:05 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {FAD7C6E1-9947-494C-AECC-717F75C5DC18}
Information	1/29/2018 9:01:02 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/29/2018 9:01:00 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/29/2018 9:00:54 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/29/2018 9:00:52 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/29/2018 9:00:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2018 9:00:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:00:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:00:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/29/2018 9:00:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37974)(?)])(1 )(2 )]

"
Information	1/29/2018 9:00:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37974)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 9:00:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 9:00:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 9:00:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 9:00:04 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 8:59:52 AM	ESENT	302	Logging/Recovery	Windows (7924) Windows: The database engine has successfully completed recovery steps.
Information	1/29/2018 8:59:43 AM	ESENT	301	Logging/Recovery	Windows (7924) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	1/29/2018 8:59:43 AM	ESENT	300	Logging/Recovery	Windows (7924) Windows: The database engine is initiating recovery steps.
Information	1/29/2018 8:59:43 AM	ESENT	102	General	Windows (7924) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/29/2018 8:59:38 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8784.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Error	1/29/2018 8:59:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/29/2018 8:58:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/29/2018 8:58:19 AM	Service1	0	None	Service started successfully.
Error	1/29/2018 8:58:13 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/29/2018 8:58:13 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/29/2018 8:57:52 AM	PostgreSQL	0	None	Server started and accepting connections

Information	1/29/2018 8:57:51 AM	PostgreSQL	0	None	"2018-01-29 08:57:51 IST LOG:  redirecting log output to logging collector process
2018-01-29 08:57:51 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/29/2018 8:57:48 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/29/2018 8:57:47 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/29/2018 8:57:44 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/29/2018 8:57:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/29/2018 8:57:42 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	1/29/2018 8:57:42 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/29/2018 8:57:41 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/29/2018 8:57:41 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	1/29/2018 8:57:33 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:33 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/29/2018 8:57:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/29/2018 8:57:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/29/2018 8:57:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/29/2018 8:57:31 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/29/2018 8:57:30 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/29/2018 8:57:28 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:28 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:28 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/29/2018 8:57:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3260 at 1/29/2018 8:52:09 AM (local) 1/29/2018 3:22:09 AM (UTC). This is an informational message only; no user action is required.
Information	1/29/2018 8:57:25 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/29/2018 8:57:24 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/29/2018 8:57:24 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/29/2018 8:57:24 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/29/2018 8:57:24 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3700.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/29/2018 8:57:23 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/29/2018 8:56:47 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/29/2018 8:56:37 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/29/2018 8:56:21 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/29/2018 8:56:21 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/29/2018 8:56:21 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	1/29/2018 8:52:29 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	1/29/2018 8:52:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/29/2018 8:52:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 8:52:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/29/2018 8:52:08 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	1/29/2018 8:51:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 792fab0d-04a3-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/29/2018 8:51:05 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 18224 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Warning	1/29/2018 8:50:59 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 34 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 18224 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2564 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/29/2018 8:50:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	1/29/2018 8:50:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/29/2018 8:50:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/29/2018 8:50:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:47Z. Reason: GVLK.
Information	1/29/2018 8:50:50 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Error	1/29/2018 8:47:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/29/2018 8:46:16 AM	McLogEvent	257	None	The scan of D:\R1.2_SetUpFile_2017_12_16_Sa_ 1_37_43_154\DISK1\ISSetupPrerequisites\{39B44035-64F8-485C-902E-7A79A185BE70}\postgresql-9.5.3-1-windows-x64.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8784.0000.
Information	1/29/2018 8:44:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/29/2018 8:44:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/29/2018 8:44:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/29/2018 8:44:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/29/2018 8:43:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/29/2018 8:41:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/29/2018 8:40:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/29/2018 8:40:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/29/2018 8:40:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/29/2018 8:40:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/29/2018 8:40:49 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/25/2018 9:17:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 8:57:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 8:57:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:35:58Z. Reason: GVLK.
Information	1/25/2018 8:52:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 8:52:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 8:52:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 8:52:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2018 7:23:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 5:47:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2018 5:46:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2018 5:26:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cfd78c17-01c6-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/25/2018 5:24:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/25/2018 3:43:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/25/2018 2:09:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 1:46:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2018 1:46:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/25/2018 12:36:20 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/25/2018 12:28:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8784.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/25/2018 12:26:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e6023c87-019c-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/25/2018 12:18:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/25/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43545)(?)])(1 )(2 )]

"
Information	1/25/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43545)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/25/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/25/2018 11:54:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 11:54:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:08Z. Reason: GVLK.
Information	1/25/2018 11:49:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 11:49:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 11:49:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 11:49:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/25/2018 11:47:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/25/2018 11:47:02 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	1/25/2018 10:18:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 9:48:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/25/2018 9:46:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2018 9:46:54 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/25/2018 9:46:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/25/2018 9:32:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 19249, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/25/2018 9:30:27 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/25/2018 9:30:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/25/2018 9:30:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/25/2018 9:30:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/25/2018 9:30:18 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/25/2018 8:44:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 8:36:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 8:36:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:05Z. Reason: GVLK.
Information	1/25/2018 8:31:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 8:31:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 8:31:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 8:31:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/25/2018 7:26:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fc54dd0e-0172-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/25/2018 6:53:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 5:46:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/25/2018 5:13:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 4:34:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 4:33:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:35:59Z. Reason: GVLK.
Information	1/25/2018 4:28:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 4:28:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 4:28:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 4:28:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/25/2018 4:24:40 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/25/2018 4:15:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 4:15:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:30Z. Reason: GVLK.
Error	1/25/2018 4:10:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/25/2018 4:10:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 4:10:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 4:10:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 4:10:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2018 3:30:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 2:48:05 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/25/2018 2:47:25 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/25/2018 2:26:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 12a56675-0149-11e8-ad6d-204747d02364
Report Status: 0"
Information	1/25/2018 2:06:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/25/2018 2:06:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:36:23Z. Reason: GVLK.
Information	1/25/2018 2:01:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/25/2018 2:01:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/25/2018 2:01:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/25/2018 2:01:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/25/2018 1:58:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 1:46:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/25/2018 12:20:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/25/2018 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/24/2018 10:24:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 9:46:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 9:26:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 28ecbe83-011f-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/24/2018 8:33:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/24/2018 6:41:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 5:46:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/24/2018 5:06:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 4:26:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3f2b69c1-00f5-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/24/2018 3:12:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 1:45:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/24/2018 1:16:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 12:46:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 12:46:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:35:57Z. Reason: GVLK.
Information	1/24/2018 12:41:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2018 12:41:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 12:41:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 12:41:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/24/2018 12:36:19 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/24/2018 12:16:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8783.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/24/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/24/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44985)(?)])(1 )(2 )]

"
Information	1/24/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44985)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/24/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/24/2018 11:33:08 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 11:26:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 556f1d09-00cb-11e8-ad6d-204747d02364
Report Status: 0"
Information	1/24/2018 10:51:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 10:46:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/24/2018 10:46:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 10:46:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/24/2018 10:32:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 10:27:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/24/2018 10:27:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45087)(?)])(1 )(2 )]

"
Information	1/24/2018 10:27:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45087)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 10:27:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/24/2018 10:27:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 10:27:45 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/24/2018 10:16:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/24/2018 10:15:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/24/2018 10:11:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 10:11:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-31T04:35:48Z. Reason: GVLK.
Information	1/24/2018 10:06:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 10:06:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 10:06:47 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/01/24 04:36"
Information	1/24/2018 10:06:47 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/01/24 04:36, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/24/2018 10:01:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2018 10:01:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 10:01:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 10:01:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/24/2018 9:55:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 9:45:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 9:25:41 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/24/2018 8:09:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 7:22:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 7:22:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:44Z. Reason: GVLK.
Information	1/24/2018 7:17:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2018 7:17:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 7:17:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 7:17:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/24/2018 6:26:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6bad6665-00a1-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/24/2018 6:09:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 5:45:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 5:45:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 5:09:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 5:09:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:04Z. Reason: GVLK.
Information	1/24/2018 5:04:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2018 5:04:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 5:04:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 5:04:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/24/2018 4:59:50 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/24/2018 4:53:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/24/2018 4:53:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:25Z. Reason: GVLK.
Error	1/24/2018 4:48:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/24/2018 4:48:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/24/2018 4:48:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/24/2018 4:48:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/24/2018 4:48:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/24/2018 4:26:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/24/2018 2:41:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 2:10:17 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/24/2018 2:09:47 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/24/2018 1:45:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 1:45:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/24/2018 1:26:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 81fef46d-0077-11e8-ad6d-204747d02364
Report Status: 0"
Warning	1/24/2018 12:59:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/24/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/23/2018 11:04:26 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 9:45:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 9:45:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2018 9:28:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 8:26:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 986e0cd3-004d-11e8-ad6d-204747d02364
Report Status: 0"
Information	1/23/2018 8:09:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 8:04:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/23/2018 8:04:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 8:04:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/23/2018 7:48:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/23/2018 6:05:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 5:45:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 5:45:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 5:45:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 4:54:12 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/23/2018 4:54:06 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/23/2018 4:14:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 3:26:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ae9c345e-0023-11e8-ad6d-204747d02364
Report Status: 0"
Information	1/23/2018 2:34:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 2:34:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:31Z. Reason: GVLK.
Information	1/23/2018 2:29:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2018 2:29:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2018 2:29:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 2:29:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/23/2018 2:19:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 1:45:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 1:45:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/23/2018 12:43:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/23/2018 12:36:05 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/23/2018 12:36:05 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/23/2018 12:30:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 12:25:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/23/2018 12:25:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 12:25:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/23/2018 12:23:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8782.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/23/2018 12:14:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/23/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46425)(?)])(1 )(2 )]

"
Information	1/23/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/23/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/23/2018 10:47:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 10:27:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 10:26:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c4e2c02d-fff9-11e7-ad6d-204747d02364
Report Status: 0"
Information	1/23/2018 10:21:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/23/2018 10:21:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 10:21:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/23/2018 9:45:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/23/2018 9:45:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 9:42:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/23/2018 9:42:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/23/2018 9:42:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	1/23/2018 8:47:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/23/2018 7:16:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 6:46:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 6:41:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎23T01:11:57.585901600Z.
Information	1/23/2018 6:41:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/23/2018 6:41:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 6:41:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/23/2018 5:45:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 5:44:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 5:44:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 5:39:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 5:39:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:56Z. Reason: GVLK.
Information	1/23/2018 5:34:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2018 5:34:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2018 5:34:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 5:34:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/23/2018 5:26:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: db4229d8-ffcf-11e7-ad6d-204747d02364
Report Status: 0"
Warning	1/23/2018 5:21:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 4:00:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 4:00:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:45Z. Reason: GVLK.
Information	1/23/2018 3:55:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2018 3:55:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2018 3:55:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 3:55:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/23/2018 3:51:46 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	1/23/2018 3:49:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 3:45:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/23/2018 3:45:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:19Z. Reason: GVLK.
Error	1/23/2018 3:40:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/23/2018 3:40:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/23/2018 3:40:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/23/2018 3:40:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/23/2018 3:40:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/23/2018 2:07:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/23/2018 1:45:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 1:44:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/23/2018 12:26:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f184cbb6-ffa5-11e7-ad6d-204747d02364
Report Status: 0"
Information	1/23/2018 12:19:06 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/23/2018 12:18:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/22/2018 10:20:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 9:44:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 9:44:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 9:44:31 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/22/2018 9:44:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2018 8:31:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 7:26:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 06a13802-ff7c-11e7-ad6d-204747d02364
Report Status: 0"
Warning	1/22/2018 6:52:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 5:44:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 5:44:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2018 5:09:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/22/2018 3:30:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 2:26:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bbead3e-ff52-11e7-ad6d-204747d02364
Report Status: 0"
Information	1/22/2018 1:44:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 1:44:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/22/2018 1:41:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/22/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47865)(?)])(1 )(2 )]

"
Information	1/22/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47865)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/22/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/22/2018 11:44:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/22/2018 11:42:52 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/22/2018 11:42:46 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/22/2018 11:14:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 11:14:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:24Z. Reason: GVLK.
Information	1/22/2018 11:09:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2018 11:09:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 11:09:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 11:09:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 11:02:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 10:57:37 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎22T05:27:37.581613400Z.
Information	1/22/2018 10:57:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/22/2018 10:57:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 10:57:24 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 10:33:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 10:33:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:53Z. Reason: GVLK.
Information	1/22/2018 10:32:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 10:28:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2018 10:28:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 10:28:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 10:28:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 10:27:43 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎22T04:57:43.204461300Z.
Information	1/22/2018 10:27:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/22/2018 10:27:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 10:27:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 10:24:51 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8781.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/22/2018 10:22:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎22T04:52:15.610705200Z.
Error	1/22/2018 10:07:35 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/22/2018 10:02:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 9:57:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/22/2018 9:57:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 9:57:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 9:52:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 90, Deleted: 0, Modified: 21, Compared: 19061, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/22/2018 9:49:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 9:47:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 9:47:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:28Z. Reason: GVLK.
Warning	1/22/2018 9:46:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/22/2018 9:45:20 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/22/2018 9:44:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 9:44:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/22/2018 9:44:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/22/2018 9:44:32 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 202

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	1/22/2018 9:44:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/22/2018 9:43:37 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	1/22/2018 9:43:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/22/2018 9:43:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48011)(?)])(1 )(2 )]

"
Information	1/22/2018 9:43:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48011)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	1/22/2018 9:43:02 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5023F48B-38A5-4DDC-8E20-D3378D349365}
Error	1/22/2018 9:43:02 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {5023F48B-38A5-4DDC-8E20-D3378D349365}
Error	1/22/2018 9:42:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/22/2018 9:42:43 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	1/22/2018 9:42:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/22/2018 9:42:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48012)(?)])(1 )(2 )]

"
Information	1/22/2018 9:42:41 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48012)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 9:42:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2018 9:42:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 9:42:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 9:42:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 9:42:06 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	1/22/2018 9:42:06 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	1/22/2018 9:42:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	1/22/2018 9:42:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	1/22/2018 9:39:21 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	1/22/2018 9:39:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B56BF067-609E-4E98-AFF9-A5AA9FE543BD}
Error	1/22/2018 9:39:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {B56BF067-609E-4E98-AFF9-A5AA9FE543BD}
Information	1/22/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/22/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48015)(?)])(1 )(2 )]

"
Information	1/22/2018 9:39:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48015)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 9:39:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/22/2018 9:39:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 9:39:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 9:31:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/22/2018 9:31:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:10Z. Reason: GVLK.
Information	1/22/2018 9:30:02 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/22/2018 9:30:02 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	1/22/2018 9:25:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/22/2018 9:25:31 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 84 second(s) to handle the notification event (CreateSession).
Information	1/22/2018 9:25:22 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	1/22/2018 9:25:16 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/22/2018 9:25:14 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/22/2018 9:25:13 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	1/22/2018 9:25:07 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	1/22/2018 9:24:11 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/22/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/22/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/22/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	1/22/2018 9:23:55 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (RasBase)
License Id=dbbd74e8-8a74-f200-ab6a-d5ac9689cb5b"
Information	1/22/2018 9:23:54 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (PeerToPeerBase)
License Id=3fe222d7-0891-97e9-4ee7-323d5c48265d"
Information	1/22/2018 9:23:54 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (NetworkSecurity)
License Id=b1d0a08e-b875-344e-ea23-c5ef62d74c32"
Information	1/22/2018 9:23:54 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	1/22/2018 9:23:54 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	1/22/2018 9:23:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/22/2018 9:23:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/22/2018 9:23:40 AM	ESENT	302	Logging/Recovery	Windows (6732) Windows: The database engine has successfully completed recovery steps.
Information	1/22/2018 9:23:37 AM	ESENT	301	Logging/Recovery	Windows (6732) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	1/22/2018 9:23:28 AM	ESENT	301	Logging/Recovery	Windows (6732) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05777.log.
Information	1/22/2018 9:23:28 AM	ESENT	300	Logging/Recovery	Windows (6732) Windows: The database engine is initiating recovery steps.
Information	1/22/2018 9:23:28 AM	ESENT	102	General	Windows (6732) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/22/2018 9:23:10 AM	Service1	0	None	Service started successfully.
Error	1/22/2018 9:22:58 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	1/22/2018 9:22:58 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	1/22/2018 9:22:58 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8778.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/22/2018 9:22:46 AM	PostgreSQL	0	None	Server started and accepting connections

Information	1/22/2018 9:22:45 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	1/22/2018 9:22:45 AM	PostgreSQL	0	None	"2018-01-22 09:22:45 IST LOG:  redirecting log output to logging collector process
2018-01-22 09:22:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	1/22/2018 9:22:42 AM	PostgreSQL	0	None	Waiting for server startup...

Information	1/22/2018 9:22:41 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	1/22/2018 9:22:36 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:36 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	1/22/2018 9:22:36 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	1/22/2018 9:22:36 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	1/22/2018 9:22:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	1/22/2018 9:22:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	1/22/2018 9:22:34 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	1/22/2018 9:22:32 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:32 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:32 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3824 at 1/19/2018 8:38:47 PM (local) 1/19/2018 3:08:47 PM (UTC). This is an informational message only; no user action is required.
Information	1/22/2018 9:22:31 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	1/22/2018 9:22:30 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	1/22/2018 9:22:30 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	1/22/2018 9:22:30 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	1/22/2018 9:22:30 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	1/22/2018 9:22:30 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3260.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	1/22/2018 9:22:29 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	1/22/2018 9:22:00 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	1/22/2018 9:21:50 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	1/22/2018 9:19:50 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	1/22/2018 9:19:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	1/22/2018 9:19:50 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	1/19/2018 8:38:55 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	1/19/2018 8:38:47 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	1/19/2018 8:37:12 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 35 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2408 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2408 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 952 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 952 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 952 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 952 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 952 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1208 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	1/19/2018 8:37:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	1/19/2018 8:37:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	1/19/2018 8:37:08 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Warning	1/19/2018 8:32:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 8:14:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30c55729-fd27-11e7-923e-80e860e098da
Report Status: 0"
Information	1/19/2018 6:53:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/19/2018 6:53:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:13Z. Reason: GVLK.
Information	1/19/2018 6:48:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/19/2018 6:48:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2018 6:48:13 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2018 6:48:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/19/2018 6:42:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 6:04:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2018 6:04:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2018 5:56:31 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/19/2018 4:49:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 3:14:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47056c7a-fcfd-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/19/2018 2:55:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 2:04:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/19/2018 2:03:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/19/2018 1:15:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 12:26:35 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8778.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/19/2018 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/19/2018 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/19/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52185)(?)])(1 )(2 )]

"
Information	1/19/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2018 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/19/2018 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2018 12:09:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/19/2018 11:44:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 10:52:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/19/2018 10:52:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:51Z. Reason: GVLK.
Information	1/19/2018 10:47:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/19/2018 10:47:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2018 10:47:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2018 10:47:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/19/2018 10:44:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95bfc1e7-fcd7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/19/2018 10:44:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95bfc1e6-fcd7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/19/2018 10:44:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95bfc1e5-fcd7-11e7-923e-80e860e098da
Report Status: 0"
Error	1/19/2018 10:28:58 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/19/2018 10:13:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d00742f-fcd3-11e7-923e-80e860e098da
Report Status: 0"
Information	1/19/2018 10:11:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/19/2018 10:11:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:55Z. Reason: GVLK.
Information	1/19/2018 10:09:42 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/19/2018 10:08:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/19/2018 10:06:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/19/2018 10:06:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/19/2018 10:06:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2018 10:06:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/19/2018 10:06:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/19/2018 10:04:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/19/2018 10:04:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/19/2018 10:04:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/19/2018 10:04:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/19/2018 10:03:57 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/19/2018 10:03:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/19/2018 10:03:53 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/19/2018 10:03:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	1/18/2018 7:31:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/18/2018 5:51:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 5:48:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ab58cc8c-fc49-11e7-923e-80e860e098da
Report Status: 0"
Information	1/18/2018 5:41:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 5:41:22 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/18/2018 5:41:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 5:40:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/18/2018 3:57:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/18/2018 2:26:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 1:41:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 1:40:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 1:24:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 1:24:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:10Z. Reason: GVLK.
Information	1/18/2018 1:19:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 1:19:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 1:19:08 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	1/18/2018 1:19:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 1:19:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 1:18:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/18/2018 1:17:41 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/18/2018 1:17:40 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/18/2018 1:16:58 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/18/2018 1:16:43 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/18/2018 12:59:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎18T07:24:58.738510000Z.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 26216.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/18/2018 12:59:53 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6 -- Configuration completed successfully.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4055002. Installation success or error status: 0.
Information	1/18/2018 12:59:53 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6 - Update 'KB4055002' installed successfully.
Information	1/18/2018 12:57:50 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:50 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:50 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:49 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:49 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:48 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:48 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:47 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:47 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:47 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:37 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00003.log
Information	1/18/2018 12:57:34 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/18/2018 12:57:30 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/18/2018 12:57:30 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:57:26 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/18/2018 12:57:03 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	1/18/2018 12:57:02 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00002.log
Information	1/18/2018 12:57:00 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/18/2018 12:56:57 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/18/2018 12:56:57 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:56:35 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	1/18/2018 12:56:34 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	1/18/2018 12:56:23 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	1/18/2018 12:56:15 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:56:15 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:56:03 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4908.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4908.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4908.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 8056.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4908.
Information	1/18/2018 12:56:01 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 3912.
Information	1/18/2018 12:55:15 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe' (pid 17588) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE' (pid 22584) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE' (pid 12044) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 12696) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe' (pid 8056) cannot be restarted - Application SID does not match Conductor SID..
Warning	1/18/2018 12:55:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\explorer.exe' (pid 4908) cannot be restarted - Application SID does not match Conductor SID..
Information	1/18/2018 12:54:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎18T07:24:58.738510000Z.
Information	1/18/2018 12:54:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 26216.
Information	1/18/2018 12:48:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1946cec-fc1f-11e7-923e-80e860e098da
Report Status: 0"
Information	1/18/2018 12:48:03 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎18T07:13:13.386510000Z.
Information	1/18/2018 12:48:03 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 23512.
Information	1/18/2018 12:48:03 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/18/2018 12:48:03 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6 -- Configuration completed successfully.
Information	1/18/2018 12:48:03 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4054183. Installation success or error status: 0.
Information	1/18/2018 12:48:03 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6 - Update 'KB4054183' installed successfully.
Warning	1/18/2018 12:45:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 12:44:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/18/2018 12:44:14 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:14 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:13 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:13 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:13 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:12 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:11 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:11 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:10 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:44:10 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:43:51 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:43:50 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	1/18/2018 12:43:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎18T07:13:13.386510000Z.
Information	1/18/2018 12:43:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 23512.
Information	1/18/2018 12:42:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 12:42:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:46Z. Reason: GVLK.
Information	1/18/2018 12:37:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 12:37:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 12:37:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 12:37:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 12:31:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8777.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/18/2018 12:22:27 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/18/2018 12:14:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/18/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53625)(?)])(1 )(2 )]

"
Information	1/18/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53625)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/18/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 11:08:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 11:08:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:26Z. Reason: GVLK.
Information	1/18/2018 11:03:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 11:03:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 11:03:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 11:03:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/18/2018 10:58:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 9:52:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/18/2018 9:46:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 8, Compared: 18895, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/18/2018 9:45:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/18/2018 9:45:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/18/2018 9:41:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 9:40:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 9:40:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/18/2018 9:38:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	1/18/2018 9:38:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/18/2018 9:00:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 7:56:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/18/2018 7:56:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/18/2018 7:48:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d77c54ac-fbf5-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/18/2018 7:22:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 7:14:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 7:14:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:24Z. Reason: GVLK.
Information	1/18/2018 7:09:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 7:09:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 7:09:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 7:09:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 5:41:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 5:40:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 5:40:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/18/2018 5:23:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 4:57:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 4:57:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:07Z. Reason: GVLK.
Information	1/18/2018 4:52:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 4:52:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 4:52:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 4:52:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 4:51:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a56dbb6-fbdd-11e7-923e-80e860e098da
Report Status: 0"
Information	1/18/2018 4:51:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a56dbb5-fbdd-11e7-923e-80e860e098da
Report Status: 0"
Information	1/18/2018 4:51:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a56dbb4-fbdd-11e7-923e-80e860e098da
Report Status: 0"
Error	1/18/2018 4:47:56 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/18/2018 4:39:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 4:39:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:36Z. Reason: GVLK.
Error	1/18/2018 4:35:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/18/2018 4:34:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 4:34:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 4:34:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 4:34:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/18/2018 4:04:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/18/2018 4:04:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:04Z. Reason: GVLK.
Information	1/18/2018 3:59:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/18/2018 3:59:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/18/2018 3:59:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/18/2018 3:59:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/18/2018 3:28:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 2:58:36 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/18/2018 2:57:09 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	1/18/2018 2:48:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: edd4cde5-fbcb-11e7-923e-80e860e098da
Report Status: 0"
Information	1/18/2018 1:41:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 1:40:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 1:40:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/18/2018 1:40:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/18/2018 1:29:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/18/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/17/2018 11:52:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/17/2018 10:04:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 9:48:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 04039770-fba2-11e7-923e-80e860e098da
Report Status: 0"
Information	1/17/2018 9:40:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 9:40:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 9:40:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2018 8:15:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 6:49:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2018 6:49:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:32:34Z. Reason: GVLK.
Information	1/17/2018 6:44:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2018 6:44:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 6:44:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2018 6:44:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/17/2018 6:29:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 5:40:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 5:40:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 5:39:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 4:48:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a3fe8c9-fb78-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/17/2018 4:33:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/17/2018 2:49:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 1:40:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 1:39:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 1:39:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2018 1:17:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 12:24:24 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8776.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/17/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/17/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/17/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]

"
Information	1/17/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/17/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/17/2018 11:48:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3092071d-fb4e-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/17/2018 11:34:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 10:18:36 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F32180144F0}. Client Process Id: 23392.
Information	1/17/2018 10:18:36 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java 8 Update 144. Product Version: 8.0.1440.1. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	1/17/2018 10:18:36 AM	MsiInstaller	11724	None	Product: Java 8 Update 144 -- Removal completed successfully.
Information	1/17/2018 10:17:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F32180144F0}. Client Process Id: 23392.
Information	1/17/2018 10:17:54 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F64180144F0}. Client Process Id: 23392.
Information	1/17/2018 10:17:54 AM	MsiInstaller	1029	None	Product: Java 8 Update 144 (64-bit). Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	1/17/2018 10:17:54 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Java 8 Update 144 (64-bit). Product Version: 8.0.1440.1. Product Language: 1033. Manufacturer: Oracle Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	1/17/2018 10:17:54 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java 8 Update 144 (64-bit). Product Version: 8.0.1440.1. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	1/17/2018 10:17:54 AM	MsiInstaller	11724	None	Product: Java 8 Update 144 (64-bit) -- Removal completed successfully.
Information	1/17/2018 10:16:43 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎17T04:46:42.518658200Z.
Information	1/17/2018 10:16:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F64180144F0}. Client Process Id: 23392.
Information	1/17/2018 10:16:43 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161\au.msi. Client Process Id: 23392.
Information	1/17/2018 10:16:43 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java Auto Updater. Product Version: 2.8.161.12. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 1603.
Information	1/17/2018 10:16:43 AM	MsiInstaller	11708	None	Product: Java Auto Updater -- Installation failed.
Error	1/17/2018 10:16:43 AM	MsiInstaller	11303	None	Product: Java Auto Updater -- Error 1303. The installer has insufficient privileges to access this directory: C:\Program Files (x86)\Common Files\Java\Java Update.  The installation cannot continue.  Log on as administrator or contact your system administrator.
Information	1/17/2018 10:16:42 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎17T04:46:42.518658200Z.
Information	1/17/2018 10:16:42 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2018‎-‎01‎-‎17T04:46:37.387658200Z.
Information	1/17/2018 10:16:42 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎17T04:46:37.132658200Z.
Information	1/17/2018 10:16:42 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161\au.msi. Client Process Id: 23392.
Information	1/17/2018 10:16:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4A03706F-666A-4037-7777-5F2748764D10}. Client Process Id: 23392.
Information	1/17/2018 10:16:42 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java Auto Updater. Product Version: 2.8.144.1. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	1/17/2018 10:16:42 AM	MsiInstaller	11724	None	Product: Java Auto Updater -- Removal completed successfully.
Information	1/17/2018 10:16:37 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎17T04:46:37.387658200Z.
Information	1/17/2018 10:16:37 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/17/2018 10:16:37 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe' (pid 6836) cannot be restarted - Application SID does not match Conductor SID..
Information	1/17/2018 10:16:37 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎17T04:46:37.132658200Z.
Information	1/17/2018 10:16:37 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4A03706F-666A-4037-7777-5F2748764D10}. Client Process Id: 23392.
Information	1/17/2018 10:16:36 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161_x64\jre1.8.0_161patch64.msi. Client Process Id: 23392.
Information	1/17/2018 10:16:36 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java 8 Update 161 (64-bit). Product Version: 8.0.1610.12. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 0.
Information	1/17/2018 10:16:36 AM	MsiInstaller	11707	None	Product: Java 8 Update 161 (64-bit) -- Installation completed successfully.
Information	1/17/2018 10:15:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161_x64\jre1.8.0_161patch64.msi. Client Process Id: 23392.
Information	1/17/2018 10:15:46 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161\jre1.8.0_161patch.msi. Client Process Id: 23392.
Information	1/17/2018 10:15:46 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java 8 Update 161. Product Version: 8.0.1610.12. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 0.
Information	1/17/2018 10:15:46 AM	MsiInstaller	11707	None	Product: Java 8 Update 161 -- Installation completed successfully.
Information	1/17/2018 10:15:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/17/2018 10:14:53 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_161\jre1.8.0_161patch.msi. Client Process Id: 23392.
Information	1/17/2018 10:14:42 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/17/2018 10:07:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2018 10:07:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-24T04:31:36Z. Reason: GVLK.
Information	1/17/2018 10:02:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 10:02:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 10:02:35 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/01/17 04:32"
Information	1/17/2018 10:02:34 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/01/17 04:32, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/17/2018 9:57:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/17/2018 9:57:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2018 9:57:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 9:57:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2018 9:57:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/17/2018 9:47:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 9:40:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 9:39:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 9:39:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 9:39:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/17/2018 9:38:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/17/2018 7:52:16 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 6:48:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46d5bd06-fb24-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/17/2018 6:01:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 5:40:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 5:39:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 5:39:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 4:19:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2018 4:19:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:31Z. Reason: GVLK.
Information	1/17/2018 4:14:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2018 4:14:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 4:14:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2018 4:14:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/17/2018 4:13:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5843314-fb0e-11e7-923e-80e860e098da
Report Status: 0"
Information	1/17/2018 4:13:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5843313-fb0e-11e7-923e-80e860e098da
Report Status: 0"
Information	1/17/2018 4:13:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5843312-fb0e-11e7-923e-80e860e098da
Report Status: 0"
Error	1/17/2018 4:10:42 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	1/17/2018 4:09:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 4:03:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/17/2018 4:03:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:13Z. Reason: GVLK.
Error	1/17/2018 3:58:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/17/2018 3:58:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/17/2018 3:58:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/17/2018 3:58:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/17/2018 3:58:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/17/2018 2:15:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 1:48:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5d307c21-fafa-11e7-923e-80e860e098da
Report Status: 0"
Information	1/17/2018 1:40:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 1:39:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/17/2018 1:39:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/17/2018 12:18:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/17/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/16/2018 11:24:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2018 11:24:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:36Z. Reason: GVLK.
Information	1/16/2018 11:19:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2018 11:19:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2018 11:19:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2018 11:19:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/16/2018 10:19:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 9:39:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 9:39:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 9:39:26 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/16/2018 9:39:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 9:39:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 8:48:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 73742f8f-fad0-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/16/2018 8:27:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/16/2018 6:38:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 5:39:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 5:39:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 5:38:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 5:38:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2018 5:04:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 3:48:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89adf71c-faa6-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/16/2018 3:16:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/16/2018 3:05:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/16/2018 1:41:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 1:39:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 1:38:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 1:38:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 12:14:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/16/2018 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/16/2018 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]

"
Information	1/16/2018 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2018 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/16/2018 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2018 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/16/2018 12:07:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8775.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Warning	1/16/2018 12:01:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 11:20:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2018 11:20:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:18Z. Reason: GVLK.
Information	1/16/2018 11:15:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2018 11:15:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2018 11:15:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2018 11:15:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/16/2018 10:48:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9feecba7-fa7c-11e7-923e-80e860e098da
Report Status: 0"
Information	1/16/2018 10:39:35 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/16/2018 10:39:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	1/16/2018 10:10:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 9:56:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/16/2018 9:39:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 9:38:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/16/2018 9:38:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/16/2018 9:38:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2018 8:24:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 7:34:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/16/2018 7:34:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:26Z. Reason: GVLK.
Information	1/16/2018 7:29:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/16/2018 7:29:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/16/2018 7:29:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2018 7:29:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/16/2018 6:49:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 6:35:27 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/16/2018 6:30:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/16/2018 6:30:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/16/2018 6:30:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/16/2018 6:20:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/16/2018 6:20:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	1/16/2018 5:48:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6313500-fa52-11e7-923e-80e860e098da
Report Status: 0"
Information	1/16/2018 5:39:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 5:38:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 5:38:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/16/2018 5:16:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/16/2018 3:29:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/16/2018 1:55:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/16/2018 1:39:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 1:38:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 1:37:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/16/2018 12:48:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cc8ed8fe-fa28-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/16/2018 12:03:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/15/2018 10:12:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 9:38:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 9:38:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 9:37:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2018 8:13:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 7:47:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e2d6a969-f9fe-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/15/2018 6:42:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 5:38:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 5:38:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 5:38:08 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/15/2018 5:38:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 5:37:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2018 4:58:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/15/2018 3:10:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 2:47:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f91b5098-f9d4-11e7-923e-80e860e098da
Report Status: 0"
Information	1/15/2018 1:56:50 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Installation complete
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Started the installation of GE Set QualityCompat 1.0 V01 with the following commandline: /Q
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	1/15/2018 1:45:45 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	1/15/2018 1:38:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/15/2018 1:38:15 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/15/2018 1:37:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/15/2018 1:12:34 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 1:10:29 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/15/2018 1:10:29 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/15/2018 12:56:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/15/2018 12:55:58 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/15/2018 12:22:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2018 12:22:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:19Z. Reason: GVLK.
Information	1/15/2018 12:17:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2018 12:17:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2018 12:17:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2018 12:17:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 12:15:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/15/2018 12:13:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8774.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/15/2018 12:10:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/15/2018 12:10:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57944)(?)])(1 )(2 )]

"
Information	1/15/2018 12:10:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57944)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2018 12:10:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/15/2018 12:10:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2018 12:10:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 12:10:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4ff34db-f9be-11e7-923e-80e860e098da
Report Status: 0"
Information	1/15/2018 12:10:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4ff34da-f9be-11e7-923e-80e860e098da
Report Status: 0"
Information	1/15/2018 12:10:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f4ff34d9-f9be-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/15/2018 11:20:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/15/2018 11:11:03 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/15/2018 10:46:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/15/2018 10:44:11 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/15/2018 10:44:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2018 10:44:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:53Z. Reason: GVLK.
Information	1/15/2018 10:38:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2018 10:38:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2018 10:38:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2018 10:38:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 10:23:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/15/2018 10:18:30 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/15/2018 10:18:30 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/15/2018 10:18:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 9:47:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0de806fe-f9ab-11e7-923e-80e860e098da
Report Status: 0"
Information	1/15/2018 9:47:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/15/2018 9:47:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:18Z. Reason: GVLK.
Information	1/15/2018 9:47:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 13, Deleted: 0, Modified: 3, Compared: 18738, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/15/2018 9:45:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/15/2018 9:43:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/15/2018 9:41:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/15/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/15/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2018 9:40:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	1/15/2018 9:40:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/15/2018 9:40:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 9:40:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/15/2018 9:40:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58094)(?)])(1 )(2 )]

"
Information	1/15/2018 9:40:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58094)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/15/2018 9:40:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/15/2018 9:40:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	1/15/2018 9:40:09 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/15/2018 9:40:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/15/2018 9:39:45 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8771.0000.
Information	1/15/2018 9:37:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/15/2018 9:37:30 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	1/12/2018 6:50:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 6:30:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 6:29:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2018 5:10:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/12/2018 3:35:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 3:33:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 3:28:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62066)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 3:28:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62066)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 3:28:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/12/2018 3:28:17 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/12/2018 3:28:17 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	1/12/2018 3:28:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2018 3:28:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 3:28:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/12/2018 3:20:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 3:15:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/12/2018 3:15:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62079)(?)])(1 )(2 )]

"
Information	1/12/2018 3:15:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62079)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 3:15:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2018 3:15:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 3:15:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/12/2018 2:46:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 525883f8-f779-11e7-923e-80e860e098da
Report Status: 0"
Information	1/12/2018 2:30:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 2:29:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/12/2018 2:29:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/12/2018 2:04:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 1:16:07 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/12/2018 1:16:05 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/12/2018 1:15:33 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/12/2018 1:15:31 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/12/2018 12:15:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 12:14:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/12/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62265)(?)])(1 )(2 )]

"
Information	1/12/2018 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 12:09:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2018 12:09:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 12:09:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/12/2018 12:07:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8771.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Warning	1/12/2018 10:44:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 10:37:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/12/2018 10:36:44 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/12/2018 10:36:44 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/12/2018 10:34:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 10:29:23 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 171

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 94

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 31

Information	1/12/2018 10:29:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 10:28:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/12/2018 10:28:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62365)(?)])(1 )(2 )]

"
Information	1/12/2018 10:28:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62365)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 10:28:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2018 10:28:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 10:28:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/12/2018 9:47:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/12/2018 9:46:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 68411a21-f74f-11e7-923e-80e860e098da
Report Status: 0"
Information	1/12/2018 9:27:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 9:27:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 9:27:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:28:02Z. Reason: GVLK.
Information	1/12/2018 9:22:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2018 9:22:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 9:22:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 9:22:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2018 9:13:18 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/12/2018 7:24:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 6:49:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 6:44:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/12/2018 6:44:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 6:44:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/12/2018 5:44:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 5:27:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 4:46:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7e2384e8-f725-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/12/2018 4:04:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/12/2018 2:21:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/12/2018 1:27:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/12/2018 1:18:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/12/2018 1:18:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:58Z. Reason: GVLK.
Information	1/12/2018 1:13:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/12/2018 1:13:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/12/2018 1:13:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/12/2018 1:13:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/12/2018 12:26:00 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 11:46:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94a155fa-f6fb-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/11/2018 10:26:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 9:27:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/11/2018 8:52:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/11/2018 7:08:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 6:46:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aadf14ea-f6d1-11e7-923e-80e860e098da
Report Status: 0"
Information	1/11/2018 5:33:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 5:28:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 5:28:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63386)(?)])(1 )(2 )]

"
Information	1/11/2018 5:28:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63386)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 5:27:06 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	1/11/2018 5:26:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2018 5:26:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 5:26:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63388)(?)])(1 )(2 )]

"
Information	1/11/2018 5:26:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63388)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 5:26:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2018 5:26:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 5:26:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/11/2018 5:21:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 4:36:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2018 4:36:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/11/2018 3:45:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 2:16:44 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/11/2018 2:14:49 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	1/11/2018 1:54:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 1:46:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c01daad9-f6a7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/11/2018 12:43:44 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/11/2018 12:36:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/11/2018 12:15:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8770.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/11/2018 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63705)(?)])(1 )(2 )]

"
Information	1/11/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/11/2018 11:58:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 11:19:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/11/2018 11:19:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/11/2018 11:19:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/11/2018 11:04:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 11:04:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:33Z. Reason: GVLK.
Information	1/11/2018 10:59:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 10:59:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 10:59:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 10:59:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 10:56:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 10:56:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:40Z. Reason: GVLK.
Information	1/11/2018 10:51:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 10:51:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 10:51:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 10:51:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 10:41:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 10:41:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:59Z. Reason: GVLK.
Information	1/11/2018 10:36:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 10:36:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 10:36:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 10:36:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 10:31:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 10:31:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:25Z. Reason: GVLK.
Information	1/11/2018 10:26:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 10:26:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 10:26:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 10:26:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/11/2018 10:21:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	1/11/2018 9:47:00 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/11/2018 9:44:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 9:39:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 9:39:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63855)(?)])(1 )(2 )]

"
Information	1/11/2018 9:39:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63855)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 9:39:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2018 9:39:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 9:39:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 9:27:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 9:21:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 9:21:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63872)(?)])(1 )(2 )]

"
Information	1/11/2018 9:21:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63872)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 9:21:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2018 9:21:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 9:21:57 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 9:16:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 9:16:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:30Z. Reason: GVLK.
Information	1/11/2018 9:11:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 9:11:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 9:11:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 9:11:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/11/2018 9:10:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21b3af6f-f681-11e7-923e-80e860e098da
Report Status: 0"
Information	1/11/2018 9:10:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21b3af6e-f681-11e7-923e-80e860e098da
Report Status: 0"
Information	1/11/2018 9:10:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21b3af6d-f681-11e7-923e-80e860e098da
Report Status: 0"
Error	1/11/2018 9:03:11 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/11/2018 8:49:27 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 8:46:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d4ce3999-f67d-11e7-923e-80e860e098da
Report Status: 0"
Information	1/11/2018 8:44:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/11/2018 8:44:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:48Z. Reason: GVLK.
Information	1/11/2018 8:44:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/11/2018 8:44:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63910)(?)])(1 )(2 )]

"
Information	1/11/2018 8:44:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63910)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 8:44:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/11/2018 8:44:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 8:44:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/11/2018 8:41:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/11/2018 8:39:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/11/2018 8:39:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/11/2018 8:39:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/11/2018 8:39:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/11/2018 8:38:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/11/2018 8:36:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/10/2018 8:21:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2018 8:21:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/10/2018 8:20:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2018 8:02:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/10/2018 6:17:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 4:56:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0b7c272a-f5f9-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/10/2018 4:27:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 4:20:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2018 2:27:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 2:10:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 2:10:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:33Z. Reason: GVLK.
Information	1/10/2018 2:05:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2018 2:05:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 2:05:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 2:05:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/10/2018 12:50:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 12:38:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8769.0000
 
 Number of signatures in EXTRA.DAT : 4
 Names of threats that EXTRA.DAT can detect : Linux/Spectre (ED)
Linux/Spectre.a (ED)
Linux/Spectre.b (ED)
Trojan-Meltdown (ED)
"
Information	1/10/2018 12:25:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 12:21:41 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/10/2018 12:21:24 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/10/2018 12:21:24 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 7, Deleted: 0, Modified: 18, Compared: 18604, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/10/2018 12:20:46 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Recovery from a failure which might have caused an indexer hole.
Information	1/10/2018 12:20:46 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/10/2018 12:20:45 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	1/10/2018 12:20:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/10/2018 12:20:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/10/2018 12:20:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65134)(?)])(1 )(2 )]

"
Information	1/10/2018 12:20:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65134)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 12:20:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/10/2018 12:20:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 12:20:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/10/2018 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/10/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]

"
Information	1/10/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/10/2018 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/10/2018 11:56:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21b66f88-f5cf-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/10/2018 11:04:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 10:03:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 10:03:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-17T04:27:11Z. Reason: GVLK.
Information	1/10/2018 9:58:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 9:58:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 9:58:10 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/01/10 04:28"
Information	1/10/2018 9:58:09 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/01/10 04:28, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/10/2018 9:53:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2018 9:53:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 9:53:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 9:53:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/10/2018 9:46:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/10/2018 9:05:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 9:04:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18cc6184-f5b7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/10/2018 9:04:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18cc6183-f5b7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/10/2018 8:42:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2018 8:41:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2018 7:33:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 6:56:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37f656b2-f5a5-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/10/2018 5:40:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 4:42:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2018 4:41:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2018 4:01:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 3:47:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 3:47:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:06Z. Reason: GVLK.
Information	1/10/2018 3:42:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2018 3:42:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 3:42:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 3:42:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/10/2018 3:41:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 042a7d08-f58a-11e7-923e-80e860e098da
Report Status: 0"
Information	1/10/2018 3:41:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 042a7d07-f58a-11e7-923e-80e860e098da
Report Status: 0"
Information	1/10/2018 3:41:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 042a7d06-f58a-11e7-923e-80e860e098da
Report Status: 0"
Error	1/10/2018 3:38:16 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/10/2018 3:31:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/10/2018 3:31:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:20Z. Reason: GVLK.
Error	1/10/2018 3:26:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/10/2018 3:26:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/10/2018 3:26:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/10/2018 3:26:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/10/2018 3:26:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/10/2018 2:25:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 1:56:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e485d66-f57b-11e7-923e-80e860e098da
Report Status: 0"
Information	1/10/2018 12:42:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/10/2018 12:41:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/10/2018 12:41:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/10/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/9/2018 10:54:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 9:51:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 9:51:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:53Z. Reason: GVLK.
Information	1/9/2018 9:46:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2018 9:46:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 9:46:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 9:46:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/9/2018 9:02:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 8:55:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 64204698-f551-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 8:42:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2018 8:40:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/9/2018 7:04:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/9/2018 5:11:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 4:42:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/9/2018 4:40:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2018 3:55:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79dbbff3-f527-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 3:39:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	1/9/2018 3:38:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 3:34:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2018 3:34:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66379)(?)])(1 )(2 )]

"
Information	1/9/2018 3:34:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66379)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 3:34:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 3:34:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 3:34:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 3:31:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 3:26:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 3:26:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 3:26:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/9/2018 1:52:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 1:20:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/9/2018 1:19:25 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/9/2018 1:19:23 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/9/2018 1:18:45 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 9, Compared: 18554, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/9/2018 1:18:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/9/2018 1:18:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/9/2018 12:48:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 12:42:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66551)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 12:42:01 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	1/9/2018 12:41:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2018 12:41:57 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/9/2018 12:41:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66553)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 12:41:24 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/9/2018 12:41:06 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/9/2018 12:40:55 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x80940819). If this error continues, contact Microsoft Support.
Information	1/9/2018 12:40:54 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/9/2018 12:40:52 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	1/9/2018 12:40:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/9/2018 12:40:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2018 12:40:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66554)(?)])(1 )(2 )]

"
Information	1/9/2018 12:40:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66554)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 12:40:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 12:40:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 12:40:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 12:35:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8768.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!8243e9b8243f (ED)
"
Information	1/9/2018 12:31:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 12:26:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 12:26:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 12:26:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 12:14:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 12:09:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66584)(?)])(1 )(2 )]

"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66584)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109784  Grace type=8.
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=4a78d59a-0594-415e-892b-ae779396c4ce"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=3c397c4c-731b-49f5-9164-30095f88f6fe"
Information	1/9/2018 12:09:50 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/9/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/9/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20505)(?)])(1 )(2 )]

"
Information	1/9/2018 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 20505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	1/9/2018 12:05:07 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/9/2018 12:04:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 12:04:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:47Z. Reason: GVLK.
Warning	1/9/2018 12:02:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 11:59:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2018 11:59:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 11:59:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 11:59:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 10:55:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9021e2cd-f4fd-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/9/2018 10:30:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 10:20:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 10:20:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:12Z. Reason: GVLK.
Information	1/9/2018 10:15:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2018 10:15:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 10:15:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 10:15:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	1/9/2018 9:46:42 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/9/2018 8:55:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/9/2018 7:00:34 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 6:08:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 6:03:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/9/2018 6:03:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 6:03:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 5:55:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a6791936-f4d3-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 5:14:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 5:14:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:28Z. Reason: GVLK.
Warning	1/9/2018 5:14:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 5:09:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2018 5:09:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 5:09:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 5:09:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/9/2018 5:08:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0cf020ea-f4cd-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 5:08:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0cf020e9-f4cd-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 5:08:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0cf020e8-f4cd-11e7-923e-80e860e098da
Report Status: 0"
Error	1/9/2018 5:05:16 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/9/2018 4:57:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/9/2018 4:57:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:01Z. Reason: GVLK.
Error	1/9/2018 4:52:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/9/2018 4:52:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/9/2018 4:52:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/9/2018 4:52:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/9/2018 4:52:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/9/2018 3:28:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/9/2018 1:28:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/9/2018 12:55:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bc8d0d40-f4a9-11e7-923e-80e860e098da
Report Status: 0"
Information	1/9/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/8/2018 11:50:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 10:58:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 10:58:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:15Z. Reason: GVLK.
Information	1/8/2018 10:53:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2018 10:53:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 10:53:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 10:53:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/8/2018 9:52:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 7:55:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2fd71cd-f47f-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/8/2018 7:55:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 7:26:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 7:20:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2018 7:20:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 7:20:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 7:16:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	1/8/2018 6:11:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 5:50:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/8/2018 5:50:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/8/2018 5:50:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/8/2018 5:50:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/8/2018 4:47:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/8/2018 4:13:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 4:00:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 3:54:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21720)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 3:53:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2018 3:53:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 3:53:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 2:55:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e9579863-f455-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/8/2018 2:18:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 1:50:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 1:50:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 1:50:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 12:48:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8767.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!8243e9b8243f (ED)
"
Warning	1/8/2018 12:39:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 12:35:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 12:35:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:29Z. Reason: GVLK.
Information	1/8/2018 12:30:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2018 12:30:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 12:30:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 12:30:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/8/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21945)(?)])(1 )(2 )]

"
Information	1/8/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 21945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2018 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 11:37:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 11:32:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/8/2018 11:32:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 11:32:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 11:08:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/8/2018 11:07:22 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	1/8/2018 10:49:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 10:43:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/8/2018 9:55:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ffa404f5-f42b-11e7-923e-80e860e098da
Report Status: 0"
Information	1/8/2018 9:50:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 9:50:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 9:50:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/8/2018 9:46:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/8/2018 9:00:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/8/2018 7:20:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 5:50:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 5:50:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 5:49:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2018 5:21:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 4:55:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15f93165-f402-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/8/2018 3:31:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 3:26:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 3:26:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:25Z. Reason: GVLK.
Information	1/8/2018 3:21:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2018 3:21:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 3:21:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 3:21:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 3:20:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2d1b705-f3f4-11e7-923e-80e860e098da
Report Status: 0"
Information	1/8/2018 3:20:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2d1b704-f3f4-11e7-923e-80e860e098da
Report Status: 0"
Information	1/8/2018 3:20:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2d1b703-f3f4-11e7-923e-80e860e098da
Report Status: 0"
Error	1/8/2018 3:17:45 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/8/2018 3:11:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 3:11:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:58Z. Reason: GVLK.
Error	1/8/2018 3:07:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/8/2018 3:06:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2018 3:06:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 3:06:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 3:06:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 1:50:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 1:50:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/8/2018 1:49:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/8/2018 1:32:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/8/2018 1:00:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/8/2018 1:00:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:20Z. Reason: GVLK.
Information	1/8/2018 12:55:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/8/2018 12:55:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/8/2018 12:55:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/8/2018 12:55:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/8/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/7/2018 11:55:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2c4fae63-f3d8-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/7/2018 11:52:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2018 9:55:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 9:50:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 9:50:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 9:50:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/7/2018 9:49:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/7/2018 7:56:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 6:55:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 42a96ec1-f3ae-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/7/2018 6:10:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 5:50:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 5:50:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 5:49:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/7/2018 4:30:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2018 2:39:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 1:55:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 59103dd1-f384-11e7-923e-80e860e098da
Report Status: 0"
Information	1/7/2018 1:50:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 1:49:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 1:49:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 1:02:26 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/7/2018 12:43:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 12:38:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8766.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!8243e9b8243f (ED)
"
Information	1/7/2018 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23385)(?)])(1 )(2 )]

"
Information	1/7/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 23385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/7/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/7/2018 10:49:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 9:50:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 9:49:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 9:49:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/7/2018 9:46:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/7/2018 9:07:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2018 9:07:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:33Z. Reason: GVLK.
Information	1/7/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2018 9:02:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2018 9:02:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2018 8:55:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6f41156d-f35a-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/7/2018 8:49:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2018 7:11:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 7:02:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/7/2018 6:57:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/7/2018 6:57:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2018 6:57:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/7/2018 5:50:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 5:49:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 5:49:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/7/2018 5:38:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/7/2018 4:03:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 3:55:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 859d10cf-f330-11e7-923e-80e860e098da
Report Status: 0"
Information	1/7/2018 3:43:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2018 3:43:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:40Z. Reason: GVLK.
Information	1/7/2018 3:38:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2018 3:38:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2018 3:38:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2018 3:38:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/7/2018 3:38:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15621985-f32e-11e7-923e-80e860e098da
Report Status: 0"
Information	1/7/2018 3:38:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15621984-f32e-11e7-923e-80e860e098da
Report Status: 0"
Information	1/7/2018 3:38:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15621983-f32e-11e7-923e-80e860e098da
Report Status: 0"
Error	1/7/2018 3:34:29 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/7/2018 3:28:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/7/2018 3:28:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:26Z. Reason: GVLK.
Error	1/7/2018 3:23:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/7/2018 3:23:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/7/2018 3:23:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/7/2018 3:23:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/7/2018 3:23:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/7/2018 2:27:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 1:50:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 1:49:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/7/2018 1:49:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/7/2018 12:39:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/7/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/6/2018 11:06:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 10:55:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9be085d2-f306-11e7-923e-80e860e098da
Report Status: 0"
Information	1/6/2018 9:49:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 9:49:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 9:48:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/6/2018 9:30:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 9:28:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 9:28:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:31Z. Reason: GVLK.
Information	1/6/2018 9:23:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 9:23:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 9:23:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 9:23:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/6/2018 7:34:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 5:55:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b242a978-f2dc-11e7-923e-80e860e098da
Report Status: 0"
Information	1/6/2018 5:49:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 5:48:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 5:48:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 5:47:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 5:47:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:39Z. Reason: GVLK.
Information	1/6/2018 5:42:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 5:42:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 5:42:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 5:42:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/6/2018 5:39:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/6/2018 4:03:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 3:57:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 3:57:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:03Z. Reason: GVLK.
Information	1/6/2018 3:52:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 3:52:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 3:52:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 3:52:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/6/2018 2:29:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 1:49:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 1:48:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 1:48:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 12:55:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c89d4541-f2b2-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/6/2018 12:43:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 12:27:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8765.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!8243e9b8243f (ED)
"
Information	1/6/2018 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/6/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 24825)(?)])(1 )(2 )]

"
Information	1/6/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 24825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/6/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/6/2018 11:20:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	1/6/2018 11:20:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/6/2018 11:20:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	1/6/2018 10:58:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 9:56:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 9:56:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:13Z. Reason: GVLK.
Information	1/6/2018 9:51:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 9:51:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 9:51:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 9:51:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/6/2018 9:49:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 9:48:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 9:48:42 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/6/2018 9:48:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/6/2018 9:46:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/6/2018 9:31:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 17, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/6/2018 9:31:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/6/2018 9:31:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 9, Compared: 18495, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/6/2018 9:30:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	1/6/2018 9:30:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/6/2018 9:30:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Warning	1/6/2018 9:12:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 7:55:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: deb00ad7-f288-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/6/2018 7:18:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 5:49:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 5:48:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/6/2018 5:31:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 4:38:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 4:38:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:49Z. Reason: GVLK.
Information	1/6/2018 4:33:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 4:33:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 4:33:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 4:33:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/6/2018 3:52:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 3:24:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 3:24:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:52Z. Reason: GVLK.
Information	1/6/2018 3:19:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 3:19:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 3:19:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 3:19:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/6/2018 3:19:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e9bb149-f262-11e7-923e-80e860e098da
Report Status: 0"
Information	1/6/2018 3:19:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e9bb148-f262-11e7-923e-80e860e098da
Report Status: 0"
Information	1/6/2018 3:19:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e9bb147-f262-11e7-923e-80e860e098da
Report Status: 0"
Error	1/6/2018 3:15:31 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/6/2018 3:09:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/6/2018 3:09:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:09Z. Reason: GVLK.
Error	1/6/2018 3:04:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/6/2018 3:04:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/6/2018 3:04:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/6/2018 3:04:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/6/2018 3:04:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/6/2018 2:55:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5104a37-f25e-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/6/2018 2:03:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 1:49:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/6/2018 1:48:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/6/2018 12:13:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/6/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/5/2018 10:31:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 9:55:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0b771b0d-f235-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 9:49:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 9:48:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 8:49:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8764.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!8243e9b8243f (ED)
"
Warning	1/5/2018 8:47:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/5/2018 7:09:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 5:48:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 5:47:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 5:47:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/5/2018 5:39:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 4:55:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21ce3bd4-f20b-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/5/2018 3:59:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/5/2018 2:02:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 1:48:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 1:47:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	1/5/2018 12:49:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8764.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!d8b368e92603 (ED)
"
Information	1/5/2018 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	1/5/2018 12:11:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/5/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26265)(?)])(1 )(2 )]

"
Information	1/5/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 26265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/5/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/5/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/5/2018 11:55:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37a6bf77-f1e1-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 11:49:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/5/2018 11:49:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:41Z. Reason: GVLK.
Information	1/5/2018 11:44:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/5/2018 11:44:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/5/2018 11:44:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 11:44:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/5/2018 10:54:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/5/2018 10:45:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/5/2018 10:45:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/5/2018 10:11:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 9:48:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 9:47:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 9:47:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/5/2018 9:46:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/5/2018 8:37:21 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/5/2018 7:02:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 6:55:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e0cb14d-f1b7-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 6:06:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎05T00:36:48.959669100Z.
Information	1/5/2018 6:06:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎05T00:36:48.112584400Z.
Information	1/5/2018 6:06:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎05T00:36:47.719545100Z.
Information	1/5/2018 6:06:52 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1928172\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10100.
Information	1/5/2018 6:06:51 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/5/2018 6:06:51 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/5/2018 6:06:50 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎05T00:36:48.959669100Z.
Information	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎05T00:36:48.112584400Z.
Information	1/5/2018 6:06:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎05T00:36:47.719545100Z.
Information	1/5/2018 6:06:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1928172\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10100.
Information	1/5/2018 5:48:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 5:47:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 5:47:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/5/2018 5:05:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/5/2018 4:47:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:26Z. Reason: GVLK.
Information	1/5/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/5/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/5/2018 4:42:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 4:42:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/5/2018 4:18:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/5/2018 4:18:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:35Z. Reason: GVLK.
Information	1/5/2018 4:13:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/5/2018 4:13:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/5/2018 4:13:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 4:13:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/5/2018 4:12:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c55d981-f1a0-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 4:12:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c55d980-f1a0-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 4:12:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c55d97f-f1a0-11e7-923e-80e860e098da
Report Status: 0"
Error	1/5/2018 4:09:46 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/5/2018 4:09:30 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/5/2018 4:04:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/5/2018 4:04:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 4:04:29 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/5/2018 4:03:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/5/2018 4:03:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:09Z. Reason: GVLK.
Error	1/5/2018 3:58:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/5/2018 3:58:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/5/2018 3:58:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/5/2018 3:58:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/5/2018 3:58:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/5/2018 3:30:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 3:07:00 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T21:36:57.019278300Z.
Information	1/5/2018 3:07:00 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T21:36:56.160278300Z.
Information	1/5/2018 3:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T21:36:55.762278300Z.
Information	1/5/2018 3:07:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927825\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 13992.
Information	1/5/2018 3:06:59 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/5/2018 3:06:59 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/5/2018 3:06:58 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/5/2018 3:06:57 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 3:06:57 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 3:06:57 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T21:36:57.019278300Z.
Information	1/5/2018 3:06:57 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 3:06:57 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 3:06:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T21:36:56.160278300Z.
Information	1/5/2018 3:06:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T21:36:55.762278300Z.
Information	1/5/2018 3:06:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927825\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 13992.
Warning	1/5/2018 1:57:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 1:55:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6441239f-f18d-11e7-923e-80e860e098da
Report Status: 0"
Information	1/5/2018 1:48:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 1:47:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/5/2018 1:47:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/5/2018 12:09:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/5/2018 12:07:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T18:37:16.967442900Z.
Information	1/5/2018 12:07:20 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T18:37:16.122358400Z.
Information	1/5/2018 12:07:20 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927477\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 14028.
Information	1/5/2018 12:07:19 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T18:37:15.733319500Z.
Information	1/5/2018 12:07:19 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/5/2018 12:07:19 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/5/2018 12:07:18 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T18:37:16.967442900Z.
Information	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/5/2018 12:07:16 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T18:37:16.122358400Z.
Information	1/5/2018 12:07:15 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T18:37:15.733319500Z.
Information	1/5/2018 12:07:14 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927477\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 14028.
Information	1/5/2018 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	1/4/2018 10:38:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 10:19:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2018 10:19:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:33Z. Reason: GVLK.
Information	1/4/2018 10:14:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2018 10:14:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2018 10:14:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2018 10:14:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2018 9:47:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 9:47:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 9:47:25 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/4/2018 9:46:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 9:07:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T15:37:42.449098800Z.
Information	1/4/2018 9:07:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T15:37:41.560009900Z.
Information	1/4/2018 9:07:45 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927102\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11428.
Information	1/4/2018 9:07:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T15:37:41.164970400Z.
Information	1/4/2018 9:07:45 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 9:07:45 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 9:07:43 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 9:07:42 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 9:07:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 9:07:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T15:37:42.449098800Z.
Information	1/4/2018 9:07:42 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 9:07:42 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 9:07:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T15:37:41.560009900Z.
Information	1/4/2018 9:07:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T15:37:41.164970400Z.
Information	1/4/2018 9:07:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1927102\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11428.
Warning	1/4/2018 9:05:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 8:55:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7aa99bd5-f163-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/4/2018 7:06:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 6:39:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/4/2018 6:34:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/4/2018 6:34:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2018 6:34:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27320)(?)])(1 )(2 )]

"
Information	1/4/2018 6:34:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27320)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2018 6:34:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/4/2018 6:34:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2018 6:34:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/4/2018 6:07:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T12:37:08.744115500Z.
Information	1/4/2018 6:07:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T12:37:07.895115500Z.
Information	1/4/2018 6:07:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T12:37:07.503115500Z.
Information	1/4/2018 6:07:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926748\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 4604.
Information	1/4/2018 6:07:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 6:07:11 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 6:07:10 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 6:07:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 6:07:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 6:07:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T12:37:08.744115500Z.
Information	1/4/2018 6:07:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 6:07:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 6:07:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T12:37:07.895115500Z.
Information	1/4/2018 6:07:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T12:37:07.503115500Z.
Information	1/4/2018 6:07:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926748\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 4604.
Information	1/4/2018 5:47:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 5:46:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/4/2018 5:30:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 3:55:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 911438e0-f139-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 3:53:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2018 3:53:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:32Z. Reason: GVLK.
Information	1/4/2018 3:48:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2018 3:48:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2018 3:48:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2018 3:48:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/4/2018 3:42:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 3:08:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T09:38:55.102458700Z.
Information	1/4/2018 3:08:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T09:38:54.241372600Z.
Information	1/4/2018 3:08:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T09:38:53.836332100Z.
Information	1/4/2018 3:08:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926408\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5308.
Information	1/4/2018 3:08:57 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 3:08:57 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 3:08:56 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 3:08:55 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 3:08:55 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 3:08:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T09:38:55.102458700Z.
Information	1/4/2018 3:08:55 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 3:08:55 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 3:08:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T09:38:54.241372600Z.
Information	1/4/2018 3:08:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T09:38:53.836332100Z.
Information	1/4/2018 3:08:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926408\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 5308.
Warning	1/4/2018 2:04:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 1:47:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 1:46:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/4/2018 12:11:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T06:41:08.681923300Z.
Information	1/4/2018 12:11:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T06:41:07.613816500Z.
Information	1/4/2018 12:11:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T06:41:07.190774200Z.
Information	1/4/2018 12:11:12 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926063\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 3528.
Information	1/4/2018 12:11:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 12:11:11 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 12:11:10 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 12:11:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 12:11:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 12:11:08 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T06:41:08.681923300Z.
Information	1/4/2018 12:11:08 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 12:11:08 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 12:11:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T06:41:07.613816500Z.
Information	1/4/2018 12:11:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T06:41:07.190774200Z.
Information	1/4/2018 12:11:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1926063\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 3528.
Information	1/4/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/4/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27705)(?)])(1 )(2 )]

"
Information	1/4/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 27705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/4/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	1/4/2018 12:06:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 12:02:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8763.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!d8b368e92603 (ED)
"
Information	1/4/2018 10:55:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a42fcc5f-f10f-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 10:39:38 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/4/2018 10:39:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/4/2018 10:39:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	1/4/2018 10:31:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 10:10:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 524f9ed0-f109-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 10:10:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 524f9ecf-f109-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 9:47:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	1/4/2018 9:46:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/4/2018 9:46:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 9:07:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T03:37:49.461470600Z.
Information	1/4/2018 9:07:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T03:37:48.648389300Z.
Information	1/4/2018 9:07:52 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T03:37:48.255350000Z.
Information	1/4/2018 9:07:52 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925722\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11128.
Information	1/4/2018 9:07:52 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 9:07:52 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Information	1/4/2018 9:07:49 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 9:07:49 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 9:07:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T03:37:49.461470600Z.
Information	1/4/2018 9:07:49 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 9:07:49 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Error	1/4/2018 9:07:50 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 9:07:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T03:37:48.648389300Z.
Information	1/4/2018 9:07:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T03:37:48.255350000Z.
Information	1/4/2018 9:07:47 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925722\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11128.
Warning	1/4/2018 8:41:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/4/2018 6:45:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T00:36:45.438996500Z.
Information	1/4/2018 6:06:48 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T00:36:44.603996500Z.
Information	1/4/2018 6:06:47 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎04T00:36:44.185996500Z.
Information	1/4/2018 6:06:48 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925372\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8544.
Information	1/4/2018 6:06:47 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 6:06:47 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 6:06:46 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 6:06:45 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 6:06:45 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 6:06:45 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T00:36:45.438996500Z.
Information	1/4/2018 6:06:45 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 6:06:45 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 6:06:44 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T00:36:44.603996500Z.
Information	1/4/2018 6:06:44 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎04T00:36:44.185996500Z.
Information	1/4/2018 6:06:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925372\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8544.
Information	1/4/2018 5:55:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ba92810d-f0e5-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 5:47:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 5:46:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/4/2018 5:08:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	1/4/2018 3:09:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 3:07:36 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T21:37:33.537641100Z.
Information	1/4/2018 3:07:36 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T21:37:32.691556500Z.
Information	1/4/2018 3:07:36 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T21:37:32.295516900Z.
Information	1/4/2018 3:07:36 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925022\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10072.
Information	1/4/2018 3:07:36 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 3:07:36 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/4/2018 3:07:35 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 3:07:33 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 3:07:33 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 3:07:33 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T21:37:33.537641100Z.
Information	1/4/2018 3:07:33 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 3:07:33 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 3:07:32 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T21:37:32.691556500Z.
Information	1/4/2018 3:07:32 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T21:37:32.295516900Z.
Information	1/4/2018 3:07:31 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1925022\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 10072.
Information	1/4/2018 2:51:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/4/2018 2:51:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:23Z. Reason: GVLK.
Information	1/4/2018 2:46:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/4/2018 2:46:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/4/2018 2:46:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/4/2018 2:46:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/4/2018 1:47:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/4/2018 1:46:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/4/2018 1:28:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/4/2018 12:55:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d0ea97cd-f0bb-11e7-923e-80e860e098da
Report Status: 0"
Information	1/4/2018 12:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T18:36:56.045813100Z.
Information	1/4/2018 12:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T18:36:55.223992100Z.
Information	1/4/2018 12:06:58 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T18:36:54.827596100Z.
Information	1/4/2018 12:06:59 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1924675\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12684.
Information	1/4/2018 12:06:58 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/4/2018 12:06:58 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Information	1/4/2018 12:06:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 12:06:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/4/2018 12:06:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T18:36:56.045813100Z.
Information	1/4/2018 12:06:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/4/2018 12:06:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Error	1/4/2018 12:06:57 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/4/2018 12:06:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T18:36:55.223992100Z.
Information	1/4/2018 12:06:54 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T18:36:54.827596100Z.
Information	1/4/2018 12:06:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1924675\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12684.
Warning	1/3/2018 11:31:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 9:47:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/3/2018 9:46:13 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 9:46:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 9:08:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T15:38:33.831992700Z.
Information	1/3/2018 9:08:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T15:38:33.020911600Z.
Information	1/3/2018 9:08:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1924315\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12212.
Information	1/3/2018 9:08:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T15:38:32.629872500Z.
Information	1/3/2018 9:08:36 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/3/2018 9:08:36 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/3/2018 9:08:35 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T15:38:33.831992700Z.
Information	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 9:08:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T15:38:33.020911600Z.
Information	1/3/2018 9:08:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T15:38:32.629872500Z.
Information	1/3/2018 9:08:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1924315\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12212.
Warning	1/3/2018 7:57:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 7:55:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e72e1898-f091-11e7-923e-80e860e098da
Report Status: 0"
Information	1/3/2018 6:07:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T12:36:59.746833100Z.
Information	1/3/2018 6:07:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T12:36:58.812739700Z.
Information	1/3/2018 6:07:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T12:36:58.413699800Z.
Information	1/3/2018 6:07:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923969\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12728.
Information	1/3/2018 6:07:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/3/2018 6:07:02 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/3/2018 6:07:01 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/3/2018 6:06:59 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 6:06:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 6:06:59 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T12:36:59.746833100Z.
Information	1/3/2018 6:06:59 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 6:06:59 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 6:06:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T12:36:58.812739700Z.
Information	1/3/2018 6:06:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T12:36:58.413699800Z.
Information	1/3/2018 6:06:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923969\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12728.
Warning	1/3/2018 6:06:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 5:47:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 5:45:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 5:15:57 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	1/3/2018 5:15:21 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	1/3/2018 4:32:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 3:12:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T09:41:56.093774700Z.
Information	1/3/2018 3:12:02 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T09:41:54.038774700Z.
Information	1/3/2018 3:12:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923618\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 9852.
Information	1/3/2018 3:12:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T09:41:34.428774700Z.
Information	1/3/2018 3:12:01 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/3/2018 3:12:01 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/3/2018 3:11:59 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/3/2018 3:11:56 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 3:11:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 3:11:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T09:41:56.093774700Z.
Information	1/3/2018 3:11:56 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 3:11:56 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 3:11:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T09:41:54.038774700Z.
Information	1/3/2018 3:11:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T09:41:34.428774700Z.
Information	1/3/2018 3:11:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923618\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 9852.
Information	1/3/2018 3:02:11 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\sparx systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8762.0000.
Information	1/3/2018 2:55:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fa969376-f067-11e7-923e-80e860e098da
Report Status: 0"
Warning	1/3/2018 2:46:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 1:47:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 1:45:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	1/3/2018 1:14:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 12:18:40 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8762.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!d8b368e92603 (ED)
"
Information	1/3/2018 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/3/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29145)(?)])(1 )(2 )]

"
Information	1/3/2018 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/3/2018 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 12:07:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T06:37:14.283652800Z.
Information	1/3/2018 12:07:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T06:37:12.909790200Z.
Information	1/3/2018 12:07:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923275\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 1148.
Information	1/3/2018 12:07:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2018‎-‎01‎-‎03T06:37:11.570924100Z.
Information	1/3/2018 12:07:16 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	1/3/2018 12:07:16 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	1/3/2018 12:07:15 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	1/3/2018 12:07:14 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 12:07:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 12:07:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T06:37:14.283652800Z.
Information	1/3/2018 12:07:14 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	1/3/2018 12:07:14 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 12900) cannot be restarted - Application SID does not match Conductor SID..
Information	1/3/2018 12:07:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T06:37:12.909790200Z.
Information	1/3/2018 12:07:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2018‎-‎01‎-‎03T06:37:11.570924100Z.
Information	1/3/2018 12:07:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1923275\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 1148.
Information	1/3/2018 11:37:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/3/2018 11:34:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	1/3/2018 11:34:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 11:32:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/3/2018 11:32:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29181)(?)])(1 )(2 )]

"
Information	1/3/2018 11:32:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29181)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 11:32:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/3/2018 11:32:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 11:32:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 11:05:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 11:00:48 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29214)(?)])(1 )(2 )]

"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29214)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/3/2018 11:00:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 11:00:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 10:55:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 10:55:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:58Z. Reason: GVLK.
Information	1/3/2018 10:50:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/3/2018 10:50:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 10:50:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 10:50:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 10:50:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd025992-f045-11e7-923e-80e860e098da
Report Status: 0"
Information	1/3/2018 10:50:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd025991-f045-11e7-923e-80e860e098da
Report Status: 0"
Information	1/3/2018 10:50:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd025990-f045-11e7-923e-80e860e098da
Report Status: 0"
Error	1/3/2018 10:44:31 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	1/3/2018 10:39:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 10:37:55 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5632.
Information	1/3/2018 10:37:55 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/3/2018 10:37:55 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	1/3/2018 10:37:49 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5632.
Information	1/3/2018 10:37:48 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5632.
Information	1/3/2018 10:37:48 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	1/3/2018 10:37:48 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	1/3/2018 10:37:08 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	1/3/2018 10:36:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5632.
Information	1/3/2018 10:36:00 AM	ESENT	102	General	Windows (2580) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	1/3/2018 10:35:57 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	1/3/2018 10:35:57 AM	ESENT	103	General	Windows (2172) Windows: The database engine stopped the instance (0).
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:43 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:42 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:42 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	1/3/2018 10:35:42 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:42 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:35:42 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	1/3/2018 10:34:47 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	1/3/2018 10:34:46 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	1/3/2018 10:34:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/3/2018 10:34:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 10:34:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 10:33:35 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2018‎-‎01‎-‎03T05:03:35.771994700Z.
Error	1/3/2018 10:22:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/3/2018 10:10:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 10:10:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:22:38Z. Reason: GVLK.
Information	1/3/2018 10:05:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/3/2018 10:05:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 10:05:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 10:05:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 9:58:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	1/3/2018 9:58:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2018-01-10T04:23:27Z. Reason: GVLK.
Information	1/3/2018 9:55:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0fe3283d-f03e-11e7-923e-80e860e098da
Report Status: 0"
Information	1/3/2018 9:53:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 9:53:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 9:53:27 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2018/01/03 04:23"
Information	1/3/2018 9:53:21 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2018/01/03 04:23, 0, 1, 237780, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	1/3/2018 9:51:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	1/3/2018 9:51:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	1/3/2018 9:50:46 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	1/3/2018 9:49:38 AM	McLogEvent	257	None	The scan of D:\R1.2_SetUpFile_2017_12_16_Sa_ 1_37_43_154\DISK1\ISSetupPrerequisites\{39B44035-64F8-485C-902E-7A79A185BE70}\postgresql-9.5.3-1-windows-x64.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8750.0000.
Information	1/3/2018 9:48:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	1/3/2018 9:48:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 237780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 9:48:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 9:47:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	1/3/2018 9:47:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	1/3/2018 9:47:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 9:47:17 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	1/3/2018 9:47:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/3/2018 9:47:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	1/3/2018 9:47:08 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	1/3/2018 9:46:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e802c03b-f03c-11e7-923e-80e860e098da
Report Status: 0"
Information	1/3/2018 9:45:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	1/3/2018 9:45:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29288)(?)])(1 )(2 )]

"
Information	1/3/2018 9:45:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 29288)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	1/3/2018 9:45:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	1/3/2018 9:45:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	1/3/2018 9:45:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	1/3/2018 9:45:52 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 17, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/3/2018 9:45:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	1/3/2018 9:45:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	1/3/2018 9:45:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	1/3/2018 9:45:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 18150, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	1/3/2018 9:44:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	1/3/2018 9:44:49 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/20/2017 6:08:07 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T12:38:04.806511900Z.
Information	12/20/2017 6:08:07 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T12:38:03.747406000Z.
Information	12/20/2017 6:08:07 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T12:38:03.333364600Z.
Information	12/20/2017 6:08:07 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1886301\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 7300.
Information	12/20/2017 6:08:07 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	12/20/2017 6:08:07 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	12/20/2017 6:08:06 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	12/20/2017 6:08:04 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 6:08:04 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 6:08:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T12:38:04.806511900Z.
Information	12/20/2017 6:08:04 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 6:08:04 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 6:08:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T12:38:03.747406000Z.
Information	12/20/2017 6:08:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T12:38:03.333364600Z.
Information	12/20/2017 6:08:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1886301\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 7300.
Information	12/20/2017 5:20:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee16d4ae-e57b-11e7-923e-204747d02364
Report Status: 0"
Warning	12/20/2017 5:05:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 3:39:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/20/2017 3:34:00 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 4, Deleted: 0, Modified: 0, Compared: 18140, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	12/20/2017 3:32:55 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/20/2017 3:07:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T09:37:22.971437700Z.
Information	12/20/2017 3:07:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T09:37:21.889329500Z.
Information	12/20/2017 3:07:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T09:37:21.024243000Z.
Information	12/20/2017 3:07:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885954\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12236.
Information	12/20/2017 3:07:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	12/20/2017 3:07:25 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	12/20/2017 3:07:24 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	12/20/2017 3:07:22 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 3:07:22 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 3:07:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T09:37:22.971437700Z.
Information	12/20/2017 3:07:22 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 3:07:22 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 3:07:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T09:37:21.889329500Z.
Information	12/20/2017 3:07:21 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T09:37:21.024243000Z.
Information	12/20/2017 3:07:19 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885954\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 12236.
Warning	12/20/2017 3:06:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 2:11:52 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	12/20/2017 2:11:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/20/2017 2:03:27 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	12/20/2017 1:34:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 12:46:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8750.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!d8b368e92603 (ED)
"
Information	12/20/2017 12:20:09 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 045fb08d-e552-11e7-923e-204747d02364
Report Status: 0"
Information	12/20/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/20/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49305)(?)])(1 )(2 )]

"
Information	12/20/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 49305)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/20/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 12:07:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T06:37:50.370628300Z.
Information	12/20/2017 12:07:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T06:37:49.583101100Z.
Information	12/20/2017 12:07:52 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T06:37:49.190336900Z.
Information	12/20/2017 12:07:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885609\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8832.
Information	12/20/2017 12:07:52 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	12/20/2017 12:07:52 PM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	12/20/2017 12:07:51 PM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	12/20/2017 12:07:50 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 12:07:50 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 12:07:50 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T06:37:50.370628300Z.
Information	12/20/2017 12:07:50 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 12:07:50 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 12:07:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T06:37:49.583101100Z.
Information	12/20/2017 12:07:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T06:37:49.190336900Z.
Information	12/20/2017 12:07:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885609\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 8832.
Information	12/20/2017 12:07:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/20/2017 11:52:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 11:39:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/20/2017 10:00:28 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 9:18:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 9:18:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:32:22Z. Reason: GVLK.
Information	12/20/2017 9:13:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/20/2017 9:13:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 9:13:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 9:13:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 9:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T03:36:56.731970800Z.
Information	12/20/2017 9:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T03:36:55.907970800Z.
Information	12/20/2017 9:06:59 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T03:36:55.510970800Z.
Information	12/20/2017 9:06:59 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885268\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11568.
Information	12/20/2017 9:06:59 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	12/20/2017 9:06:59 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Information	12/20/2017 9:06:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 9:06:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 9:06:56 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T03:36:56.731970800Z.
Information	12/20/2017 9:06:56 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 9:06:56 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Error	12/20/2017 9:06:58 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	12/20/2017 9:06:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T03:36:55.907970800Z.
Information	12/20/2017 9:06:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T03:36:55.510970800Z.
Information	12/20/2017 9:06:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1885268\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 11568.
Information	12/20/2017 8:30:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 8:30:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:31:59Z. Reason: GVLK.
Warning	12/20/2017 8:27:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 8:24:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/20/2017 8:24:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 8:24:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 8:24:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 7:38:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/20/2017 7:20:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ad4bc5d-e528-11e7-923e-204747d02364
Report Status: 0"
Information	12/20/2017 6:48:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 6:48:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:32:46Z. Reason: GVLK.
Warning	12/20/2017 6:46:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 6:43:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/20/2017 6:43:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 6:43:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 6:43:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 6:13:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T00:43:31.574549000Z.
Information	12/20/2017 6:13:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T00:43:30.579449500Z.
Information	12/20/2017 6:13:34 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎20T00:43:29.052296800Z.
Information	12/20/2017 6:13:34 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1884918\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 7764.
Information	12/20/2017 6:13:34 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Google Chrome. Product Version: 67.41.49260. Product Language: 1033. Manufacturer: Google, Inc.. Installation success or error status: 1603.
Information	12/20/2017 6:13:34 AM	MsiInstaller	11708	None	Product: Google Chrome -- Installation failed.
Error	12/20/2017 6:13:32 AM	MsiInstaller	11306	None	Product: Google Chrome -- Error 1306. Another application has exclusive access to the file 'C:\Users\212558710\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal'.  Please shut down all other applications, then click Retry.
Information	12/20/2017 6:13:31 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 6:13:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 6:13:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T00:43:31.574549000Z.
Information	12/20/2017 6:13:31 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/20/2017 6:13:31 AM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe' (pid 5444) cannot be restarted - Application SID does not match Conductor SID..
Information	12/20/2017 6:13:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T00:43:30.579449500Z.
Information	12/20/2017 6:13:29 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎20T00:43:29.052296800Z.
Information	12/20/2017 6:13:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Tanium\Tanium Client\Downloads\Action_1884918\GoogleChromeStandaloneEnterprise.msi. Client Process Id: 7764.
Warning	12/20/2017 4:49:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 4:04:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 4:04:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:32:40Z. Reason: GVLK.
Information	12/20/2017 3:59:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/20/2017 3:59:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 3:59:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 3:59:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 3:59:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0858182e-e50c-11e7-923e-204747d02364
Report Status: 0"
Information	12/20/2017 3:59:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0858182d-e50c-11e7-923e-204747d02364
Report Status: 0"
Information	12/20/2017 3:59:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0858182c-e50c-11e7-923e-204747d02364
Report Status: 0"
Error	12/20/2017 3:56:04 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/20/2017 3:38:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/20/2017 3:33:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/20/2017 3:32:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/20/2017 3:32:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:31:59Z. Reason: GVLK.
Error	12/20/2017 3:29:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/20/2017 3:28:49 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8749.0000.
Information	12/20/2017 3:26:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/20/2017 3:26:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/20/2017 3:26:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/20/2017 3:26:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/20/2017 3:11:28 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	12/20/2017 2:59:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 2:20:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 312f9c10-e4fe-11e7-923e-204747d02364
Report Status: 0"
Warning	12/20/2017 1:16:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/20/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/19/2017 11:38:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/19/2017 11:31:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/19/2017 9:54:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/19/2017 9:20:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 477bdd0e-e4d4-11e7-923e-204747d02364
Report Status: 0"
Information	12/19/2017 8:05:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8749.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!d8b368e92603 (ED)
"
Warning	12/19/2017 7:59:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/19/2017 7:38:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/19/2017 6:18:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/19/2017 5:19:27 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/19/2017 4:32:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/19/2017 4:20:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5dca2ffd-e4aa-11e7-923e-204747d02364
Report Status: 0"
Information	12/19/2017 3:37:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/19/2017 2:32:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/19/2017 1:01:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/19/2017 12:37:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 12:37:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:32:24Z. Reason: GVLK.
Information	12/19/2017 12:32:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/19/2017 12:32:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 12:32:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 12:32:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/19/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50745)(?)])(1 )(2 )]

"
Information	12/19/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50745)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/19/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 12:07:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 12:07:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T06:31:55Z. Reason: GVLK.
Information	12/19/2017 12:04:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8749.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/19/2017 12:02:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 12:02:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 12:02:54 PM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/12/19 06:32"
Information	12/19/2017 12:02:53 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/12/19 06:32, 0, 1, 249060, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/19/2017 11:57:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/19/2017 11:57:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:57:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:57:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 11:57:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5f47cf2-e485-11e7-923e-204747d02364
Report Status: 0"
Information	12/19/2017 11:57:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5f47cf1-e485-11e7-923e-204747d02364
Report Status: 0"
Information	12/19/2017 11:57:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a5f47cf0-e485-11e7-923e-204747d02364
Report Status: 0"
Error	12/19/2017 11:52:34 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/19/2017 11:42:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 11:37:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/19/2017 11:37:37 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Information	12/19/2017 11:37:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/19/2017 11:37:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50777)(?)])(1 )(2 )]

"
Information	12/19/2017 11:37:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50777)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:34:43 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2213.
Information	12/19/2017 11:34:40 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 46

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 140

Information	12/19/2017 11:34:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/19/2017 11:33:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	12/19/2017 11:33:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/19/2017 11:33:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50781)(?)])(1 )(2 )]

"
Information	12/19/2017 11:33:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50781)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:32:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/19/2017 11:32:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:32:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 11:31:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 11:30:14 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8748.0000.
Information	12/19/2017 11:27:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 11:27:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-26T05:51:02Z. Reason: GVLK.
Information	12/19/2017 11:26:47 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:47 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/19/2017 11:26:47 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	12/19/2017 11:26:46 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/19/2017 11:26:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 50788)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:26:44 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/19/2017 11:26:43 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/19/2017 11:26:43 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:26:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/19/2017 11:26:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:26:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 11:26:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/19/2017 11:26:24 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:23 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:23 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/19/2017 11:26:23 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	12/19/2017 11:26:22 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:22 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:22 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/19/2017 11:26:22 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	12/19/2017 11:26:20 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/19/2017 11:26:19 AM	ESENT	102	General	Windows (2172) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/19/2017 11:26:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:19 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:26:19 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/19/2017 11:26:19 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	12/19/2017 11:25:56 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:25:53 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/19/2017 11:25:53 AM	ESENT	103	General	Windows (6460) Windows: The database engine stopped the instance (0).
Information	12/19/2017 11:25:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:25:53 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2213. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/19/2017 11:25:53 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	12/19/2017 11:24:49 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9032.
Information	12/19/2017 11:23:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/19/2017 11:23:49 AM	ESENT	102	General	Windows (6460) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/19/2017 11:23:46 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/19/2017 11:23:46 AM	ESENT	103	General	Windows (7188) Windows: The database engine stopped the instance (0).
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:45 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:44 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:44 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/19/2017 11:23:44 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:44 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:23:44 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	12/19/2017 11:22:44 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	12/19/2017 11:22:43 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	12/19/2017 11:22:42 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	12/19/2017 11:22:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/19/2017 11:22:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:22:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	12/19/2017 11:22:33 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/19/2017 11:22:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:22:02 AM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	12/19/2017 11:22:02 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/12/19 05:52, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/19/2017 11:21:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎19T05:51:53.380594200Z.
Error	12/19/2017 11:19:59 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/19/2017 11:19:05 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	12/19/2017 11:18:53 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/19/2017 11:18:27 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/19/2017 11:18:25 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/19/2017 11:18:23 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/19/2017 11:18:18 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/19/2017 11:17:23 AM	ESENT	302	Logging/Recovery	Windows (7188) Windows: The database engine has successfully completed recovery steps.
Information	12/19/2017 11:17:22 AM	ESENT	301	Logging/Recovery	Windows (7188) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/19/2017 11:17:15 AM	ESENT	301	Logging/Recovery	Windows (7188) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05726.log.
Information	12/19/2017 11:17:15 AM	ESENT	300	Logging/Recovery	Windows (7188) Windows: The database engine is initiating recovery steps.
Information	12/19/2017 11:17:14 AM	ESENT	102	General	Windows (7188) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/19/2017 11:17:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/19/2017 11:17:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/19/2017 11:17:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/19/2017 11:16:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/19/2017 11:16:51 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8748.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/19/2017 11:16:36 AM	Service1	0	None	Service started successfully.
Error	12/19/2017 11:16:32 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/19/2017 11:16:32 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/19/2017 11:16:30 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	12/19/2017 11:16:29 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/19/2017 11:16:27 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/19/2017 11:16:22 AM	PostgreSQL	0	None	"2017-12-19 11:16:22 IST LOG:  redirecting log output to logging collector process
2017-12-19 11:16:22 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/19/2017 11:16:19 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/19/2017 11:16:17 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/19/2017 11:16:13 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/19/2017 11:16:13 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/19/2017 11:16:13 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/19/2017 11:16:13 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/19/2017 11:16:13 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/19/2017 11:16:08 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/19/2017 11:16:07 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:07 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/19/2017 11:16:05 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/19/2017 11:16:03 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:03 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:03 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/19/2017 11:16:02 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3396 at 12/14/2017 7:20:20 PM (local) 12/14/2017 1:50:20 PM (UTC). This is an informational message only; no user action is required.
Information	12/19/2017 11:16:00 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/19/2017 11:16:00 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/19/2017 11:16:00 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/19/2017 11:16:00 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/19/2017 11:16:00 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3824.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/19/2017 11:15:59 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/19/2017 11:15:18 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/19/2017 11:15:11 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/19/2017 11:14:59 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/19/2017 11:14:59 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/19/2017 11:14:59 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/18/2017 7:27:19 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/18/2017 7:26:56 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/18/2017 7:22:23 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/18/2017 7:05:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎18T13:34:01.309466400Z.
Information	12/18/2017 7:05:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 16832.
Information	12/18/2017 7:05:34 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.154. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/18/2017 7:05:34 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	12/18/2017 7:04:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎18T13:34:01.309466400Z.
Information	12/18/2017 7:03:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 16832.
Warning	12/18/2017 7:02:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 6:46:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97606457-e3f5-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/18/2017 6:12:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8748.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/18/2017 6:08:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/18/2017 6:08:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:33Z. Reason: GVLK.
Information	12/18/2017 6:03:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/18/2017 6:03:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/18/2017 6:03:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/18/2017 6:03:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/18/2017 5:16:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 4:40:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 4:40:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 4:40:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/18/2017 4:40:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 3:30:29 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/18/2017 3:30:29 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/18/2017 3:30:13 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/18/2017 3:30:10 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	12/18/2017 3:29:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 2:55:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/18/2017 2:55:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:26Z. Reason: GVLK.
Information	12/18/2017 2:50:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/18/2017 2:50:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/18/2017 2:50:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/18/2017 2:50:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	12/18/2017 2:36:37 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/18/2017 1:55:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 1:45:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad9ac904-e3cb-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/18/2017 12:40:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 12:40:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 12:14:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/18/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/18/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52185)(?)])(1 )(2 )]

"
Information	12/18/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 52185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/18/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/18/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/18/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/18/2017 12:04:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 11:59:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/18/2017 11:58:55 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	12/18/2017 10:11:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 8:45:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c33a479c-e3a1-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/18/2017 8:40:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 8:40:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/18/2017 8:16:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/18/2017 6:36:27 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 5:16:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/18/2017 5:16:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:42Z. Reason: GVLK.
Information	12/18/2017 5:11:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/18/2017 5:11:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/18/2017 5:11:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/18/2017 5:11:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/18/2017 5:10:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b9f0ca6e-e383-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/18/2017 5:10:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b9f0ca6d-e383-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/18/2017 5:10:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b9f0ca6c-e383-11e7-8c2e-0205857feb80
Report Status: 0"
Error	12/18/2017 5:06:28 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/18/2017 4:59:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/18/2017 4:59:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:14Z. Reason: GVLK.
Warning	12/18/2017 4:55:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/18/2017 4:54:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/18/2017 4:54:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/18/2017 4:54:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/18/2017 4:54:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/18/2017 4:54:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/18/2017 4:40:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 4:40:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 4:40:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 3:45:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9885e8c-e377-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/18/2017 3:07:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/18/2017 1:23:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/18/2017 12:40:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 12:40:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/18/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/17/2017 11:25:21 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 11:16:23 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/17/2017 10:45:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eff12176-e34d-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/17/2017 9:49:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 9:30:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/17/2017 9:30:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:53Z. Reason: GVLK.
Information	12/17/2017 9:25:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/17/2017 9:25:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/17/2017 9:25:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/17/2017 9:25:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/17/2017 8:40:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/17/2017 8:40:21 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/17/2017 8:39:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/17/2017 7:53:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/17/2017 6:04:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 5:45:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 06498687-e324-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/17/2017 4:39:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/17/2017 4:21:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 3:31:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 9, Compared: 17929, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/17/2017 3:30:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	12/17/2017 2:45:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/17/2017 2:36:30 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/17/2017 12:56:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 12:45:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1c96750c-e2fa-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/17/2017 12:43:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8747.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/17/2017 12:39:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/17/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/17/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53625)(?)])(1 )(2 )]

"
Information	12/17/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 53625)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/17/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/17/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/17/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/17/2017 11:19:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/17/2017 9:27:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 8:54:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/17/2017 8:54:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:40Z. Reason: GVLK.
Information	12/17/2017 8:49:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/17/2017 8:49:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/17/2017 8:49:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/17/2017 8:49:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/17/2017 8:39:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/17/2017 8:39:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/17/2017 7:45:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072efd
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 322c2175-e2d0-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/17/2017 7:45:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 5:52:55 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎12‎-‎17T00:22:55.467893000Z.
Information	12/17/2017 5:51:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/17/2017 5:46:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/17/2017 5:46:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/17/2017 5:46:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/17/2017 5:46:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 4:48:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74748a95-e2b7-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/17/2017 4:39:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/17/2017 3:50:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/17/2017 2:06:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/17/2017 12:44:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/17/2017 12:44:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:04Z. Reason: GVLK.
Information	12/17/2017 12:39:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/17/2017 12:39:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/17/2017 12:39:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/17/2017 12:39:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/17/2017 12:39:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/17/2017 12:35:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 11:48:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8a886503-e28d-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/16/2017 10:41:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/16/2017 8:46:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 8:39:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/16/2017 7:26:32 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/16/2017 7:15:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 6:48:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0c083d0-e263-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/16/2017 5:36:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 4:38:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/16/2017 4:37:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 4:32:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/16/2017 4:32:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54802)(?)])(1 )(2 )]

"
Information	12/16/2017 4:32:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54802)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 4:32:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/16/2017 4:32:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 4:32:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 4:30:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 4:24:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/16/2017 4:24:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 4:24:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/16/2017 3:41:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 3:30:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 3:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/16/2017 3:25:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54869)(?)])(1 )(2 )]

"
Information	12/16/2017 3:25:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 54869)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 3:25:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/16/2017 3:25:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 3:25:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 3:16:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 3:11:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/16/2017 3:11:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 3:11:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	12/16/2017 2:36:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/16/2017 2:33:14 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/16/2017 1:53:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 1:48:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b71fb397-e239-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/16/2017 12:45:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8746.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/16/2017 12:38:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/16/2017 12:38:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/16/2017 12:17:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/16/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55065)(?)])(1 )(2 )]

"
Information	12/16/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 55065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/16/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 11:47:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 11:47:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:40Z. Reason: GVLK.
Information	12/16/2017 11:42:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/16/2017 11:42:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 11:42:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 11:42:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 10:45:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 10:45:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:30Z. Reason: GVLK.
Information	12/16/2017 10:40:30 AM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	12/16/2017 10:40:30 AM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	12/16/2017 10:40:30 AM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	12/16/2017 10:40:30 AM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	12/16/2017 10:40:30 AM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	12/16/2017 10:40:29 AM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	12/16/2017 10:40:27 AM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	12/16/2017 10:40:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/16/2017 10:40:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 10:40:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 10:40:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 10:40:25 AM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Warning	12/16/2017 10:33:10 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 9:31:12 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.154. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/16/2017 9:31:12 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	12/16/2017 9:30:55 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎16T03:57:31.530254000Z.
Information	12/16/2017 9:30:55 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D1A84565-440A-46AD-B197-34B31A5DB8B1}\4Sight™ 2.msi. Client Process Id: 13072.
Information	12/16/2017 9:27:31 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎16T03:57:31.530254000Z.
Information	12/16/2017 9:27:22 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{D1A84565-440A-46AD-B197-34B31A5DB8B1}\4Sight™ 2.msi. Client Process Id: 13072.
Information	12/16/2017 9:27:04 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/16/2017 9:27:03 AM	PostgreSQL	0	None	"2017-12-16 09:27:03 IST LOG:  redirecting log output to logging collector process
2017-12-16 09:27:03 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/16/2017 9:27:03 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/16/2017 9:13:18 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.154. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	12/16/2017 9:13:18 AM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	12/16/2017 9:04:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 9:04:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:19Z. Reason: GVLK.
Information	12/16/2017 8:59:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/16/2017 8:59:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 8:59:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 8:59:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 8:58:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d12f481-e211-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/16/2017 8:58:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d12f480-e211-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/16/2017 8:58:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3d12f47f-e211-11e7-8c2e-0205857feb80
Report Status: 0"
Error	12/16/2017 8:56:13 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/16/2017 8:55:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 8:55:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:29Z. Reason: GVLK.
Information	12/16/2017 8:50:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/16/2017 8:50:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 8:50:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 8:50:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/16/2017 8:48:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccae197e-e20f-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/16/2017 8:46:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/16/2017 8:46:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:31Z. Reason: GVLK.
Error	12/16/2017 8:42:01 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/16/2017 8:41:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/16/2017 8:41:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/16/2017 8:41:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/16/2017 8:41:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/16/2017 8:39:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/16/2017 8:38:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	12/15/2017 10:36:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 9:13:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T15:42:15.020070800Z.
Information	12/15/2017 9:13:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9184.
Information	12/15/2017 9:13:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.152. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/15/2017 9:13:38 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	12/15/2017 9:12:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T15:42:15.020070800Z.
Information	12/15/2017 9:11:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9184.
Warning	12/15/2017 8:56:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 7:35:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/15/2017 7:35:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/15/2017 7:22:43 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/15/2017 7:22:13 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/15/2017 7:22:13 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	12/15/2017 7:02:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 6:53:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.152. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/15/2017 6:53:25 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	12/15/2017 6:50:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T13:16:09.981806800Z.
Information	12/15/2017 6:50:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{7A1A989B-AD07-4021-A1F6-C70BA470C082}\4Sight™ 2.msi. Client Process Id: 11000.
Information	12/15/2017 6:46:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T13:16:09.981806800Z.
Information	12/15/2017 6:46:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{7A1A989B-AD07-4021-A1F6-C70BA470C082}\4Sight™ 2.msi. Client Process Id: 11000.
Information	12/15/2017 6:41:36 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.2.0.152. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	12/15/2017 6:41:36 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	12/15/2017 6:41:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T13:08:51.542967300Z.
Information	12/15/2017 6:41:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{93906EC1-79B2-4537-AFA3-1BF691850E22}\4Sight™ 2.msi. Client Process Id: 11212.
Information	12/15/2017 6:38:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T13:08:51.542967300Z.
Information	12/15/2017 6:38:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{93906EC1-79B2-4537-AFA3-1BF691850E22}\4Sight™ 2.msi. Client Process Id: 11212.
Information	12/15/2017 6:20:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b3a9142-e196-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/15/2017 5:04:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 4:08:43 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/15/2017 4:08:41 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/15/2017 3:40:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 3:35:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/15/2017 3:35:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/15/2017 3:35:20 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/15/2017 3:35:14 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 47

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 109

Information	12/15/2017 3:35:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/15/2017 3:34:40 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	12/15/2017 3:34:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/15/2017 3:34:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56300)(?)])(1 )(2 )]

"
Information	12/15/2017 3:34:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/15/2017 3:34:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/15/2017 3:34:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 3:34:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/15/2017 3:19:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 2:59:07 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/15/2017 2:59:07 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	12/15/2017 2:58:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T09:27:58.462666900Z.
Information	12/15/2017 2:58:22 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{378D685B-CC86-4AA4-9D56-0BF32165A707}\DeviceManager.msi. Client Process Id: 5040.
Information	12/15/2017 2:57:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T09:27:58.462666900Z.
Information	12/15/2017 2:57:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{378D685B-CC86-4AA4-9D56-0BF32165A707}\DeviceManager.msi. Client Process Id: 5040.
Information	12/15/2017 2:57:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 2:56:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T09:25:53.348179600Z.
Information	12/15/2017 2:56:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{378D685B-CC86-4AA4-9D56-0BF32165A707}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 10316.
Information	12/15/2017 2:56:01 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/15/2017 2:56:01 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	12/15/2017 2:55:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T09:25:53.348179600Z.
Information	12/15/2017 2:55:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{378D685B-CC86-4AA4-9D56-0BF32165A707}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 10316.
Information	12/15/2017 2:54:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T09:24:32.117303500Z.
Information	12/15/2017 2:54:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 9184.
Information	12/15/2017 2:54:40 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/15/2017 2:54:40 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	12/15/2017 2:54:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T09:24:32.117303500Z.
Information	12/15/2017 2:54:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 9184.
Information	12/15/2017 2:54:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎15T09:23:57.794736100Z.
Information	12/15/2017 2:54:22 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 9184.
Information	12/15/2017 2:54:22 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/15/2017 2:54:22 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	12/15/2017 2:53:57 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎15T09:23:57.794736100Z.
Information	12/15/2017 2:53:55 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 9184.
Information	12/15/2017 2:52:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/15/2017 2:52:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 2:52:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/15/2017 2:51:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 518c27cd-e179-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/15/2017 2:48:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df850ae4-e178-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/15/2017 2:48:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df850ae3-e178-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/15/2017 2:48:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df850ae2-e178-11e7-8c2e-0205857feb80
Report Status: 0"
Error	12/15/2017 2:36:14 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/15/2017 1:58:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 1:58:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:22Z. Reason: GVLK.
Information	12/15/2017 1:53:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/15/2017 1:53:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/15/2017 1:53:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 1:53:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/15/2017 1:20:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a197da85-e16c-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/15/2017 1:20:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 12:53:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8745.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/15/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/15/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56505)(?)])(1 )(2 )]

"
Information	12/15/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 56505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/15/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/15/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/15/2017 11:32:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/15/2017 9:42:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 8:20:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6b84926-e142-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/15/2017 7:54:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/15/2017 6:09:44 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 4:37:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 4:32:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/15/2017 4:32:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 4:32:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/15/2017 4:30:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 4:30:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:17Z. Reason: GVLK.
Information	12/15/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/15/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/15/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/15/2017 4:24:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c8640001-e121-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/15/2017 4:24:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c8640000-e121-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/15/2017 4:24:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c863ffff-e121-11e7-8c2e-0205857feb80
Report Status: 0"
Error	12/15/2017 4:21:05 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	12/15/2017 4:17:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 4:09:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/15/2017 4:09:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:49Z. Reason: GVLK.
Error	12/15/2017 4:05:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/15/2017 4:04:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/15/2017 4:04:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/15/2017 4:04:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/15/2017 4:04:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/15/2017 3:20:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ccab1bab-e118-11e7-8c2e-0205857feb80
Report Status: 0"
Warning	12/15/2017 2:18:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/15/2017 12:19:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/15/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 10:46:44 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Warning	12/14/2017 10:44:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2017 10:44:05 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	12/14/2017 10:20:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e2c5d652-e0ee-11e7-8c2e-0205857feb80
Report Status: 0"
Information	12/14/2017 10:02:37 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 9:07:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 9:07:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:45Z. Reason: GVLK.
Warning	12/14/2017 9:01:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2017 8:57:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 8:57:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 8:57:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 8:57:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 8:43:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 8:38:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 8:38:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 8:38:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 8:13:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 8:08:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 8:08:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 8:08:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 7:43:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 7:38:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 7:38:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 7:38:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 7:29:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 7:29:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:28Z. Reason: GVLK.
Information	12/14/2017 7:29:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	12/14/2017 7:27:37 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/14/2017 7:24:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/14/2017 7:24:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2017 7:24:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57510)(?)])(1 )(2 )]

"
Information	12/14/2017 7:24:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57510)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 7:24:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 7:24:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 7:24:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 7:23:39 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/14/2017 7:23:18 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 7:23:16 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 7:23:13 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 7:22:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/14/2017 7:22:56 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/14/2017 7:22:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/14/2017 7:22:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	12/14/2017 7:22:48 PM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 70 second(s) to handle the notification event (CreateSession).
Warning	12/14/2017 7:22:38 PM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	12/14/2017 7:21:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 7:21:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 7:21:37 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	12/14/2017 7:21:37 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	12/14/2017 7:21:36 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/14/2017 7:21:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 7:21:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 7:21:11 PM	ESENT	302	Logging/Recovery	Windows (6792) Windows: The database engine has successfully completed recovery steps.
Information	12/14/2017 7:21:08 PM	ESENT	301	Logging/Recovery	Windows (6792) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/14/2017 7:21:08 PM	ESENT	300	Logging/Recovery	Windows (6792) Windows: The database engine is initiating recovery steps.
Information	12/14/2017 7:21:08 PM	ESENT	102	General	Windows (6792) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/14/2017 7:20:58 PM	Service1	0	None	Service started successfully.
Error	12/14/2017 7:20:51 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/14/2017 7:20:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8744.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/14/2017 7:20:49 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/14/2017 7:20:49 PM	PostgreSQL	0	None	Server started and accepting connections

Information	12/14/2017 7:20:35 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	12/14/2017 7:20:34 PM	PostgreSQL	0	None	"2017-12-14 19:20:34 IST LOG:  redirecting log output to logging collector process
2017-12-14 19:20:34 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/14/2017 7:20:34 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/14/2017 7:20:33 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/14/2017 7:20:33 PM	PostgreSQL	0	None	Waiting for server startup...

Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/14/2017 7:20:28 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/14/2017 7:20:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/14/2017 7:20:26 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:26 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/14/2017 7:20:26 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/14/2017 7:20:26 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/14/2017 7:20:25 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/14/2017 7:20:21 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:21 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:21 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3660 at 12/14/2017 2:09:16 PM (local) 12/14/2017 8:39:16 AM (UTC). This is an informational message only; no user action is required.
Information	12/14/2017 7:20:20 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/14/2017 7:20:17 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/14/2017 7:20:17 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/14/2017 7:20:17 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/14/2017 7:20:17 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/14/2017 7:20:17 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3396.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/14/2017 7:20:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/14/2017 7:19:54 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/14/2017 7:19:48 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 7:18:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/14/2017 7:18:24 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/14/2017 7:18:00 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/14/2017 6:46:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 6:46:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:51Z. Reason: GVLK.
Information	12/14/2017 6:45:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d35b374f-e0d0-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 6:41:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 6:41:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 6:41:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 6:41:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 6:41:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 47cd968f-e0d0-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 6:36:06 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/14/2017 6:36:06 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/14/2017 6:29:30 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	12/14/2017 6:29:30 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	12/14/2017 6:17:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ebccba18-e0cc-11e7-8cde-0205857feb80
Report Status: 0"
Warning	12/14/2017 5:23:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2017 5:20:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f64468f3-e0c4-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 4:34:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cb2a5c6-e0be-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 4:34:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9cb2a5c5-e0be-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 4:08:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 4:05:15 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 72, Deleted: 0, Modified: 2, Compared: 16816, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/14/2017 4:03:32 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/14/2017 4:03:27 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 343

Information	12/14/2017 4:03:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/14/2017 4:02:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2017 4:02:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57711)(?)])(1 )(2 )]

"
Information	12/14/2017 4:02:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57711)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 4:02:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 4:02:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 4:02:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/14/2017 3:44:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2017 3:39:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 3:39:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:03Z. Reason: GVLK.
Information	12/14/2017 3:34:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 3:34:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 3:34:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 3:34:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 3:33:50 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 3:30:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 3:25:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 3:25:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 3:25:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 3:24:26 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 3:17:07 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 3:15:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 3:15:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:27Z. Reason: GVLK.
Information	12/14/2017 3:10:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 3:10:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 3:10:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 3:10:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 3:04:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 3:04:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:56Z. Reason: GVLK.
Information	12/14/2017 3:00:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:59:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 2:59:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 2:59:53 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	12/14/2017 2:59:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:59:51 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/14/2017 2:59:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:58:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:58:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:40Z. Reason: GVLK.
Information	12/14/2017 2:55:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 2:55:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:55:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:53:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 2:53:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 2:53:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:53:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:43:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:43:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:55Z. Reason: GVLK.
Information	12/14/2017 2:38:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 2:38:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 2:38:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:38:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:38:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c51b477-e0ae-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 2:38:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c51b476-e0ae-11e7-8cde-0205857feb80
Report Status: 0"
Information	12/14/2017 2:38:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c51b475-e0ae-11e7-8cde-0205857feb80
Report Status: 0"
Error	12/14/2017 2:36:07 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/14/2017 2:34:10 PM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/14/2017 2:30:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:25:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 2:25:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:25:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:24:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:24:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:33Z. Reason: GVLK.
Error	12/14/2017 2:18:59 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/14/2017 2:16:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 2:12:47 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	12/14/2017 2:11:45 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/14/2017 2:11:42 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 2:11:40 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 2:11:39 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 2:11:37 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/14/2017 2:10:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 2:10:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 2:10:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:10:56 PM	ESENT	302	Logging/Recovery	Windows (7428) Windows: The database engine has successfully completed recovery steps.
Information	12/14/2017 2:10:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2017 2:10:55 PM	ESENT	301	Logging/Recovery	Windows (7428) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/14/2017 2:10:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57823)(?)])(1 )(2 )]

"
Information	12/14/2017 2:10:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57823)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 2:10:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 2:10:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 2:10:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:10:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 2:10:50 PM	ESENT	301	Logging/Recovery	Windows (7428) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05700.log.
Information	12/14/2017 2:10:50 PM	ESENT	300	Logging/Recovery	Windows (7428) Windows: The database engine is initiating recovery steps.
Information	12/14/2017 2:10:49 PM	ESENT	102	General	Windows (7428) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/14/2017 2:10:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8744.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/14/2017 2:09:53 PM	Service1	0	None	Service started successfully.
Error	12/14/2017 2:09:45 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/14/2017 2:09:45 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/14/2017 2:09:38 PM	PostgreSQL	0	None	Server started and accepting connections

Information	12/14/2017 2:09:32 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	12/14/2017 2:09:31 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/14/2017 2:09:30 PM	PostgreSQL	0	None	"2017-12-14 14:09:30 IST LOG:  redirecting log output to logging collector process
2017-12-14 14:09:30 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/14/2017 2:09:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/14/2017 2:09:27 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/14/2017 2:09:27 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/14/2017 2:09:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/14/2017 2:09:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/14/2017 2:09:27 PM	PostgreSQL	0	None	Waiting for server startup...

Information	12/14/2017 2:09:26 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/14/2017 2:09:21 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:21 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/14/2017 2:09:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/14/2017 2:09:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/14/2017 2:09:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:20 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/14/2017 2:09:19 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/14/2017 2:09:19 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/14/2017 2:09:19 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/14/2017 2:09:17 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/14/2017 2:09:16 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/14/2017 2:09:16 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3724 at 12/13/2017 2:30:29 PM (local) 12/13/2017 9:00:29 AM (UTC). This is an informational message only; no user action is required.
Information	12/14/2017 2:09:14 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/14/2017 2:09:14 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/14/2017 2:09:14 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/14/2017 2:09:14 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/14/2017 2:09:14 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3660.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/14/2017 2:09:13 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/14/2017 2:08:47 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/14/2017 2:08:41 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/14/2017 2:08:30 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/14/2017 2:08:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/14/2017 2:08:30 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/14/2017 1:41:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 1:41:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 1:41:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 1:41:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 12:39:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 12:34:23 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 343

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 718

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 343

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 296

Information	12/14/2017 12:34:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/14/2017 12:33:43 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	12/14/2017 12:33:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2017 12:33:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57921)(?)])(1 )(2 )]

"
Information	12/14/2017 12:33:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57921)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 12:33:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 12:33:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 12:33:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/14/2017 12:20:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 08fe7b39-e09b-11e7-b1ef-0205857feb80
Report Status: 0"
Information	12/14/2017 12:17:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 12:17:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:12Z. Reason: GVLK.
Information	12/14/2017 12:15:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/14/2017 12:12:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8744.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/14/2017 12:12:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/14/2017 12:12:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 12:12:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 12:12:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/14/2017 12:12:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/14/2017 12:10:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/14/2017 12:10:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57944)(?)])(1 )(2 )]

"
Information	12/14/2017 12:10:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 57944)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/14/2017 12:10:14 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/14/2017 12:10:13 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/14/2017 12:10:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/14/2017 12:10:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/14/2017 12:10:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/13/2017 8:55:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2017 8:48:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e83d32d7-e018-11e7-b1ef-0205857feb80
Report Status: 0"
Information	12/13/2017 8:26:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 8:21:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2017 8:21:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 8:21:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/13/2017 7:16:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/13/2017 5:39:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/13/2017 4:06:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2017 4:06:14 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/13/2017 4:06:14 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	12/13/2017 4:03:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎13T10:32:42.012136200Z.
Information	12/13/2017 4:03:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{280EB920-6707-4086-9B54-20F625D2322E}\DeviceManager.msi. Client Process Id: 5068.
Information	12/13/2017 4:02:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎13T10:32:42.012136200Z.
Information	12/13/2017 4:02:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{280EB920-6707-4086-9B54-20F625D2322E}\DeviceManager.msi. Client Process Id: 5068.
Information	12/13/2017 4:02:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎13T10:32:17.466909200Z.
Information	12/13/2017 4:02:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{280EB920-6707-4086-9B54-20F625D2322E}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 6040.
Information	12/13/2017 4:02:27 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.147. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/13/2017 4:02:27 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	12/13/2017 4:02:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎13T10:32:17.466909200Z.
Information	12/13/2017 4:02:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{280EB920-6707-4086-9B54-20F625D2322E}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 6040.
Information	12/13/2017 3:57:10 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎13T10:27:03.726579700Z.
Information	12/13/2017 3:57:10 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 11180.
Information	12/13/2017 3:57:10 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/13/2017 3:57:10 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	12/13/2017 3:57:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎13T10:27:03.726579700Z.
Information	12/13/2017 3:57:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 11180.
Information	12/13/2017 3:56:32 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎13T10:26:10.034023900Z.
Information	12/13/2017 3:56:32 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 11180.
Information	12/13/2017 3:56:32 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/13/2017 3:56:32 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	12/13/2017 3:56:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎13T10:26:10.034023900Z.
Information	12/13/2017 3:56:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 11180.
Information	12/13/2017 3:48:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fe0e21fe-dfee-11e7-b1ef-0205857feb80
Report Status: 0"
Information	12/13/2017 2:45:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 2:45:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:55Z. Reason: GVLK.
Information	12/13/2017 2:40:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2017 2:40:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 2:40:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 2:40:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 2:40:02 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 2:40:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:59Z. Reason: GVLK.
Information	12/13/2017 2:39:58 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 2:39:13 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9292.
Information	12/13/2017 2:39:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/13/2017 2:39:13 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	12/13/2017 2:39:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 9292.
Information	12/13/2017 2:39:09 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/13/2017 2:39:08 PM	ESENT	102	General	Windows (6304) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/13/2017 2:39:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9292.
Information	12/13/2017 2:39:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/13/2017 2:39:08 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	12/13/2017 2:38:03 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 9292.
Information	12/13/2017 2:37:58 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/13/2017 2:37:58 PM	ESENT	103	General	Windows (10468) Windows: The database engine stopped the instance (0).
Information	12/13/2017 2:37:04 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/13/2017 2:37:03 PM	ESENT	102	General	Windows (10468) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/13/2017 2:37:00 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/13/2017 2:37:00 PM	ESENT	103	General	Windows (8152) Windows: The database engine stopped the instance (0).
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:59 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:57 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:57 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/13/2017 2:36:57 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:57 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/13/2017 2:36:57 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	12/13/2017 2:36:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/13/2017 2:35:45 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8743.0000.
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	12/13/2017 2:34:58 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	12/13/2017 2:34:57 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	12/13/2017 2:34:56 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	12/13/2017 2:34:55 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	12/13/2017 2:34:55 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	12/13/2017 2:34:55 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	12/13/2017 2:34:54 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	12/13/2017 2:34:54 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Error	12/13/2017 2:34:47 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/13/2017 2:34:42 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	12/13/2017 2:34:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2017 2:34:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59240)(?)])(1 )(2 )]

"
Information	12/13/2017 2:34:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59240)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 2:34:13 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/13/2017 2:33:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	12/13/2017 2:33:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	12/13/2017 2:33:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Windows\SysWOW64\SearchProtocolHost.exe' (pid 10172) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/13/2017 2:33:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE' (pid 6760) cannot be restarted - Application SID does not match Conductor SID..
Warning	12/13/2017 2:33:49 PM	Microsoft-Windows-RestartManager	10010	None	Application 'C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe' (pid 6444) cannot be restarted - Application SID does not match Conductor SID..
Error	12/13/2017 2:33:34 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/13/2017 2:33:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎13T09:03:28.308719800Z.
Information	12/13/2017 2:33:22 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/13/2017 2:33:04 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/13/2017 2:33:03 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/13/2017 2:32:58 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/13/2017 2:32:17 PM	ESENT	302	Logging/Recovery	Windows (8152) Windows: The database engine has successfully completed recovery steps.
Information	12/13/2017 2:32:15 PM	ESENT	301	Logging/Recovery	Windows (8152) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/13/2017 2:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2017 2:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59242)(?)])(1 )(2 )]

"
Information	12/13/2017 2:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59242)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 2:32:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2017 2:32:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 2:32:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2017 2:32:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 2:32:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 2:32:08 PM	ESENT	301	Logging/Recovery	Windows (8152) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS056F8.log.
Information	12/13/2017 2:32:08 PM	ESENT	300	Logging/Recovery	Windows (8152) Windows: The database engine is initiating recovery steps.
Information	12/13/2017 2:32:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 2:32:08 PM	ESENT	102	General	Windows (8152) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/13/2017 2:32:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 2:32:05 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8743.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Error	12/13/2017 2:31:24 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/13/2017 2:31:10 PM	Service1	0	None	Service started successfully.
Error	12/13/2017 2:31:04 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/13/2017 2:31:04 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/13/2017 2:31:02 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	12/13/2017 2:31:00 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/13/2017 2:30:57 PM	PostgreSQL	0	None	Server started and accepting connections

Information	12/13/2017 2:30:46 PM	PostgreSQL	0	None	"2017-12-13 14:30:46 IST LOG:  redirecting log output to logging collector process
2017-12-13 14:30:46 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/13/2017 2:30:45 PM	PostgreSQL	0	None	Waiting for server startup...

Information	12/13/2017 2:30:42 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/13/2017 2:30:39 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:39 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/13/2017 2:30:38 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/13/2017 2:30:38 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/13/2017 2:30:38 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/13/2017 2:30:37 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/13/2017 2:30:37 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/13/2017 2:30:37 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/13/2017 2:30:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/13/2017 2:30:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/13/2017 2:30:37 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/13/2017 2:30:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/13/2017 2:30:36 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:35 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/13/2017 2:30:32 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/13/2017 2:30:32 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/13/2017 2:30:32 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/13/2017 2:30:30 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:29 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/13/2017 2:30:29 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/13/2017 2:30:29 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3800 at 12/11/2017 5:26:19 PM (local) 12/11/2017 11:56:19 AM (UTC). This is an informational message only; no user action is required.
Information	12/13/2017 2:30:29 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/13/2017 2:30:27 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/13/2017 2:30:27 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/13/2017 2:30:27 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/13/2017 2:30:27 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/13/2017 2:30:27 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3724.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/13/2017 2:30:26 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/13/2017 2:30:05 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/13/2017 2:29:57 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/13/2017 2:29:43 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/13/2017 2:29:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/13/2017 2:29:43 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/13/2017 1:31:33 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 2, Deleted: 0, Modified: 9, Compared: 17571, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/13/2017 1:30:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	12/13/2017 12:35:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2017 12:14:49 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 12:10:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8743.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/13/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/13/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59385)(?)])(1 )(2 )]

"
Information	12/13/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 59385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/13/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 10:55:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 10:55:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:54:35Z. Reason: GVLK.
Information	12/13/2017 10:50:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2017 10:50:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 10:50:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 10:50:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 10:48:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 14e058f9-dfc5-11e7-bdf2-204747d02364
Report Status: 0"
Information	12/13/2017 10:45:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/13/2017 10:45:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:48Z. Reason: GVLK.
Information	12/13/2017 10:44:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/13/2017 10:43:54 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	12/13/2017 10:41:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/13/2017 10:40:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/13/2017 10:40:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/13/2017 10:40:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/13/2017 10:40:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/13/2017 10:38:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	12/12/2017 7:02:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 6:26:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 6:25:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 5:40:02 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/12/2017 5:28:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bd575278-df33-11e7-bdf2-204747d02364
Report Status: 0"
Warning	12/12/2017 5:05:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 4:19:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2883f414-df2a-11e7-bdf2-204747d02364
Report Status: 0"
Warning	12/12/2017 3:19:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/12/2017 2:36:05 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/12/2017 2:31:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 2:31:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:57Z. Reason: GVLK.
Information	12/12/2017 2:30:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 2:26:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2017 2:26:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 2:26:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 2:26:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/12/2017 2:25:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 2:25:49 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/12/2017 2:25:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 2:25:43 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	12/12/2017 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/12/2017 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60689)(?)])(1 )(2 )]

"
Information	12/12/2017 2:25:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60689)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 2:25:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2017 2:25:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 2:25:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/12/2017 1:30:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 12:43:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8742.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/12/2017 12:28:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d3d356a3-df09-11e7-bdf2-204747d02364
Report Status: 0"
Information	12/12/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/12/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60825)(?)])(1 )(2 )]

"
Information	12/12/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 60825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/12/2017 11:59:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/12/2017 11:34:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 11:19:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 11:14:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2017 11:14:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 11:14:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/12/2017 10:29:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 10:29:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-19T04:53:44Z. Reason: GVLK.
Information	12/12/2017 10:24:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 10:24:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 10:24:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/12/12 04:54"
Information	12/12/2017 10:24:39 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/12/12 04:54, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/12/2017 10:19:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2017 10:19:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 10:19:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 10:19:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/12/2017 10:00:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 8:30:48 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/12/2017 8:30:45 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	12/12/2017 8:04:40 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 7:59:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 7:59:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 7:28:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ea7f934d-dedf-11e7-bdf2-204747d02364
Report Status: 0"
Warning	12/12/2017 6:09:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 5:28:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎12‎-‎11T23:58:30.151918300Z.
Information	12/12/2017 5:26:49 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 5:21:49 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/12/2017 5:21:49 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 5:21:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/12/2017 4:17:52 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 3:59:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 3:59:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:35Z. Reason: GVLK.
Information	12/12/2017 3:59:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/12/2017 3:54:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2017 3:54:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 3:54:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 3:54:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/12/2017 3:53:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f97efff7-dec1-11e7-bdf2-204747d02364
Report Status: 0"
Information	12/12/2017 3:53:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f97efff6-dec1-11e7-bdf2-204747d02364
Report Status: 0"
Information	12/12/2017 3:53:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f97efff5-dec1-11e7-bdf2-204747d02364
Report Status: 0"
Error	12/12/2017 3:50:51 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/12/2017 3:45:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 3:45:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:50:01Z. Reason: GVLK.
Error	12/12/2017 3:40:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/12/2017 3:40:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2017 3:40:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 3:40:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 3:39:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/12/2017 2:28:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ffb84ea0-deb5-11e7-bdf2-204747d02364
Report Status: 0"
Warning	12/12/2017 2:23:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 1:47:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/12/2017 1:47:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:55Z. Reason: GVLK.
Information	12/12/2017 1:42:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/12/2017 1:42:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/12/2017 1:42:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/12/2017 1:42:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/12/2017 12:29:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/12/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/11/2017 11:58:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/11/2017 10:34:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 9:28:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 153c4f0b-de8c-11e7-bdf2-204747d02364
Report Status: 0"
Information	12/11/2017 9:10:06 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/11/2017 8:44:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 8:03:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 7:58:43 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2209.
Information	12/11/2017 7:58:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 7:58:38 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 374

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 546

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 32

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 46

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 32

Information	12/11/2017 7:58:38 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/11/2017 7:58:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 7:58:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2017 7:58:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61796)(?)])(1 )(2 )]

"
Information	12/11/2017 7:58:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61796)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 7:58:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2017 7:58:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61796)(?)])(1 )(2 )]

"
Information	12/11/2017 7:58:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61796)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 7:58:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2017 7:58:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 7:58:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	12/11/2017 7:58:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/11/2017 7:08:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 5:42:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 5:37:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 3080.
Information	12/11/2017 5:37:04 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/11/2017 5:37:04 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	12/11/2017 5:37:04 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/11/2017 5:37:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 5:37:02 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/11/2017 5:37:02 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/11/2017 5:37:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 5:37:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2017 5:37:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 5:37:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 5:36:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 5:36:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/11/2017 5:36:43 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	12/11/2017 5:36:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:41 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/11/2017 5:36:41 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	12/11/2017 5:36:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/11/2017 5:36:37 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	12/11/2017 5:36:26 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/11/2017 5:36:26 PM	ESENT	102	General	Windows (8828) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/11/2017 5:36:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 5:36:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:50:00Z. Reason: GVLK.
Information	12/11/2017 5:36:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:10 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/11/2017 5:36:10 PM	ESENT	103	General	Windows (7180) Windows: The database engine stopped the instance (0).
Information	12/11/2017 5:36:10 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:36:10 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2209. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	12/11/2017 5:36:10 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	12/11/2017 5:34:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 3080.
Information	12/11/2017 5:33:47 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/11/2017 5:33:46 PM	ESENT	102	General	Windows (7180) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/11/2017 5:33:43 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/11/2017 5:33:43 PM	ESENT	103	General	Windows (9044) Windows: The database engine stopped the instance (0).
Information	12/11/2017 5:33:42 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:42 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:42 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:41 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	12/11/2017 5:33:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	12/11/2017 5:33:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Error	12/11/2017 5:33:21 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/11/2017 5:33:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2017 5:33:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61941)(?)])(1 )(2 )]

"
Information	12/11/2017 5:33:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61941)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 5:33:07 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/11/2017 5:33:07 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/11/2017 5:32:26 PM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	12/11/2017 5:32:26 PM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Skype for Business'.
Information	12/11/2017 5:32:23 PM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Windows Explorer'.
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	12/11/2017 5:32:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	12/11/2017 5:32:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	12/11/2017 5:31:31 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	12/11/2017 5:30:01 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/11/2017 5:29:57 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Microsoft Windows Search Protocol Host'.
Information	12/11/2017 5:29:57 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Windows Explorer'.
Information	12/11/2017 5:29:55 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Information	12/11/2017 5:29:55 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Skype for Business'.
Error	12/11/2017 5:29:38 PM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Microsoft Windows Search Protocol Host' could not be shut down.
Information	12/11/2017 5:29:14 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/11/2017 5:29:12 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/11/2017 5:29:11 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/11/2017 5:29:09 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	12/11/2017 5:28:59 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/11/2017 5:28:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎12‎-‎11T11:58:52.026683000Z.
Information	12/11/2017 5:28:27 PM	ESENT	302	Logging/Recovery	Windows (9044) Windows: The database engine has successfully completed recovery steps.
Information	12/11/2017 5:28:20 PM	ESENT	301	Logging/Recovery	Windows (9044) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/11/2017 5:28:20 PM	ESENT	300	Logging/Recovery	Windows (9044) Windows: The database engine is initiating recovery steps.
Information	12/11/2017 5:28:20 PM	ESENT	102	General	Windows (9044) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/11/2017 5:28:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2017 5:28:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61946)(?)])(1 )(2 )]

"
Information	12/11/2017 5:28:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2017 5:28:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 5:28:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 5:28:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 61946)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 5:28:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2017 5:28:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 5:28:01 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 5:28:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 5:27:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8741.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/11/2017 5:27:31 PM	PostgreSQL	0	None	Server started and accepting connections

Information	12/11/2017 5:27:21 PM	Service1	0	None	Service started successfully.
Error	12/11/2017 5:27:16 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/11/2017 5:27:14 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/11/2017 5:26:51 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	12/11/2017 5:26:50 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/11/2017 5:26:45 PM	PostgreSQL	0	None	"2017-12-11 17:26:45 IST LOG:  redirecting log output to logging collector process
2017-12-11 17:26:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/11/2017 5:26:42 PM	PostgreSQL	0	None	Waiting for server startup...

Information	12/11/2017 5:26:41 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/11/2017 5:26:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/11/2017 5:26:29 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/11/2017 5:26:29 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/11/2017 5:26:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/11/2017 5:26:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/11/2017 5:26:25 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/11/2017 5:26:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:23 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/11/2017 5:26:22 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/11/2017 5:26:22 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/11/2017 5:26:22 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/11/2017 5:26:20 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:20 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/11/2017 5:26:20 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/11/2017 5:26:19 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:19 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/11/2017 5:26:19 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/11/2017 5:26:19 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3752 at 12/4/2017 9:50:07 AM (local) 12/4/2017 4:20:07 AM (UTC). This is an informational message only; no user action is required.
Information	12/11/2017 5:26:19 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/11/2017 5:26:17 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/11/2017 5:26:16 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/11/2017 5:26:16 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/11/2017 5:26:16 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/11/2017 5:26:16 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3800.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/11/2017 5:26:15 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/11/2017 5:25:39 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/11/2017 5:25:33 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/11/2017 5:25:22 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/11/2017 5:25:22 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/11/2017 5:25:22 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/11/2017 4:28:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2a9142a0-de62-11e7-99c0-204747d02364
Report Status: 0"
Information	12/11/2017 4:01:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 3:55:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2017 3:55:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 3:55:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/11/2017 3:20:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/11/2017 2:35:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/11/2017 2:32:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 2:32:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:16Z. Reason: GVLK.
Information	12/11/2017 2:27:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2017 2:27:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 2:27:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 2:27:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/11/2017 1:22:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 1:18:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 1:17:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 1:17:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 1:06:54 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/11/2017 1:06:43 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/11/2017 12:42:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8741.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/11/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62265)(?)])(1 )(2 )]

"
Information	12/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 62265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/11/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 11:43:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 11:43:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:30Z. Reason: GVLK.
Warning	12/11/2017 11:43:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 11:38:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2017 11:38:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 11:38:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 11:38:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 11:34:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/11/2017 11:28:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3f614337-de38-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/11/2017 10:03:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 9:17:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 9:17:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 9:17:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/11/2017 8:12:36 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 6:28:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 55e1a758-de0e-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/11/2017 6:20:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 5:17:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 5:17:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 5:17:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 4:40:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 4:40:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:31Z. Reason: GVLK.
Information	12/11/2017 4:35:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2017 4:35:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 4:35:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 4:35:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/11/2017 4:35:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c33a3e6-ddfe-11e7-99c0-204747d02364
Report Status: 0"
Information	12/11/2017 4:35:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c33a3e5-ddfe-11e7-99c0-204747d02364
Report Status: 0"
Information	12/11/2017 4:35:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c33a3e4-ddfe-11e7-99c0-204747d02364
Report Status: 0"
Error	12/11/2017 4:32:06 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/11/2017 4:24:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/11/2017 4:24:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:15Z. Reason: GVLK.
Warning	12/11/2017 4:22:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/11/2017 4:19:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/11/2017 4:16:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/11/2017 4:16:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/11/2017 4:16:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/11/2017 4:16:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/11/2017 2:44:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 1:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6b5aab64-dde4-11e7-99c0-204747d02364
Report Status: 0"
Information	12/11/2017 1:17:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/11/2017 1:17:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/11/2017 1:12:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/11/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/10/2017 11:31:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/10/2017 9:34:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 9:17:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2017 8:27:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8133439d-ddba-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/10/2017 7:43:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/10/2017 5:45:48 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 5:17:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/10/2017 4:12:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 3:27:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 970371cc-dd90-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/10/2017 2:38:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/10/2017 2:35:52 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/10/2017 1:31:01 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 17160, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/10/2017 1:30:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/10/2017 1:17:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/10/2017 12:39:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/10/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/10/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63705)(?)])(1 )(2 )]

"
Information	12/10/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 63705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/10/2017 12:01:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8740.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/10/2017 11:33:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/10/2017 10:44:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 10:27:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad56d768-dd66-11e7-99c0-204747d02364
Report Status: 0"
Information	12/10/2017 9:37:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/10/2017 9:37:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:45Z. Reason: GVLK.
Information	12/10/2017 9:32:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/10/2017 9:32:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2017 9:32:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2017 9:32:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/10/2017 9:16:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/10/2017 9:04:14 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/10/2017 7:14:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 5:27:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3a9dde8-dd3c-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/10/2017 5:24:51 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 5:16:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2017 4:22:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/10/2017 4:22:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:50Z. Reason: GVLK.
Information	12/10/2017 4:17:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/10/2017 4:17:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/10/2017 4:17:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2017 4:17:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/10/2017 4:13:17 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎12‎-‎09T22:43:17.047524000Z.
Information	12/10/2017 4:12:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/10/2017 4:07:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/10/2017 4:07:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/10/2017 4:07:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/10/2017 3:42:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/10/2017 2:04:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/10/2017 1:16:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2017 1:16:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/10/2017 12:27:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9d6fc07-dd12-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/10/2017 12:11:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/9/2017 10:15:00 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 9:16:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/9/2017 9:16:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/9/2017 8:18:18 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 7:27:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f02c68df-dce8-11e7-99c0-204747d02364
Report Status: 0"
Warning	12/9/2017 6:24:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 6:08:50 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/9/2017 5:16:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/9/2017 5:16:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/9/2017 4:46:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/9/2017 3:02:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/9/2017 2:35:53 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/9/2017 2:27:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 04e4f6a5-dcbf-11e7-99c0-204747d02364
Report Status: 0"
Information	12/9/2017 1:16:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/9/2017 1:16:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/9/2017 1:16:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/9/2017 1:10:19 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 12:14:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/9/2017 12:09:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65144)(?)])(1 )(2 )]

"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 45 65144)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=108344  Grace type=8.
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=d1d46498-70e9-4158-ab21-eb6ffd14ff66"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=13cb9fdb-bbd7-41ac-9984-8f5b8146d0c3"
Information	12/9/2017 12:09:52 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/9/2017 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/9/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19065)(?)])(1 )(2 )]

"
Information	12/9/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 19065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/9/2017 12:09:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/9/2017 12:09:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/9/2017 12:09:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/9/2017 12:06:57 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8739.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Information	12/9/2017 11:21:33 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	12/9/2017 11:21:33 AM	MsiInstaller	11729	None	Product: DeviceManager -- Configuration failed.
Information	12/9/2017 11:20:01 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Warning	12/9/2017 11:16:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 11:14:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/9/2017 10:20:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/9/2017 10:19:47 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/9/2017 10:05:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/9/2017 10:05:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:18Z. Reason: GVLK.
Information	12/9/2017 10:00:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/9/2017 10:00:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/9/2017 10:00:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/9/2017 10:00:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/9/2017 9:59:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89a3981f-dc99-11e7-99c0-204747d02364
Report Status: 0"
Information	12/9/2017 9:59:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89a3981e-dc99-11e7-99c0-204747d02364
Report Status: 0"
Information	12/9/2017 9:59:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89a3981d-dc99-11e7-99c0-204747d02364
Report Status: 0"
Error	12/9/2017 9:55:37 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/9/2017 9:27:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ac54614-dc95-11e7-99c0-204747d02364
Report Status: 0"
Information	12/9/2017 9:27:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/9/2017 9:27:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:05Z. Reason: GVLK.
Error	12/9/2017 9:23:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/9/2017 9:18:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/9/2017 9:18:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/9/2017 9:18:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/9/2017 9:18:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/9/2017 9:18:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/9/2017 9:16:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/9/2017 9:16:16 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/9/2017 9:16:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/9/2017 9:16:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	12/9/2017 9:16:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/8/2017 6:18:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 6:18:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/8/2017 5:59:50 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 4:27:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a1b626bd-dc06-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/8/2017 4:16:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/8/2017 2:35:48 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/8/2017 2:20:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 2:18:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 2:18:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 12:57:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8738.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!eebbfb82ad42 (ED)
"
Warning	12/8/2017 12:34:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20505)(?)])(1 )(2 )]

"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/8/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/8/2017 11:27:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5aa5018-dbdc-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/8/2017 11:02:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 10:20:37 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/8/2017 10:18:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/8/2017 10:18:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 10:18:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 10:18:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 10:17:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/8/2017 9:36:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/8/2017 9:36:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:22Z. Reason: GVLK.
Information	12/8/2017 9:31:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/8/2017 9:31:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/8/2017 9:31:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/8/2017 9:31:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/8/2017 9:11:25 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/8/2017 7:24:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 6:34:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/8/2017 6:29:48 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/8/2017 6:29:48 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/8/2017 6:29:48 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/8/2017 6:27:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb891e0d-dbb2-11e7-99bf-204747d02364
Report Status: 0"
Information	12/8/2017 6:18:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 6:18:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/8/2017 5:37:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/8/2017 3:55:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 2:18:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/8/2017 2:18:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/8/2017 2:01:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/8/2017 1:27:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1a25e85-db88-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/8/2017 12:05:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/7/2017 10:29:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 10:18:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2017 10:13:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 10:13:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:18Z. Reason: GVLK.
Information	12/7/2017 10:08:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2017 10:08:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2017 10:08:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 10:08:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2017 9:43:26 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/7/2017 9:42:20 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	12/7/2017 8:35:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 8:27:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f7aebcfb-db5e-11e7-99bf-204747d02364
Report Status: 0"
Information	12/7/2017 8:25:39 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	12/7/2017 6:44:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 6:23:17 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/7/2017 6:23:17 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	12/7/2017 6:22:45 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎07T12:52:10.447179900Z.
Information	12/7/2017 6:22:45 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0A3F1EB0-FD9B-4499-B860-C737938187B0}\DeviceManager.msi. Client Process Id: 16908.
Information	12/7/2017 6:22:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎07T12:52:10.447179900Z.
Information	12/7/2017 6:22:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0A3F1EB0-FD9B-4499-B860-C737938187B0}\DeviceManager.msi. Client Process Id: 16908.
Information	12/7/2017 6:21:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎07T12:51:24.331340400Z.
Information	12/7/2017 6:21:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0A3F1EB0-FD9B-4499-B860-C737938187B0}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 12256.
Information	12/7/2017 6:21:53 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.2.0.130. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	12/7/2017 6:21:53 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	12/7/2017 6:21:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎07T12:51:24.331340400Z.
Information	12/7/2017 6:21:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0A3F1EB0-FD9B-4499-B860-C737938187B0}\{30EC6747-4D4C-4350-A498-38CEA5BDE9E1}\DeviceDriver.msi. Client Process Id: 12256.
Information	12/7/2017 6:20:46 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/7/2017 6:17:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/7/2017 6:07:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 6:02:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/7/2017 6:02:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 6:02:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/7/2017 5:41:52 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/7/2017 5:02:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎07T11:32:36.194195200Z.
Information	12/7/2017 5:02:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15680.
Information	12/7/2017 5:02:43 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/7/2017 5:02:43 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	12/7/2017 5:02:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎07T11:32:36.194195200Z.
Information	12/7/2017 5:02:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 15680.
Information	12/7/2017 5:02:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎07T11:30:00.724195200Z.
Information	12/7/2017 5:02:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15680.
Information	12/7/2017 5:02:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	12/7/2017 5:02:27 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	12/7/2017 5:00:09 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	12/7/2017 5:00:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎07T11:30:00.724195200Z.
Information	12/7/2017 4:59:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15680.
Information	12/7/2017 4:55:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎12‎-‎07T11:24:58.020469200Z.
Information	12/7/2017 4:55:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15680.
Information	12/7/2017 4:55:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 1602.
Information	12/7/2017 4:55:29 PM	MsiInstaller	11725	None	Product: DeviceManager -- Removal failed.
Information	12/7/2017 4:55:19 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	12/7/2017 4:54:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎12‎-‎07T11:24:58.020469200Z.
Information	12/7/2017 4:54:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 15680.
Error	12/7/2017 4:54:15 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/7/2017 4:46:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 4:05:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 4:00:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/7/2017 4:00:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21714)(?)])(1 )(2 )]

"
Information	12/7/2017 4:00:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21714)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2017 4:00:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/7/2017 4:00:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 4:00:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/7/2017 3:27:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d997180-db35-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/7/2017 3:06:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 2:17:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/7/2017 1:33:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 1:32:16 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 16890, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/7/2017 1:31:22 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	12/7/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 12:13:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8737.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21945)(?)])(1 )(2 )]

"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/7/2017 11:56:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 10:47:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 10:47:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:31Z. Reason: GVLK.
Information	12/7/2017 10:42:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2017 10:42:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2017 10:42:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 10:42:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/7/2017 10:41:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bfb1f55-db0d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/7/2017 10:41:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bfb1f54-db0d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/7/2017 10:41:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bfb1f53-db0d-11e7-99bf-204747d02364
Report Status: 0"
Error	12/7/2017 10:35:48 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/7/2017 10:27:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 222a225b-db0b-11e7-99bf-204747d02364
Report Status: 0"
Information	12/7/2017 10:26:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/7/2017 10:26:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:55Z. Reason: GVLK.
Error	12/7/2017 10:20:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/7/2017 10:20:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/7/2017 10:20:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/7/2017 10:20:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/7/2017 10:20:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/7/2017 10:19:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/7/2017 10:17:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/7/2017 10:17:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/7/2017 10:17:42 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/7/2017 10:17:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2017 8:40:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/6/2017 6:41:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 5:10:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 5:10:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 4:56:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 42b7451b-da78-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/6/2017 4:41:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 3:31:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/6/2017 3:26:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/6/2017 3:26:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23189)(?)])(1 )(2 )]

"
Information	12/6/2017 3:26:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23189)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2017 3:26:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/6/2017 3:26:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2017 3:26:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/6/2017 2:48:13 PM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Warning	12/6/2017 2:45:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/6/2017 2:35:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/6/2017 1:10:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 1:10:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 1:09:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/6/2017 1:09:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2017 12:50:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 12:46:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8736.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/6/2017 12:34:22 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/6/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/6/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/6/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23385)(?)])(1 )(2 )]

"
Information	12/6/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/6/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/6/2017 11:56:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 575c07a8-da4e-11e7-99bf-204747d02364
Report Status: 0"
Information	12/6/2017 11:28:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2017 11:28:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:14Z. Reason: GVLK.
Information	12/6/2017 11:23:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2017 11:23:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2017 11:23:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2017 11:23:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/6/2017 11:15:18 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	12/6/2017 11:00:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 9:59:17 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/6/2017 9:27:07 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 9:10:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 9:09:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2017 7:53:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 6:56:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6b4f2ddf-da24-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/6/2017 6:07:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 5:10:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 5:09:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/6/2017 4:25:12 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 4:16:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2017 4:16:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:06Z. Reason: GVLK.
Information	12/6/2017 4:11:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2017 4:11:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2017 4:11:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2017 4:11:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/6/2017 4:09:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 379d41f4-da0d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/6/2017 4:09:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 379d41f3-da0d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/6/2017 4:09:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 379d41f2-da0d-11e7-99bf-204747d02364
Report Status: 0"
Error	12/6/2017 4:06:22 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/6/2017 3:57:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/6/2017 3:57:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:20Z. Reason: GVLK.
Error	12/6/2017 3:52:47 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/6/2017 3:52:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/6/2017 3:52:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/6/2017 3:52:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/6/2017 3:52:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/6/2017 3:33:44 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	12/6/2017 3:19:23 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	12/6/2017 2:54:15 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 1:55:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 802a6322-d9fa-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/6/2017 1:15:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/6/2017 1:10:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 1:09:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/6/2017 12:16:57 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/5/2017 11:34:01 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 10:16:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 10:16:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:56Z. Reason: GVLK.
Information	12/5/2017 10:11:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 10:11:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 10:11:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 10:11:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/5/2017 9:41:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 9:09:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2017 9:09:54 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/5/2017 9:09:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2017 8:55:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8baf2053-d9d0-11e7-99bf-204747d02364
Report Status: 0"
Error	12/5/2017 7:43:58 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/5/2017 7:43:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 7:36:01 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/5/2017 7:36:01 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/5/2017 7:34:49 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/5/2017 7:34:47 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	12/5/2017 6:00:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 5:54:29 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 5:54:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:29Z. Reason: GVLK.
Information	12/5/2017 5:49:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 5:49:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 5:49:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 5:49:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 5:09:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/5/2017 4:11:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 3:54:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 87a02d02-d9a6-11e7-99bf-204747d02364
Report Status: 0"
Error	12/5/2017 2:35:27 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	12/5/2017 2:23:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 1:14:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 1:09:20 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	12/5/2017 1:09:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2017 1:08:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2017 1:08:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24766)(?)])(1 )(2 )]

"
Information	12/5/2017 1:08:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24766)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 1:08:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2017 1:08:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 1:08:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/5/2017 12:50:42 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 12:42:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/5/2017 12:17:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 12:14:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8735.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/5/2017 12:11:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2017 12:11:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24823)(?)])(1 )(2 )]

"
Information	12/5/2017 12:11:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24823)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/5/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]

"
Information	12/5/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 12:08:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 12:08:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:52Z. Reason: GVLK.
Information	12/5/2017 12:03:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 12:03:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 12:03:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 12:03:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 11:06:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/5/2017 11:06:38 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 10:54:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ae34514-d97c-11e7-99bf-204747d02364
Report Status: 0"
Information	12/5/2017 10:37:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/5/2017 10:25:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 10:25:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-12T04:49:04Z. Reason: GVLK.
Information	12/5/2017 10:20:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 10:20:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 10:20:04 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/12/05 04:50"
Information	12/5/2017 10:20:03 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/12/05 04:50, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	12/5/2017 10:15:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 10:15:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 10:15:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 10:15:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 10:13:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/5/2017 9:14:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/5/2017 7:18:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 7:06:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/5/2017 6:43:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 6:38:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/5/2017 6:38:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 6:38:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 5:54:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: afe5623d-d952-11e7-99bf-204747d02364
Report Status: 0"
Warning	12/5/2017 5:23:48 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/5/2017 3:28:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 3:25:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 3:25:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:45:00Z. Reason: GVLK.
Information	12/5/2017 3:20:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 3:20:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 3:20:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 3:19:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/5/2017 3:19:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0305d9bd-d93d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/5/2017 3:19:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0305d9bc-d93d-11e7-99bf-204747d02364
Report Status: 0"
Information	12/5/2017 3:19:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0305d9bb-d93d-11e7-99bf-204747d02364
Report Status: 0"
Error	12/5/2017 3:16:42 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/5/2017 3:10:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/5/2017 3:10:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:45:01Z. Reason: GVLK.
Information	12/5/2017 3:06:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	12/5/2017 3:05:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/5/2017 3:05:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/5/2017 3:05:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/5/2017 3:05:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/5/2017 3:05:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/5/2017 1:36:54 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/5/2017 12:54:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c57dba89-d928-11e7-99bf-204747d02364
Report Status: 0"
Information	12/5/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	12/4/2017 11:58:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2017 11:22:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 11:22:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:45:10Z. Reason: GVLK.
Information	12/4/2017 11:17:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2017 11:17:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 11:17:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 11:17:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 11:06:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/4/2017 10:27:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/4/2017 8:32:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2017 7:54:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: db785081-d8fe-11e7-99bf-204747d02364
Report Status: 0"
Information	12/4/2017 7:06:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/4/2017 6:35:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/4/2017 4:58:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	12/4/2017 3:13:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2017 3:05:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2017 2:54:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f12d8565-d8d4-11e7-99bf-204747d02364
Report Status: 0"
Error	12/4/2017 2:35:20 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/4/2017 1:57:47 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/4/2017 1:36:17 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 6, Compared: 16453, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/4/2017 1:35:32 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	12/4/2017 1:27:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2017 12:58:31 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8734.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Wednesday, November 22, 2017 1:55:07 AM.
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <E=acraiz@suscerte.gob.ve, OU=Superintendencia de Servicios de Certificacion Electronica, O=Sistema Nacional de Certificacion Electronica, S=Distrito Capital, L=Caracas, C=VE, CN=Autoridad de Certificacion Raiz del Estado Venezolano> Sha1 thumbprint: <398EBE9C0F46C079C3C7AFE07A2FDD9FAE5F8A5C>.
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <E=Info@izenpe.com, CN=Izenpe.com, L=Avda del Mediterraneo Etorbidea 3 - 01010 Vitoria-Gasteiz, O=IZENPE S.A. - CIF A-01337260-RMerc.Vitoria-Gasteiz T1055 F62 S8, C=ES> Sha1 thumbprint: <4A3F8D6BDC0E1ECFCD72E377DEF2D7FF92C19BC7>.
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE> Sha1 thumbprint: <B1BC968BD4F49D622AA89A81F2150152A41D829C>.
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GlobalSign, O=GlobalSign, OU=GlobalSign Root CA - R3> Sha1 thumbprint: <D69B561148F01C77C54578C10926DF5B856976AD>.
Information	12/4/2017 12:58:12 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <E=acraiz@suscerte.gob.ve, OU=Superintendencia de Servicios de Certificacion Electronica, O=Sistema Nacional de Certificacion Electronica, S=Distrito Capital, L=Caracas, C=VE, CN=Autoridad de Certificacion Raiz del Estado Venezolano> Sha1 thumbprint: <DD83C519D43481FAD4C22C03D702FE9F3B22F517>.
Information	12/4/2017 12:21:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 12:16:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 12:16:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 12:16:18 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/4/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]

"
Information	12/4/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 11:39:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 11:34:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 11:34:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 11:34:18 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	12/4/2017 11:34:18 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	12/4/2017 11:34:17 AM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	12/4/2017 11:34:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 11:34:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 11:34:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/4/2017 11:27:19 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/4/2017 11:11:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 11:05:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	12/4/2017 11:05:43 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 93

Information	12/4/2017 11:05:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/4/2017 11:05:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/4/2017 11:05:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26329)(?)])(1 )(2 )]

"
Information	12/4/2017 11:05:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26329)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 11:05:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 11:05:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 11:05:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 10:41:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 10:36:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 10:36:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 10:36:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 10:20:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 10:20:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:45:09Z. Reason: GVLK.
Information	12/4/2017 10:15:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2017 10:15:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 10:15:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 10:15:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 10:14:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d981107b-d8ad-11e7-99bf-204747d02364
Report Status: 0"
Information	12/4/2017 10:14:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d981107a-d8ad-11e7-99bf-204747d02364
Report Status: 0"
Information	12/4/2017 10:14:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9811079-d8ad-11e7-99bf-204747d02364
Report Status: 0"
Error	12/4/2017 10:12:24 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/4/2017 10:11:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 10:06:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 10:06:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 10:06:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 9:59:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/4/2017 9:59:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:26Z. Reason: GVLK.
Information	12/4/2017 9:57:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	12/4/2017 9:54:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/4/2017 9:53:40 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Error	12/4/2017 9:52:33 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {68941369-C166-4E15-8DBE-883698C28633}
Error	12/4/2017 9:52:33 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {68941369-C166-4E15-8DBE-883698C28633}
Information	12/4/2017 9:52:33 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/4/2017 9:52:32 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/4/2017 9:52:31 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	12/4/2017 9:52:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/4/2017 9:52:27 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/4/2017 9:51:50 AM	ESENT	302	Logging/Recovery	Windows (8124) Windows: The database engine has successfully completed recovery steps.
Information	12/4/2017 9:51:49 AM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/4/2017 9:51:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/4/2017 9:51:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 9:51:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 9:51:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/4/2017 9:51:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26403)(?)])(1 )(2 )]

"
Information	12/4/2017 9:51:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26403)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/4/2017 9:51:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/4/2017 9:51:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/4/2017 9:51:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 9:51:42 AM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05652.log.
Information	12/4/2017 9:51:42 AM	ESENT	300	Logging/Recovery	Windows (8124) Windows: The database engine is initiating recovery steps.
Information	12/4/2017 9:51:42 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/4/2017 9:51:42 AM	ESENT	102	General	Windows (8124) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/4/2017 9:51:38 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8733.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/4/2017 9:50:50 AM	Service1	0	None	Service started successfully.
Error	12/4/2017 9:50:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/4/2017 9:50:42 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/4/2017 9:50:33 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/4/2017 9:50:32 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/4/2017 9:50:28 AM	PostgreSQL	0	None	"2017-12-04 09:50:28 IST LOG:  redirecting log output to logging collector process
2017-12-04 09:50:28 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/4/2017 9:50:26 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/4/2017 9:50:24 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/4/2017 9:50:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/4/2017 9:50:17 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/4/2017 9:50:17 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/4/2017 9:50:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/4/2017 9:50:17 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/4/2017 9:50:12 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:12 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/4/2017 9:50:12 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/4/2017 9:50:12 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/4/2017 9:50:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/4/2017 9:50:11 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/4/2017 9:50:10 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3680 at 12/4/2017 5:38:00 AM (local) 12/4/2017 12:08:00 AM (UTC). This is an informational message only; no user action is required.
Information	12/4/2017 9:50:07 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/4/2017 9:50:04 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/4/2017 9:50:04 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/4/2017 9:50:04 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/4/2017 9:50:04 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/4/2017 9:50:04 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3752.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/4/2017 9:50:03 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/4/2017 9:49:29 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/4/2017 9:49:23 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/4/2017 9:49:12 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/4/2017 5:38:10 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	12/4/2017 9:49:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/4/2017 9:49:12 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/4/2017 5:38:00 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	12/4/2017 5:38:00 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	12/4/2017 5:37:57 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 932 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 932 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 932 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 932 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 932 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	12/4/2017 5:37:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	12/4/2017 5:37:56 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	12/4/2017 5:37:56 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	12/4/2017 5:37:54 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	12/4/2017 5:37:49 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	12/4/2017 5:34:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2017 9:32:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e53bc4a-d843-11e7-af08-204747d02364
Report Status: 0"
Information	12/3/2017 9:20:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/3/2017 3:15:44 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/3/2017 3:15:00 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	12/3/2017 2:35:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/3/2017 2:10:56 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/3/2017 2:10:55 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/3/2017 1:54:37 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x7265635c
Faulting process id: 0x2a48
Faulting application start time: 0x01d36b7fbe6e14ed
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: 65d5a6ac-d803-11e7-af08-204747d02364"
Error	12/3/2017 1:54:36 PM	RasClient	20227	None	CoId={66140C9C-F1E6-4C2C-B3FB-64CECECD5494}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	12/3/2017 1:54:36 PM	RasClient	20221	None	CoId={66140C9C-F1E6-4C2C-B3FB-64CECECD5494}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	12/3/2017 1:54:36 PM	RasClient	20227	None	CoId={F6EA3EDB-7FFC-4B51-8D2F-7BC14707B82E}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	12/3/2017 1:54:36 PM	RasClient	20221	None	CoId={F6EA3EDB-7FFC-4B51-8D2F-7BC14707B82E}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	12/3/2017 1:54:33 PM	RasClient	20226	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	12/3/2017 1:35:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c668a85f-d800-11e7-af08-204747d02364
Report Status: 0"
Warning	12/3/2017 1:14:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2017 12:26:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2017 12:26:05 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/3/2017 12:25:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/3/2017 12:15:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8733.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/3/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/3/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27705)(?)])(1 )(2 )]

"
Information	12/3/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2017 11:44:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2017 11:38:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2017 11:38:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2017 11:38:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2017 11:00:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2017 10:54:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2017 10:54:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2017 10:54:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	12/3/2017 10:37:10 AM	Application Error	1000	(100)	"Faulting application name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x57316441
Faulting module name: wxbase28u_vc_custom.dll, version: 2.8.12.0, time stamp: 0x5359fda3
Exception code: 0xc0000005
Fault offset: 0x0000000000080971
Faulting process id: 0x2714
Faulting application start time: 0x01d36b3e4eec6326
Faulting application path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Faulting module path: C:\Program Files\PostgreSQL\9.5\bin\wxbase28u_vc_custom.dll
Report Id: d04c7e56-d7e7-11e7-af08-204747d02364"
Warning	12/3/2017 10:01:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/3/2017 9:58:03 AM	RasClient	20225	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.227.96
TunnelIpv6Address = None
Dial-in User = .
Information	12/3/2017 9:57:58 AM	RasClient	20224	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	12/3/2017 9:57:58 AM	RasClient	20223	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/3/2017 9:57:58 AM	RasClient	20222	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/3/2017 9:57:58 AM	RasClient	20221	None	CoId={3567031D-C91B-4265-9FA4-1F5F1ADBBF5C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	12/3/2017 8:40:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/3/2017 8:40:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:35Z. Reason: GVLK.
Information	12/3/2017 8:35:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8ac1681-d7d6-11e7-af08-204747d02364
Report Status: 0"
Information	12/3/2017 8:35:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/3/2017 8:35:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/3/2017 8:35:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2017 8:35:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/3/2017 8:30:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/3/2017 8:25:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/3/2017 8:25:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/3/2017 8:25:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/3/2017 8:25:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/2/2017 11:40:11 PM	RasClient	20226	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	12/2/2017 10:32:56 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2017 9:47:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/2/2017 9:46:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/2/2017 9:30:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2017 9:30:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	12/2/2017 9:29:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/2/2017 9:29:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cecb7a62-d779-11e7-af08-204747d02364
Report Status: 0"
Warning	12/2/2017 8:44:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2017 8:42:35 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/2/2017 8:42:01 PM	RasClient	20225	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.226.70
TunnelIpv6Address = None
Dial-in User = .
Information	12/2/2017 8:41:55 PM	RasClient	20224	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	12/2/2017 8:41:55 PM	RasClient	20223	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 8:41:55 PM	RasClient	20222	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 8:41:55 PM	RasClient	20221	None	CoId={59D3203E-C52A-4B2E-B702-4D32F12F03C7}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	12/2/2017 8:40:36 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: f5fpapi.dll, version: 7132.2017.404.2206, time stamp: 0x58e419a1
Exception code: 0x40000015
Fault offset: 0x000dfbae
Faulting process id: 0x1ca4
Faulting application start time: 0x01d36b3961af58d5
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: C:\Program Files (x86)\F5 VPN\f5fpapi.dll
Report Id: f2d120e1-d772-11e7-af08-204747d02364"
Information	12/2/2017 6:44:18 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	12/2/2017 6:30:17 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/2/2017 6:30:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	12/2/2017 6:30:06 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	12/2/2017 6:30:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Error	12/2/2017 6:28:34 PM	RasClient	20227	None	CoId={73887CE8-B5C2-4120-BBC5-F432655B1356}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 628.
Information	12/2/2017 6:27:57 PM	RasClient	20224	None	CoId={73887CE8-B5C2-4120-BBC5-F432655B1356}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	12/2/2017 6:27:57 PM	RasClient	20223	None	CoId={73887CE8-B5C2-4120-BBC5-F432655B1356}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 6:27:57 PM	RasClient	20222	None	CoId={73887CE8-B5C2-4120-BBC5-F432655B1356}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 6:27:57 PM	RasClient	20221	None	CoId={73887CE8-B5C2-4120-BBC5-F432655B1356}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	12/2/2017 6:27:48 PM	RasClient	20226	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	12/2/2017 6:15:58 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/2/2017 6:04:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	12/2/2017 6:03:49 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	12/2/2017 5:29:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/2/2017 4:50:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 4:50:37 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:36Z. Reason: GVLK.
Information	12/2/2017 4:46:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	12/2/2017 4:46:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2017 4:45:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2017 4:45:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 4:45:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 4:45:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 4:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28874)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 4:38:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 4:38:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 4:38:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 4:29:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9c9269d-d74f-11e7-af08-204747d02364
Report Status: 0"
Information	12/2/2017 3:14:52 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	12/2/2017 3:14:47 PM	ESENT	102	General	Windows (13360) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/2/2017 3:09:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15632.
Information	12/2/2017 3:09:55 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20050. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	12/2/2017 3:09:55 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	12/2/2017 3:09:55 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20050. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.009.20050). Installation success or error status: 0.
Information	12/2/2017 3:09:55 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.009.20050)' installed successfully.
Information	12/2/2017 3:09:43 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	12/2/2017 3:09:43 PM	ESENT	103	General	Windows (1516) Windows: The database engine stopped the instance (0).
Information	12/2/2017 3:09:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 15632.
Information	12/2/2017 3:09:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6592.
Information	12/2/2017 3:09:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20050. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	12/2/2017 3:09:30 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	12/2/2017 3:09:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6592.
Warning	12/2/2017 3:07:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/2/2017 2:15:55 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/2/2017 1:34:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 1:29:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	12/2/2017 1:29:16 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	12/2/2017 1:28:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/2/2017 1:28:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29066)(?)])(1 )(2 )]

"
Information	12/2/2017 1:28:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29066)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 1:28:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 1:28:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 1:28:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/2/2017 1:14:55 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/2/2017 12:47:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 12:42:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29113)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 12:40:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 12:40:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 12:40:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 12:27:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8732.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/2/2017 12:22:49 PM	RasClient	20225	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.224.46
TunnelIpv6Address = None
Dial-in User = .
Information	12/2/2017 12:22:44 PM	RasClient	20224	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	12/2/2017 12:22:44 PM	RasClient	20223	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 12:22:44 PM	RasClient	20222	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	12/2/2017 12:22:44 PM	RasClient	20221	None	CoId={A72FAAF6-039D-4958-BB1A-FCDF8CE9E6F1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	12/2/2017 12:16:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/2/2017 12:16:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/2/2017 12:15:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/2/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]

"
Information	12/2/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 11:45:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 11:40:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 11:40:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 11:40:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 11:33:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 11:33:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:54Z. Reason: GVLK.
Information	12/2/2017 11:31:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/2/2017 11:28:08 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	12/2/2017 11:27:01 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/2/2017 11:26:59 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/2/2017 11:26:56 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/2/2017 11:26:54 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Error	12/2/2017 11:26:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	12/2/2017 11:26:41 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {514F3F36-773F-45AD-9F38-33FFF45DE2B6}
Error	12/2/2017 11:26:41 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {514F3F36-773F-45AD-9F38-33FFF45DE2B6}
Information	12/2/2017 11:26:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/2/2017 11:26:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 11:26:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 11:26:21 AM	ESENT	302	Logging/Recovery	Windows (1516) Windows: The database engine has successfully completed recovery steps.
Information	12/2/2017 11:26:16 AM	ESENT	301	Logging/Recovery	Windows (1516) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	12/2/2017 11:26:16 AM	ESENT	300	Logging/Recovery	Windows (1516) Windows: The database engine is initiating recovery steps.
Information	12/2/2017 11:26:16 AM	ESENT	102	General	Windows (1516) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	12/2/2017 11:26:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 11:26:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/2/2017 11:26:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29189)(?)])(1 )(2 )]

"
Information	12/2/2017 11:26:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29189)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/2/2017 11:26:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/2/2017 11:26:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/2/2017 11:26:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	12/2/2017 11:26:05 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8731.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/2/2017 11:25:41 AM	Service1	0	None	Service started successfully.
Error	12/2/2017 11:25:37 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	12/2/2017 11:25:37 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	12/2/2017 11:25:06 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	12/2/2017 11:24:57 AM	PostgreSQL	0	None	Server started and accepting connections

Information	12/2/2017 11:24:54 AM	PostgreSQL	0	None	"2017-12-02 11:24:54 IST LOG:  redirecting log output to logging collector process
2017-12-02 11:24:54 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	12/2/2017 11:24:53 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	12/2/2017 11:24:52 AM	PostgreSQL	0	None	Waiting for server startup...

Information	12/2/2017 11:24:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	12/2/2017 11:24:45 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	12/2/2017 11:24:45 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	12/2/2017 11:24:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	12/2/2017 11:24:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	12/2/2017 11:24:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:41 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	12/2/2017 11:24:40 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	12/2/2017 11:24:39 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	12/2/2017 11:24:37 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3672 at 12/1/2017 9:08:56 PM (local) 12/1/2017 3:38:56 PM (UTC). This is an informational message only; no user action is required.
Information	12/2/2017 11:24:36 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	12/2/2017 11:24:34 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	12/2/2017 11:24:33 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	12/2/2017 11:24:33 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	12/2/2017 11:24:33 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	12/2/2017 11:24:33 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3680.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	12/2/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	12/2/2017 11:24:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	12/2/2017 11:24:00 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	12/2/2017 11:23:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	12/2/2017 11:23:47 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	12/2/2017 11:23:48 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	12/1/2017 9:09:26 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	12/1/2017 9:08:58 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	12/1/2017 9:08:56 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	12/1/2017 9:08:50 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1000 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1000 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1000 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1000 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1000 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2028 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	12/1/2017 9:08:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	12/1/2017 9:08:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	12/1/2017 9:08:47 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	12/1/2017 9:08:38 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	12/1/2017 8:30:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 8:24:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9327eba3-d6a7-11e7-a349-204747d02364
Report Status: 0"
Warning	12/1/2017 6:43:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 6:33:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 6:32:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	12/1/2017 4:47:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	12/1/2017 4:18:54 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/1/2017 3:24:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a7837145-d67d-11e7-a349-204747d02364
Report Status: 0"
Warning	12/1/2017 2:50:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 2:33:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 2:32:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 2:20:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 2:15:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/1/2017 2:15:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30459)(?)])(1 )(2 )]

"
Information	12/1/2017 2:15:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30459)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 2:15:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/1/2017 2:15:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 2:15:34 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/1/2017 1:14:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 12:29:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8731.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	12/1/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	12/1/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30585)(?)])(1 )(2 )]

"
Information	12/1/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/1/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/1/2017 11:43:13 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 10:48:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	12/1/2017 10:47:40 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	12/1/2017 10:37:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 10:37:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:57Z. Reason: GVLK.
Information	12/1/2017 10:32:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 10:32:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2017 10:32:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 10:32:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 10:32:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2017 10:32:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 10:24:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b99ad0d1-d653-11e7-a349-204747d02364
Report Status: 0"
Warning	12/1/2017 9:43:05 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 9:26:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	12/1/2017 7:52:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 6:32:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 6:32:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 6:23:05 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 6:18:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	12/1/2017 6:18:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 6:18:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	12/1/2017 6:03:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 5:24:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cf4e3c68-d629-11e7-a349-204747d02364
Report Status: 0"
Warning	12/1/2017 4:20:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 4:18:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 4:18:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:53Z. Reason: GVLK.
Information	12/1/2017 4:13:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2017 4:13:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 4:13:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 4:13:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2017 4:13:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8fd00ed-d61f-11e7-a349-204747d02364
Report Status: 0"
Information	12/1/2017 4:13:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8fd00ec-d61f-11e7-a349-204747d02364
Report Status: 0"
Information	12/1/2017 4:13:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d8fd00eb-d61f-11e7-a349-204747d02364
Report Status: 0"
Error	12/1/2017 4:10:15 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	12/1/2017 4:02:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 4:02:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:27Z. Reason: GVLK.
Error	12/1/2017 3:57:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	12/1/2017 3:57:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2017 3:57:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 3:57:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 3:57:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	12/1/2017 2:44:31 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 2:32:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	12/1/2017 2:31:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	12/1/2017 12:59:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	12/1/2017 12:24:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e46d6ce6-d5ff-11e7-a349-204747d02364
Report Status: 0"
Information	12/1/2017 12:13:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	12/1/2017 12:13:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:22Z. Reason: GVLK.
Information	12/1/2017 12:08:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	12/1/2017 12:08:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	12/1/2017 12:08:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	12/1/2017 12:08:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	12/1/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/30/2017 11:19:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 10:32:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2017 10:31:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/30/2017 9:38:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 8:38:06 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/30/2017 8:37:15 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/30/2017 7:46:29 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 7:24:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fa5d3ff7-d5d5-11e7-a349-204747d02364
Report Status: 0"
Information	11/30/2017 6:31:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/30/2017 6:08:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/30/2017 4:35:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/30/2017 3:44:14 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	11/30/2017 2:50:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 2:31:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2017 2:24:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e7efa89-d5ac-11e7-a349-204747d02364
Report Status: 0"
Information	11/30/2017 2:16:55 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8730.0000.
Information	11/30/2017 2:06:42 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/30/2017 1:04:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32025)(?)])(1 )(2 )]

"
Information	11/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32025)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/30/2017 11:15:35 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/30/2017 10:40:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 10:32:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 41, Deleted: 0, Modified: 19, Compared: 15229, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/30/2017 10:31:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2017 10:31:17 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/30/2017 10:31:15 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	11/30/2017 10:31:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/30/2017 10:30:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/30/2017 10:30:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32124)(?)])(1 )(2 )]

"
Information	11/30/2017 10:30:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32124)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2017 10:30:38 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2017 10:30:38 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 10:30:37 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 10:24:18 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8730.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/30/2017 10:10:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 10:05:50 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2017 10:05:50 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 10:05:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 9:55:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 9:55:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:45:12Z. Reason: GVLK.
Information	11/30/2017 9:50:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2017 9:50:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2017 9:50:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 9:50:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 9:49:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: acd6e02e-d585-11e7-a349-204747d02364
Report Status: 0"
Information	11/30/2017 9:49:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: acd6e02d-d585-11e7-a349-204747d02364
Report Status: 0"
Information	11/30/2017 9:49:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: acd6e02c-d585-11e7-a349-204747d02364
Report Status: 0"
Error	11/30/2017 9:46:41 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/30/2017 9:40:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 9:37:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/30/2017 9:37:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:43Z. Reason: GVLK.
Information	11/30/2017 9:35:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2017 9:35:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 9:35:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 9:28:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/30/2017 9:28:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	11/30/2017 9:23:47 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {D3BF2FD5-B751-409F-AFED-03B85865A8B4}
Error	11/30/2017 9:23:47 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {D3BF2FD5-B751-409F-AFED-03B85865A8B4}
Error	11/30/2017 9:23:45 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/30/2017 9:23:22 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	11/30/2017 9:23:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/30/2017 9:23:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32191)(?)])(1 )(2 )]

"
Information	11/30/2017 9:23:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32191)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2017 9:23:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/30/2017 9:23:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 9:23:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 9:23:13 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/30/2017 9:22:41 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/30/2017 9:22:40 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/30/2017 9:22:39 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/30/2017 9:22:37 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/30/2017 9:21:38 AM	ESENT	302	Logging/Recovery	Windows (4688) Windows: The database engine has successfully completed recovery steps.
Information	11/30/2017 9:21:38 AM	ESENT	301	Logging/Recovery	Windows (4688) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/30/2017 9:21:27 AM	ESENT	301	Logging/Recovery	Windows (4688) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0561C.log.
Information	11/30/2017 9:21:27 AM	ESENT	300	Logging/Recovery	Windows (4688) Windows: The database engine is initiating recovery steps.
Information	11/30/2017 9:21:27 AM	ESENT	102	General	Windows (4688) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/30/2017 9:21:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/30/2017 9:21:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/30/2017 9:21:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/30/2017 9:20:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/30/2017 9:20:48 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8729.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/30/2017 9:20:26 AM	Service1	0	None	Service started successfully.
Error	11/30/2017 9:20:22 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/30/2017 9:20:22 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/30/2017 9:20:17 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/30/2017 9:20:02 AM	PostgreSQL	0	None	"2017-11-30 09:20:02 IST LOG:  redirecting log output to logging collector process
2017-11-30 09:20:02 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/30/2017 9:20:00 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	11/30/2017 9:19:59 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/30/2017 9:19:56 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/30/2017 9:19:55 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/30/2017 9:19:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/30/2017 9:19:55 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/30/2017 9:19:55 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/30/2017 9:19:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/30/2017 9:19:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/30/2017 9:19:50 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:50 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/30/2017 9:19:50 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/30/2017 9:19:50 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/30/2017 9:19:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/30/2017 9:19:49 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/30/2017 9:19:48 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/30/2017 9:19:47 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:47 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:47 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3628 at 11/27/2017 8:47:01 PM (local) 11/27/2017 3:17:01 PM (UTC). This is an informational message only; no user action is required.
Information	11/30/2017 9:19:44 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/30/2017 9:19:41 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/30/2017 9:19:41 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/30/2017 9:19:41 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/30/2017 9:19:41 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/30/2017 9:19:41 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3672.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/30/2017 9:19:40 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/30/2017 9:18:59 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/30/2017 9:18:49 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/30/2017 9:18:34 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/30/2017 9:18:34 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/30/2017 9:18:34 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/29/2017 7:24:23 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/29/2017 7:24:23 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/29/2017 7:23:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/29/2017 7:23:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/29/2017 7:16:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/29/2017 7:11:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/29/2017 7:11:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2017 7:11:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/29/2017 7:03:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2017 6:01:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2017 5:11:27 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/29/2017 4:33:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/29/2017 3:53:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/29/2017 3:53:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:56Z. Reason: GVLK.
Information	11/29/2017 3:48:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/29/2017 3:48:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2017 3:48:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2017 3:48:52 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/29/2017 3:17:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2017 3:14:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d44a7b85-d4e9-11e7-8a26-9aac01396ad0
Report Status: 0"
Information	11/29/2017 2:01:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2017 1:25:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2017 12:53:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎11‎-‎29T07:23:25.649998200Z.
Information	11/29/2017 12:53:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎11‎-‎29T07:23:25.649998200Z.
Information	11/29/2017 12:40:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎11‎-‎29T07:10:17.518892500Z.
Information	11/29/2017 12:40:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎11‎-‎29T07:10:17.518892500Z.
Information	11/29/2017 12:40:17 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎11‎-‎29T07:10:17.370877700Z.
Information	11/29/2017 12:40:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎11‎-‎29T07:10:17.370877700Z.
Information	11/29/2017 12:40:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎11‎-‎29T07:10:16.630803700Z.
Information	11/29/2017 12:40:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎11‎-‎29T07:10:16.630803700Z.
Information	11/29/2017 12:40:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎11‎-‎29T07:10:14.530593700Z.
Information	11/29/2017 12:40:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎11‎-‎29T07:10:14.530593700Z.
Information	11/29/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/29/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/29/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]

"
Information	11/29/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/29/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/29/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/29/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/29/2017 11:47:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2017 11:44:33 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 16004, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/29/2017 11:43:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/29/2017 10:32:49 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8729.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/29/2017 10:14:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 09e8f128-d4c0-11e7-8a26-9aac01396ad0
Report Status: 0"
Warning	11/29/2017 10:03:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/29/2017 10:01:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/29/2017 10:01:14 AM	ESENT	508	Performance	"wuaueng.dll (1184) SUS20ClientDataStore: A request to write to the file ""C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log"" at offset 16384 (0x0000000000004000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (45513 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem."
Information	11/28/2017 9:19:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/28/2017 9:14:57 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/28/2017 9:14:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/28/2017 9:14:37 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	11/28/2017 7:48:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2017 7:29:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c86b5f0-d444-11e7-8a26-9aac01396ad0
Report Status: 0"
Warning	11/28/2017 6:14:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2017 5:19:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/28/2017 4:41:20 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/28/2017 3:01:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/28/2017 2:58:25 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/28/2017 2:28:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5e37c5a8-d41a-11e7-8a26-9aac01396ad0
Report Status: 0"
Information	11/28/2017 2:21:00 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/28/2017 1:19:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/28/2017 1:08:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]

"
Information	11/28/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2017 12:09:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/28/2017 11:11:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2017 10:31:05 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 10:25:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/28/2017 10:25:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35009)(?)])(1 )(2 )]

"
Information	11/28/2017 10:25:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35009)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2017 10:25:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2017 10:25:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2017 10:25:52 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	11/28/2017 10:25:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	11/28/2017 10:25:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/28/2017 10:24:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 10:20:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 10:20:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-12-05T04:44:20Z. Reason: GVLK.
Information	11/28/2017 10:19:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2017 10:19:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2017 10:19:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/28/2017 10:15:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2017 10:15:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2017 10:15:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/11/28 04:45"
Information	11/28/2017 10:15:18 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/11/28 04:45, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/28/2017 10:10:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/28/2017 10:10:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/28/2017 10:10:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2017 10:10:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/28/2017 9:54:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 9:49:33 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8728.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/28/2017 9:49:07 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/28/2017 9:49:07 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/28/2017 9:49:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/28/2017 9:28:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 73b11393-d3f0-11e7-8a26-9aac01396ad0
Report Status: 0"
Information	11/28/2017 9:24:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/28/2017 9:21:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/28/2017 9:20:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/28/2017 9:20:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:15Z. Reason: GVLK.
Information	11/28/2017 9:19:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2017 8:51:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 8:51:38 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 3042

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	11/27/2017 8:50:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2017 8:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 8:50:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35824)(?)])(1 )(2 )]

"
Information	11/27/2017 8:50:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35824)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 8:49:31 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/27/2017 8:48:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8727.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	11/27/2017 8:48:48 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E2E58B6A-D415-4A46-96BB-1705FA19FD6D}
Error	11/27/2017 8:48:48 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E2E58B6A-D415-4A46-96BB-1705FA19FD6D}
Error	11/27/2017 8:48:44 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/27/2017 8:48:38 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 8:48:38 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 8:48:37 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 8:48:36 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/27/2017 8:48:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 8:48:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35826)(?)])(1 )(2 )]

"
Information	11/27/2017 8:48:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35826)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 8:48:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 8:48:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 8:48:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 8:47:46 PM	ESENT	302	Logging/Recovery	Windows (7484) Windows: The database engine has successfully completed recovery steps.
Information	11/27/2017 8:47:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2017 8:47:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 8:47:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 8:47:41 PM	ESENT	301	Logging/Recovery	Windows (7484) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/27/2017 8:47:40 PM	ESENT	300	Logging/Recovery	Windows (7484) Windows: The database engine is initiating recovery steps.
Information	11/27/2017 8:47:40 PM	ESENT	102	General	Windows (7484) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/27/2017 8:47:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 8:47:23 PM	Service1	0	None	Service started successfully.
Error	11/27/2017 8:47:19 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/27/2017 8:47:19 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/27/2017 8:47:17 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/27/2017 8:47:17 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/27/2017 8:47:17 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/27/2017 8:47:17 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/27/2017 8:47:17 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/27/2017 8:47:15 PM	PostgreSQL	0	None	Server started and accepting connections

Information	11/27/2017 8:47:07 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/27/2017 8:47:07 PM	PostgreSQL	0	None	"2017-11-27 20:47:07 IST LOG:  redirecting log output to logging collector process
2017-11-27 20:47:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/27/2017 8:47:06 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	11/27/2017 8:47:06 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/27/2017 8:47:06 PM	PostgreSQL	0	None	Waiting for server startup...

Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/27/2017 8:47:04 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/27/2017 8:47:03 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/27/2017 8:47:01 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3904 at 11/27/2017 9:38:09 AM (local) 11/27/2017 4:08:09 AM (UTC). This is an informational message only; no user action is required.
Information	11/27/2017 8:47:00 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3628.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/27/2017 8:46:59 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/27/2017 8:46:58 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/27/2017 8:46:47 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/27/2017 8:46:43 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 8:46:24 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/27/2017 8:46:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/27/2017 8:46:24 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Warning	11/27/2017 8:39:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 8:35:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 8:30:44 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 702

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 468

Information	11/27/2017 8:30:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2017 8:30:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 8:30:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35845)(?)])(1 )(2 )]

"
Information	11/27/2017 8:29:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35845)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 8:29:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 8:29:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 8:29:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 7:41:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e5f0dff8-d37c-11e7-a2fa-204747d02364
Report Status: 0"
Information	11/27/2017 6:59:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 6:54:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 6:54:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35941)(?)])(1 )(2 )]

"
Information	11/27/2017 6:54:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35941)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 6:54:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 6:54:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 6:54:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/27/2017 6:52:39 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 6:23:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/27/2017 5:12:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/27/2017 3:17:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 2:41:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f98a5eaa-d352-11e7-a2fa-204747d02364
Report Status: 0"
Information	11/27/2017 2:23:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	11/27/2017 2:15:33 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	11/27/2017 1:34:24 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 12:55:20 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8727.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	11/27/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]

"
Information	11/27/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/27/2017 11:35:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/27/2017 10:58:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 10:53:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 10:53:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 10:53:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 10:29:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 10:23:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36451)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 10:23:12 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 250

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 78

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 312

Information	11/27/2017 10:23:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/27/2017 10:22:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 10:22:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36452)(?)])(1 )(2 )]

"
Information	11/27/2017 10:22:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36452)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 10:21:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 10:21:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:25Z. Reason: GVLK.
Information	11/27/2017 10:19:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 10:19:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36455)(?)])(1 )(2 )]

"
Information	11/27/2017 10:19:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36455)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 10:19:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 10:19:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 10:19:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 10:19:16 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 1341

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	11/27/2017 10:16:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f9e35407-d32d-11e7-a2fa-204747d02364
Report Status: 0"
Information	11/27/2017 10:16:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2017 10:16:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 10:16:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 10:16:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 10:16:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de9dd268-d32d-11e7-a2fa-204747d02364
Report Status: 0"
Information	11/27/2017 10:16:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de9dd267-d32d-11e7-a2fa-204747d02364
Report Status: 0"
Error	11/27/2017 10:03:28 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/27/2017 9:58:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 9:54:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 9:54:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:21Z. Reason: GVLK.
Information	11/27/2017 9:53:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 9:53:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 9:53:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 9:50:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 9:49:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2017 9:49:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 9:49:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 9:49:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 9:46:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/27/2017 9:46:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:49Z. Reason: GVLK.
Information	11/27/2017 9:45:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 9:45:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36489)(?)])(1 )(2 )]

"
Information	11/27/2017 9:45:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36489)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Error	11/27/2017 9:42:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/27/2017 9:40:42 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/27/2017 9:40:34 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8726.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
W97M/Dropper (ED)
"
Error	11/27/2017 9:40:20 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DC2615F0-DBDD-4850-9AAF-B3C66BB9B7EA}
Error	11/27/2017 9:40:20 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DC2615F0-DBDD-4850-9AAF-B3C66BB9B7EA}
Error	11/27/2017 9:40:13 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/27/2017 9:40:01 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 9:40:00 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 9:39:59 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 9:39:56 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/27/2017 9:39:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/27/2017 9:39:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36495)(?)])(1 )(2 )]

"
Information	11/27/2017 9:39:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36495)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 9:39:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/27/2017 9:39:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/27/2017 9:39:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 9:39:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/27/2017 9:39:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/27/2017 9:39:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Error	11/27/2017 9:39:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/27/2017 9:39:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/27/2017 9:38:53 AM	ESENT	302	Logging/Recovery	Windows (6736) Windows: The database engine has successfully completed recovery steps.
Information	11/27/2017 9:38:43 AM	ESENT	301	Logging/Recovery	Windows (6736) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/27/2017 9:38:43 AM	ESENT	300	Logging/Recovery	Windows (6736) Windows: The database engine is initiating recovery steps.
Information	11/27/2017 9:38:43 AM	ESENT	102	General	Windows (6736) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/27/2017 9:38:36 AM	Service1	0	None	Service started successfully.
Error	11/27/2017 9:38:28 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/27/2017 9:38:22 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/27/2017 9:38:22 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/27/2017 9:38:21 AM	PostgreSQL	0	None	"2017-11-27 09:38:21 IST LOG:  redirecting log output to logging collector process
2017-11-27 09:38:21 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/27/2017 9:38:20 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/27/2017 9:38:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/27/2017 9:38:19 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/27/2017 9:38:19 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/27/2017 9:38:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/27/2017 9:38:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/27/2017 9:38:18 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/27/2017 9:38:17 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/27/2017 9:38:13 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:13 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/27/2017 9:38:13 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/27/2017 9:38:13 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/27/2017 9:38:12 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/27/2017 9:38:11 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3848 at 11/26/2017 11:26:25 PM (local) 11/26/2017 5:56:25 PM (UTC). This is an informational message only; no user action is required.
Information	11/27/2017 9:38:09 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/27/2017 9:38:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/27/2017 9:38:08 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/27/2017 9:38:08 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/27/2017 9:38:08 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/27/2017 9:38:08 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3904.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/27/2017 9:38:07 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/27/2017 9:37:46 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/27/2017 9:37:41 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/27/2017 9:37:29 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/27/2017 9:37:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/27/2017 9:37:29 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/26/2017 11:26:35 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	11/26/2017 11:26:25 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/26/2017 11:26:21 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 936 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 936 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 936 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 936 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 936 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/26/2017 11:26:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/26/2017 11:26:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/26/2017 11:26:20 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/26/2017 11:26:15 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Error	11/26/2017 11:25:01 PM	RasClient	20227	None	CoId={FD9952EF-4415-40F9-B35C-15D0B8AAB1B1}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:25:00 PM	RasClient	20222	None	CoId={FD9952EF-4415-40F9-B35C-15D0B8AAB1B1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:25:00 PM	RasClient	20221	None	CoId={FD9952EF-4415-40F9-B35C-15D0B8AAB1B1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:59 PM	RasClient	20227	None	CoId={8DFDBAB5-F102-48E8-9993-8A8E23C795D0}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:58 PM	RasClient	20222	None	CoId={8DFDBAB5-F102-48E8-9993-8A8E23C795D0}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:58 PM	RasClient	20221	None	CoId={8DFDBAB5-F102-48E8-9993-8A8E23C795D0}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:58 PM	RasClient	20227	None	CoId={A3BA3576-D688-44E4-9F6C-745ABA3C8AF8}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:57 PM	RasClient	20222	None	CoId={A3BA3576-D688-44E4-9F6C-745ABA3C8AF8}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:57 PM	RasClient	20221	None	CoId={A3BA3576-D688-44E4-9F6C-745ABA3C8AF8}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:56 PM	RasClient	20227	None	CoId={EF58DA5B-B55E-43BF-9C22-3DC3081FDB0C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:55 PM	RasClient	20222	None	CoId={EF58DA5B-B55E-43BF-9C22-3DC3081FDB0C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:55 PM	RasClient	20221	None	CoId={EF58DA5B-B55E-43BF-9C22-3DC3081FDB0C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:55 PM	RasClient	20227	None	CoId={9E51A178-A9DD-460B-BEAE-29D16D0E200C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:54 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	11/26/2017 11:24:54 PM	RasClient	20222	None	CoId={9E51A178-A9DD-460B-BEAE-29D16D0E200C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:54 PM	RasClient	20221	None	CoId={9E51A178-A9DD-460B-BEAE-29D16D0E200C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:53 PM	RasClient	20227	None	CoId={BDC6B32B-F5CB-486B-8D63-719372D563B3}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:52 PM	RasClient	20222	None	CoId={BDC6B32B-F5CB-486B-8D63-719372D563B3}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:52 PM	RasClient	20221	None	CoId={BDC6B32B-F5CB-486B-8D63-719372D563B3}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:52 PM	RasClient	20227	None	CoId={1D37011C-EF55-4CCD-8B11-74187876C534}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:51 PM	RasClient	20222	None	CoId={1D37011C-EF55-4CCD-8B11-74187876C534}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:51 PM	RasClient	20221	None	CoId={1D37011C-EF55-4CCD-8B11-74187876C534}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:50 PM	RasClient	20227	None	CoId={FA162697-C767-4939-91FC-07847F6A1A2C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:49 PM	RasClient	20222	None	CoId={FA162697-C767-4939-91FC-07847F6A1A2C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:49 PM	RasClient	20221	None	CoId={FA162697-C767-4939-91FC-07847F6A1A2C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:48 PM	RasClient	20227	None	CoId={B52D45C3-12A3-44FF-8B20-BDF695DA429C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:47 PM	RasClient	20222	None	CoId={B52D45C3-12A3-44FF-8B20-BDF695DA429C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:47 PM	RasClient	20221	None	CoId={B52D45C3-12A3-44FF-8B20-BDF695DA429C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	11/26/2017 11:24:47 PM	RasClient	20227	None	CoId={B7DAC66E-1683-4CF8-B7BC-9CBBE7B0F053}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 651.
Information	11/26/2017 11:24:46 PM	RasClient	20222	None	CoId={B7DAC66E-1683-4CF8-B7BC-9CBBE7B0F053}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 11:24:46 PM	RasClient	20221	None	CoId={B7DAC66E-1683-4CF8-B7BC-9CBBE7B0F053}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	11/26/2017 11:24:44 PM	RasClient	20226	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Warning	11/26/2017 10:58:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2017 9:10:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/26/2017 9:07:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/26/2017 9:05:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/26/2017 9:05:53 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/26/2017 9:05:50 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	11/26/2017 9:04:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2017 9:04:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37250)(?)])(1 )(2 )]

"
Information	11/26/2017 9:04:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37250)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2017 9:04:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2017 9:04:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2017 9:04:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2017 9:04:19 PM	RasClient	20225	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.254.199
TunnelIpv6Address = None
Dial-in User = .
Information	11/26/2017 9:04:14 PM	RasClient	20224	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	11/26/2017 9:04:14 PM	RasClient	20223	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 9:04:14 PM	RasClient	20222	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/26/2017 9:04:14 PM	RasClient	20221	None	CoId={6D662C9B-4048-40E1-B5F5-394CC9001289}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	11/26/2017 9:02:26 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/26/2017 8:54:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/26/2017 7:04:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7543873d-d2ae-11e7-b14d-204747d02364
Report Status: 0"
Information	11/26/2017 6:42:06 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/26/2017 6:42:04 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/26/2017 6:42:04 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/26/2017 6:13:04 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/26/2017 6:13:04 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/26/2017 6:13:04 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/26/2017 4:54:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/26/2017 2:03:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8aa2f9e9-d284-11e7-b14d-204747d02364
Report Status: 0"
Information	11/26/2017 2:01:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/26/2017 2:01:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:10Z. Reason: GVLK.
Information	11/26/2017 1:56:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/26/2017 1:56:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2017 1:56:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2017 1:56:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/26/2017 12:54:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/26/2017 12:45:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8726.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
W97M/Dropper (ED)
"
Information	11/26/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]

"
Information	11/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/26/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2017 11:52:39 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/26/2017 11:37:22 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 14404 did not respond and is being forcibly terminated {filter host process 3284}. 

Information	11/26/2017 11:31:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 2, Compared: 15690, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/26/2017 11:30:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/26/2017 9:03:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9feacf47-d25a-11e7-b14d-204747d02364
Report Status: 0"
Information	11/26/2017 8:59:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/26/2017 8:54:06 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/26/2017 8:54:06 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/26/2017 8:54:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/26/2017 8:53:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/26/2017 12:40:51 AM	RasClient	20226	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	11/25/2017 11:52:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e5382ef-d20d-11e7-b14d-204747d02364
Report Status: 0"
Information	11/25/2017 11:37:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/25/2017 11:36:02 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/25/2017 10:22:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 05566c6d-d201-11e7-b14d-204747d02364
Report Status: 0"
Warning	11/25/2017 9:38:22 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/25/2017 8:30:23 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/25/2017 8:29:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Warning	11/25/2017 8:04:49 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/25/2017 7:37:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/25/2017 7:26:58 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/25/2017 6:52:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b195153c-d1e3-11e7-b14d-204747d02364
Report Status: 0"
Warning	11/25/2017 6:32:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/25/2017 5:32:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 5:27:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 5:27:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 5:27:02 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 3:46:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 3:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/25/2017 3:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39014)(?)])(1 )(2 )]

"
Information	11/25/2017 3:41:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39014)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 3:36:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/25/2017 3:36:57 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 46

Warning	11/25/2017 3:36:57 PM	Outlook	59	None	Outlook disabled the following add-in(s):



ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
Load Behavior: 3
HKLM: 1
Location: c:\program files (x86)\microsoft office\root\office16\onbttnol.dll
Threshold Time (Milliseconds): 1000
Time Taken (Milliseconds): 1357
Disable Reason: This add-in caused Outlook to start slowly.
Policy Exception (Allow List): 0 
Information	11/25/2017 3:35:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/25/2017 3:35:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39019)(?)])(1 )(2 )]

"
Information	11/25/2017 3:35:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39019)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 3:35:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 3:35:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 3:35:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 3:06:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 3:01:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 3:01:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 3:01:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/25/2017 2:53:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/25/2017 2:36:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 2:31:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 2:31:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 2:31:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 2:29:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8725.0000
 
 Number of signatures in EXTRA.DAT : 2
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
W97M/Dropper (ED)
"
Information	11/25/2017 2:28:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 2:28:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:19Z. Reason: GVLK.
Information	11/25/2017 2:23:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/25/2017 2:23:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 2:23:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 2:23:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 2:22:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6924f8a-d1bd-11e7-b14d-204747d02364
Report Status: 0"
Information	11/25/2017 2:22:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6924f89-d1bd-11e7-b14d-204747d02364
Report Status: 0"
Information	11/25/2017 2:22:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6924f88-d1bd-11e7-b14d-204747d02364
Report Status: 0"
Error	11/25/2017 2:17:34 PM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/25/2017 2:13:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/25/2017 2:11:47 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/25/2017 2:07:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 2:07:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/25/2017 2:07:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39107)(?)])(1 )(2 )]

"
Information	11/25/2017 2:07:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39107)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 2:07:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 2:07:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 2:07:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 2:06:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 2:02:13 PM	RasClient	20225	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.235.103
TunnelIpv6Address = None
Dial-in User = .
Information	11/25/2017 2:02:08 PM	RasClient	20224	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	11/25/2017 2:02:08 PM	RasClient	20223	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/25/2017 2:02:08 PM	RasClient	20222	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	11/25/2017 2:02:08 PM	RasClient	20221	None	CoId={AFCE3609-944B-4FDE-95FB-45DD952E6102}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	11/25/2017 2:01:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 2:01:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 2:01:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 2:00:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 1:59:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 1:59:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:41Z. Reason: GVLK.
Information	11/25/2017 1:56:47 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8724.0000.
Error	11/25/2017 1:55:26 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/25/2017 1:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/25/2017 1:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39120)(?)])(1 )(2 )]

"
Information	11/25/2017 1:55:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39120)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 1:55:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 1:55:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 1:55:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 1:53:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/25/2017 1:52:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3f19ab9-d1b9-11e7-b14d-204747d02364
Report Status: 0"
Information	11/25/2017 1:49:17 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/25/2017 1:48:17 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/25/2017 1:48:16 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	11/25/2017 1:48:12 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E89B4ED5-8D8C-4B61-A6B1-9BE0B770FD8D}
Error	11/25/2017 1:48:12 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {E89B4ED5-8D8C-4B61-A6B1-9BE0B770FD8D}
Information	11/25/2017 1:48:11 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	11/25/2017 1:48:09 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/25/2017 1:48:06 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/25/2017 1:47:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/25/2017 1:47:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 1:47:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 1:47:29 PM	ESENT	302	Logging/Recovery	Windows (7816) Windows: The database engine has successfully completed recovery steps.
Information	11/25/2017 1:47:26 PM	ESENT	301	Logging/Recovery	Windows (7816) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/25/2017 1:47:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 1:47:22 PM	ESENT	301	Logging/Recovery	Windows (7816) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05601.log.
Information	11/25/2017 1:47:22 PM	ESENT	300	Logging/Recovery	Windows (7816) Windows: The database engine is initiating recovery steps.
Information	11/25/2017 1:47:22 PM	ESENT	102	General	Windows (7816) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/25/2017 1:47:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/25/2017 1:47:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39127)(?)])(1 )(2 )]

"
Information	11/25/2017 1:47:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39127)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/25/2017 1:47:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/25/2017 1:47:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/25/2017 1:47:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/25/2017 1:47:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8724.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/25/2017 1:46:28 PM	Service1	0	None	Service started successfully.
Error	11/25/2017 1:46:13 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/25/2017 1:46:10 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/25/2017 1:45:51 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/25/2017 1:45:45 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:45 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/25/2017 1:45:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/25/2017 1:45:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/25/2017 1:45:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/25/2017 1:45:44 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/25/2017 1:45:43 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:42 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/25/2017 1:45:41 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/25/2017 1:45:41 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/25/2017 1:45:41 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/25/2017 1:45:41 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/25/2017 1:45:38 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:38 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:38 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/25/2017 1:45:37 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3664 at 11/24/2017 9:16:33 PM (local) 11/24/2017 3:46:33 PM (UTC). This is an informational message only; no user action is required.
Information	11/25/2017 1:45:33 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/25/2017 1:45:32 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/25/2017 1:45:32 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/25/2017 1:45:32 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/25/2017 1:45:32 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/25/2017 1:45:27 PM	PostgreSQL	0	None	Server started and accepting connections

Information	11/25/2017 1:45:26 PM	PostgreSQL	0	None	"2017-11-25 13:45:26 IST LOG:  redirecting log output to logging collector process
2017-11-25 13:45:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/25/2017 1:45:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/25/2017 1:45:24 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/25/2017 1:45:24 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/25/2017 1:45:23 PM	PostgreSQL	0	None	Waiting for server startup...

Information	11/25/2017 1:45:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/25/2017 1:45:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3848.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/25/2017 1:45:02 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/25/2017 1:44:31 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/25/2017 1:44:26 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/25/2017 1:44:08 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/25/2017 1:44:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/25/2017 1:44:08 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/24/2017 9:16:42 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	11/24/2017 9:16:33 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/24/2017 9:16:10 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 996 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/24/2017 9:16:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/24/2017 9:16:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/24/2017 9:16:07 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/24/2017 9:15:44 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Warning	11/24/2017 7:43:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 7:41:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61e02db7-d121-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/24/2017 6:34:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 6:34:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/24/2017 5:44:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/24/2017 4:13:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 2:41:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 77cd10c1-d0f7-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/24/2017 2:34:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 2:34:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/24/2017 2:31:08 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 12:48:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8724.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Warning	11/24/2017 12:40:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/24/2017 12:11:34 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/24/2017 12:09:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/24/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40665)(?)])(1 )(2 )]

"
Information	11/24/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40665)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/24/2017 12:09:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/24/2017 12:09:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 12:09:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/24/2017 11:06:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/24/2017 11:06:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:15Z. Reason: GVLK.
Information	11/24/2017 11:01:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/24/2017 11:01:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/24/2017 11:01:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 11:01:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/24/2017 10:54:02 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 10:40:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/24/2017 10:34:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 10:34:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 10:30:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/24/2017 10:30:11 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/24/2017 9:41:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8cb90c24-d0cd-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/24/2017 9:11:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/24/2017 7:18:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 6:34:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 6:34:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 6:34:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 5:50:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/24/2017 5:45:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/24/2017 5:45:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 5:45:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/24/2017 5:44:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 5:18:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/24/2017 5:18:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:26Z. Reason: GVLK.
Information	11/24/2017 5:13:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/24/2017 5:13:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/24/2017 5:13:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 5:13:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/24/2017 5:12:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f298deb6-d0a7-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/24/2017 5:12:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f298deb5-d0a7-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/24/2017 5:12:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f298deb4-d0a7-11e7-bcbd-204747d02364
Report Status: 0"
Error	11/24/2017 5:08:50 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/24/2017 5:00:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/24/2017 5:00:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:13Z. Reason: GVLK.
Error	11/24/2017 4:55:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/24/2017 4:55:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/24/2017 4:55:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/24/2017 4:55:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 4:55:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/24/2017 4:41:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a187c7da-d0a3-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/24/2017 4:05:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 3:49:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/24/2017 3:49:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/24/2017 2:48:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/24/2017 2:48:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:05Z. Reason: GVLK.
Information	11/24/2017 2:43:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/24/2017 2:43:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/24/2017 2:43:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/24/2017 2:43:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/24/2017 2:34:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 2:34:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/24/2017 2:33:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	11/24/2017 2:24:55 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/24/2017 12:30:56 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/24/2017 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/23/2017 11:41:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b74d8608-d079-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/23/2017 10:48:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 10:34:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 10:34:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 10:33:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/23/2017 9:03:58 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 7:52:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 7:52:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:04Z. Reason: GVLK.
Information	11/23/2017 7:47:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 7:47:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 7:47:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 7:47:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/23/2017 7:08:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 6:41:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cb130584-d04f-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 6:34:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 6:33:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 6:33:52 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/23/2017 6:33:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/23/2017 5:18:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/23/2017 3:20:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 2:34:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 2:33:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 2:33:50 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/23/2017 2:33:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 1:41:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de5c0771-d025-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/23/2017 1:39:44 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 1:27:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 1:27:24 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:20Z. Reason: GVLK.
Information	11/23/2017 1:22:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 1:22:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 1:22:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 1:22:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2017 1:19:35 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/23/2017 1:19:32 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/23/2017 1:18:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/23/2017 1:18:54 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/23/2017 12:37:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8723.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/23/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/23/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42105)(?)])(1 )(2 )]

"
Information	11/23/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42105)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/23/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/23/2017 12:03:28 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 11:46:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 11:46:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:05Z. Reason: GVLK.
Information	11/23/2017 11:41:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 11:41:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 11:41:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 11:41:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2017 11:15:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/23/2017 11:15:01 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/23/2017 10:33:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 10:33:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 10:31:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 16, Compared: 15430, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/23/2017 10:30:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/23/2017 10:30:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Warning	11/23/2017 10:24:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 9:29:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aed4e7fa-d002-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 9:29:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aed4e7f9-d002-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 8:41:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f405ef69-cffb-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/23/2017 8:37:17 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/23/2017 7:05:20 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 6:33:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/23/2017 5:18:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 3:42:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 3:42:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:00Z. Reason: GVLK.
Information	11/23/2017 3:41:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 07447c69-cfd2-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 3:37:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 3:37:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 3:37:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 3:37:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2017 3:36:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5523bf5b-cfd1-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 3:36:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5523bf5a-cfd1-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/23/2017 3:36:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5523bf59-cfd1-11e7-bcbd-204747d02364
Report Status: 0"
Error	11/23/2017 3:32:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Warning	11/23/2017 3:28:22 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 3:23:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 3:23:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:36Z. Reason: GVLK.
Error	11/23/2017 3:19:08 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/23/2017 3:18:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 3:18:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 3:18:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 3:18:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2017 3:17:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/23/2017 3:17:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:37Z. Reason: GVLK.
Information	11/23/2017 3:12:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/23/2017 3:12:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/23/2017 3:12:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/23/2017 3:12:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/23/2017 2:33:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/23/2017 2:15:31 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/23/2017 2:14:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/23/2017 1:57:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/23/2017 12:15:32 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/23/2017 12:03:02 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/22/2017 10:40:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b41fa21-cfa8-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/22/2017 10:32:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2017 10:26:41 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/22/2017 8:45:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/22/2017 7:06:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 6:32:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2017 5:50:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2017 5:50:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:16Z. Reason: GVLK.
Information	11/22/2017 5:45:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2017 5:45:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2017 5:45:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2017 5:45:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/22/2017 5:40:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30a9a432-cf7e-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/22/2017 5:31:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/22/2017 3:39:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 3:10:36 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/22/2017 2:32:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2017 2:04:57 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 12:40:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 43cdd778-cf54-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/22/2017 12:17:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8722.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/22/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/22/2017 12:14:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/22/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43545)(?)])(1 )(2 )]

"
Information	11/22/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43545)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/22/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/22/2017 11:16:04 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/22/2017 11:06:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/22/2017 10:32:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2017 10:26:29 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/22/2017 8:30:30 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 7:40:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57e2dfac-cf2a-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/22/2017 6:57:33 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 6:32:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/22/2017 5:18:37 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 3:59:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2017 3:59:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:07Z. Reason: GVLK.
Information	11/22/2017 3:54:07 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2017 3:54:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2017 3:54:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2017 3:54:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/22/2017 3:53:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94992c6d-cf0a-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/22/2017 3:53:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94992c6c-cf0a-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/22/2017 3:53:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94992c6b-cf0a-11e7-bcbd-204747d02364
Report Status: 0"
Error	11/22/2017 3:49:54 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/22/2017 3:41:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/22/2017 3:41:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:02Z. Reason: GVLK.
Error	11/22/2017 3:36:30 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/22/2017 3:36:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/22/2017 3:36:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/22/2017 3:36:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/22/2017 3:36:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/22/2017 3:27:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 2:40:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6c90f54b-cf00-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/22/2017 2:32:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/22/2017 2:01:20 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/22/2017 2:00:38 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Warning	11/22/2017 1:38:43 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/22/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/21/2017 11:40:32 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 10:31:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2017 10:31:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/21/2017 9:59:38 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 9:40:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 82d7da21-ced6-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/21/2017 8:36:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 8:36:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:40:23Z. Reason: GVLK.
Information	11/21/2017 8:31:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2017 8:31:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 8:31:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 8:31:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/21/2017 8:03:43 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 6:31:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2017 6:09:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 6:09:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:49Z. Reason: GVLK.
Warning	11/21/2017 6:09:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 6:04:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2017 6:04:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 6:04:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 6:04:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/21/2017 4:40:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97cfcd0c-ceac-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/21/2017 4:25:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/21/2017 2:52:46 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 2:31:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/21/2017 1:19:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 12:28:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8721.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/21/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 12:09:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/21/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44985)(?)])(1 )(2 )]

"
Information	11/21/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44985)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 12:09:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/21/2017 11:40:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa4b7ff0-ce82-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/21/2017 11:36:46 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 11:17:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/21/2017 11:17:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/21/2017 10:47:39 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/21/2017 10:31:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2017 10:15:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 10:15:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-28T04:39:33Z. Reason: GVLK.
Information	11/21/2017 10:10:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 10:10:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 10:10:32 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/11/21 04:40"
Information	11/21/2017 10:10:31 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/11/21 04:40, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/21/2017 10:05:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2017 10:05:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 10:05:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 10:05:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/21/2017 9:48:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/21/2017 8:05:53 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 6:40:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bd46f751-ce58-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/21/2017 6:31:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/21/2017 6:24:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 5:02:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 4:57:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/21/2017 4:57:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 4:57:24 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/21/2017 4:29:01 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 3:42:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/21/2017 3:42:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:28Z. Reason: GVLK.
Information	11/21/2017 3:37:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/21/2017 3:37:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/21/2017 3:37:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/21/2017 3:37:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/21/2017 2:35:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/21/2017 2:31:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/21/2017 1:40:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d3460090-ce2e-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/21/2017 12:58:09 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/20/2017 11:05:09 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 10:31:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/20/2017 10:30:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2017 9:28:11 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 8:40:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7a81c2b-ce04-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/20/2017 7:31:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 6:30:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2017 6:30:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2017 6:30:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/20/2017 6:30:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2017 5:57:06 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/20/2017 3:57:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 3:40:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fc436c34-cdda-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/20/2017 2:30:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/20/2017 2:30:47 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/20/2017 2:30:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/20/2017 2:25:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 1:52:08 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/20/2017 1:19:06 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/20/2017 1:19:06 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/20/2017 1:17:42 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/20/2017 1:17:39 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Warning	11/20/2017 12:32:17 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 12:14:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46425)(?)])(1 )(2 )]

"
Information	11/20/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/20/2017 12:05:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8720.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/20/2017 11:55:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2017 11:55:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:23Z. Reason: GVLK.
Information	11/20/2017 11:50:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2017 11:50:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2017 11:50:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2017 11:50:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2017 10:40:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 10763db9-cdb1-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/20/2017 10:37:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/20/2017 10:37:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:14Z. Reason: GVLK.
Information	11/20/2017 10:35:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/20/2017 10:34:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/20/2017 10:33:40 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 23, Compared: 15109, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Warning	11/20/2017 10:32:24 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/20/2017 10:32:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/20/2017 10:32:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2017 10:32:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2017 10:32:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/20/2017 10:30:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/20/2017 10:30:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46524)(?)])(1 )(2 )]

"
Information	11/20/2017 10:30:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46524)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/20/2017 10:30:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/20/2017 10:30:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/20/2017 10:30:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/20/2017 10:30:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/20/2017 10:30:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/20/2017 10:29:59 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/20/2017 10:29:54 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/17/2017 3:28:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 3:23:02 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 3:23:02 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 3:23:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/17/2017 3:02:25 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/17/2017 2:45:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cbd4b10e-cb77-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/17/2017 2:38:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/17/2017 1:27:33 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/17/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50745)(?)])(1 )(2 )]

"
Information	11/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50745)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/17/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 12:03:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/17/2017 11:39:41 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/17/2017 11:01:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 10:56:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 10:56:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 10:56:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 10:44:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 10:39:47 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 16

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 0

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 62

Name: OneNote Notes about Outlook Items
Description: Adds Send to OneNote and Notes about this Item buttons to the command bar
ProgID: OneNote.OutlookAddin
GUID: {93E5752E-B889-47C5-8545-654EE2533C64}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnOL.dll
Boot Time (Milliseconds): 31

Information	11/17/2017 10:39:08 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Warning	11/17/2017 10:39:07 AM	Outlook	59	None	Outlook disabled the following add-in(s):



ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
Load Behavior: 0
HKLM: 1
Location: c:\program files (x86)\microsoft office\root\office16\ucaddin.dll
Threshold Time (Milliseconds): 1000
Time Taken (Milliseconds): 1217
Disable Reason: This add-in caused Outlook to start slowly.
Policy Exception (Allow List): 0 
Information	11/17/2017 10:38:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/17/2017 10:38:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/17/2017 10:38:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50836)(?)])(1 )(2 )]

"
Information	11/17/2017 10:38:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50836)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/17/2017 10:38:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 10:38:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 10:38:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 10:31:21 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 10:26:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 10:26:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 10:26:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	11/17/2017 10:17:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/17/2017 10:15:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 10:15:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:29Z. Reason: GVLK.
Information	11/17/2017 10:13:37 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8717.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/17/2017 10:10:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/17/2017 10:10:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/17/2017 10:10:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 10:10:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 10:09:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 540c1f58-cb51-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/17/2017 10:09:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 540c1f57-cb51-11e7-bcbd-204747d02364
Report Status: 0"
Information	11/17/2017 10:09:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 540c1f56-cb51-11e7-bcbd-204747d02364
Report Status: 0"
Warning	11/17/2017 10:07:45 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Error	11/17/2017 10:03:30 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/17/2017 10:01:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 9:53:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 9:53:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 9:53:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 9:48:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 9:47:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/17/2017 9:47:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:29Z. Reason: GVLK.
Error	11/17/2017 9:43:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/17/2017 9:42:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/17/2017 9:42:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50892)(?)])(1 )(2 )]

"
Information	11/17/2017 9:42:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50892)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/17/2017 9:42:41 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/17/2017 9:42:41 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 9:42:40 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	11/17/2017 9:42:04 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/17/2017 9:41:41 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/17/2017 9:41:31 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/17/2017 9:41:29 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/17/2017 9:41:27 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/17/2017 9:41:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/17/2017 9:41:02 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/17/2017 9:41:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/17/2017 9:41:02 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/17/2017 9:40:45 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Warning	11/17/2017 9:40:42 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 69 second(s) to handle the notification event (CreateSession).
Warning	11/17/2017 9:40:33 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	11/17/2017 9:39:49 AM	ESENT	302	Logging/Recovery	Windows (6804) Windows: The database engine has successfully completed recovery steps.
Information	11/17/2017 9:39:43 AM	ESENT	301	Logging/Recovery	Windows (6804) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/17/2017 9:39:43 AM	ESENT	300	Logging/Recovery	Windows (6804) Windows: The database engine is initiating recovery steps.
Information	11/17/2017 9:39:43 AM	ESENT	102	General	Windows (6804) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/17/2017 9:39:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/17/2017 9:39:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/17/2017 9:39:32 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	11/17/2017 9:39:32 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (WMPPlayer)
License Id=7d141cc8-75a1-5d14-1583-53c8065e7556"
Information	11/17/2017 9:39:31 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	11/17/2017 9:39:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/17/2017 9:39:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/17/2017 9:39:06 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8716.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/17/2017 9:38:41 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:41 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/17/2017 9:38:41 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/17/2017 9:38:41 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/17/2017 9:38:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/17/2017 9:38:39 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/17/2017 9:38:38 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/17/2017 9:38:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/17/2017 9:38:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/17/2017 9:38:36 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/17/2017 9:38:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/17/2017 9:38:34 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:32 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/17/2017 9:38:27 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/17/2017 9:38:26 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/17/2017 9:38:25 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/17/2017 9:38:03 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/17/2017 9:38:03 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/17/2017 9:38:03 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/17/2017 9:38:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/17/2017 9:38:02 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/17/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/17/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/17/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/17/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3708 at 11/16/2017 7:52:35 PM (local) 11/16/2017 2:22:35 PM (UTC). This is an informational message only; no user action is required.
Error	11/17/2017 9:37:56 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/17/2017 9:37:56 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/17/2017 9:37:40 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/17/2017 9:37:40 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/17/2017 9:37:39 AM	PostgreSQL	0	None	"2017-11-17 09:37:39 IST LOG:  redirecting log output to logging collector process
2017-11-17 09:37:39 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/17/2017 9:37:37 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/17/2017 9:37:29 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/17/2017 9:37:29 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/17/2017 9:37:29 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/17/2017 9:37:29 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/17/2017 9:37:29 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3664.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/17/2017 9:37:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	11/17/2017 9:35:36 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	11/17/2017 9:35:32 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/17/2017 9:35:15 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/17/2017 9:35:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/17/2017 9:35:15 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/16/2017 7:52:42 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	11/16/2017 7:52:35 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/16/2017 7:51:16 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 992 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1492 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/16/2017 7:51:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/16/2017 7:51:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/16/2017 7:51:11 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/16/2017 7:51:06 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	11/16/2017 7:50:43 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	11/16/2017 7:50:17 PM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Warning	11/16/2017 7:16:15 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 5:49:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/16/2017 5:21:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 4:19:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dffa2a19-cabb-11e7-84df-204747d02364
Report Status: 0"
Warning	11/16/2017 3:42:07 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 1:49:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2017 1:49:07 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/16/2017 1:49:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/16/2017 1:47:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 1:23:03 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/16/2017 1:23:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/16/2017 1:22:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/16/2017 1:22:46 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 14972, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/16/2017 1:22:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/16/2017 1:22:11 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/16/2017 12:59:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8716.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Error	11/16/2017 12:45:34 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	11/16/2017 12:37:29 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/16/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	11/16/2017 12:11:59 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/16/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52185)(?)])(1 )(2 )]

"
Information	11/16/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/16/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/16/2017 11:27:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/16/2017 11:27:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/16/2017 11:19:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f47e1aad-ca91-11e7-84df-204747d02364
Report Status: 0"
Information	11/16/2017 10:22:35 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/16/2017 10:22:28 AM	ESENT	102	General	Windows (15508) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/16/2017 10:21:56 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 18796.
Information	11/16/2017 10:21:56 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20044. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	11/16/2017 10:21:56 AM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	11/16/2017 10:21:56 AM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20044. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (18.009.20044). Installation success or error status: 0.
Information	11/16/2017 10:21:56 AM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (18.009.20044)' installed successfully.
Information	11/16/2017 10:21:55 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/16/2017 10:21:30 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	11/16/2017 10:21:30 AM	ESENT	103	General	Windows (6592) Windows: The database engine stopped the instance (0).
Information	11/16/2017 10:21:20 AM	McLogEvent	257	None	Blocked by access protection rule.  Access to object C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE\MCSHIELD.EXE was blocked by rule Common Standard Protection:Prevent termination of McAfee processes.
Information	11/16/2017 10:21:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 18796.
Information	11/16/2017 10:21:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 18796.
Information	11/16/2017 10:21:12 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 18.009.20044. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	11/16/2017 10:21:12 AM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	11/16/2017 10:21:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 18796.
Information	11/16/2017 10:18:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824245926_10183867821377672918057928331412892794.msi. Client Process Id: 10808.
Information	11/16/2017 10:18:51 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	11/16/2017 10:18:51 AM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	11/16/2017 10:18:50 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/16/2017 10:18:49 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	11/16/2017 10:18:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824245926_10183867821377672918057928331412892794.msi. Client Process Id: 10808.
Information	11/16/2017 10:12:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Warning	11/16/2017 10:11:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 9:48:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/16/2017 9:44:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/16/2017 9:44:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/16/2017 9:18:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2017 9:18:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:28Z. Reason: GVLK.
Information	11/16/2017 9:13:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2017 9:13:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2017 9:13:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2017 9:13:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/16/2017 8:15:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 7:38:10 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎11‎-‎16T02:08:08.302798500Z.
Information	11/16/2017 7:38:10 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 17328.
Information	11/16/2017 7:38:10 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 0.
Information	11/16/2017 7:38:10 AM	MsiInstaller	11728	None	Product: Google Update Helper -- Configuration completed successfully.
Information	11/16/2017 7:38:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎11‎-‎16T02:08:08.302798500Z.
Information	11/16/2017 7:38:07 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 17328.
Information	11/16/2017 7:38:07 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 17328.
Information	11/16/2017 7:38:07 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Google Update Helper. Product Version: 1.3.33.7. Product Language: 1033. Manufacturer: Google Inc.. Reconfiguration success or error status: 1638.
Information	11/16/2017 7:38:07 AM	MsiInstaller	11729	None	Product: Google Update Helper -- Configuration failed.
Information	11/16/2017 7:38:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleUpdateHelper.msi. Client Process Id: 17328.
Warning	11/16/2017 6:33:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 6:17:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c480a941-ca67-11e7-84df-204747d02364
Report Status: 0"
Information	11/16/2017 5:48:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/16/2017 4:33:58 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/16/2017 3:00:03 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 2:12:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/16/2017 2:10:52 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/16/2017 1:48:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/16/2017 1:24:06 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/16/2017 1:17:48 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dae925aa-ca3d-11e7-84df-204747d02364
Report Status: 0"
Information	11/16/2017 12:57:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/16/2017 12:57:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:34:52Z. Reason: GVLK.
Information	11/16/2017 12:52:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/16/2017 12:52:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/16/2017 12:52:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/16/2017 12:52:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2017 11:35:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 10:19:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 10:19:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:21Z. Reason: GVLK.
Information	11/15/2017 10:14:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 10:14:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 10:14:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 10:14:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2017 10:11:44 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/15/2017 9:56:08 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/15/2017 9:48:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/15/2017 9:47:05 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 9:38:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 9:38:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:34:31Z. Reason: GVLK.
Information	11/15/2017 9:33:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 9:33:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 9:33:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 9:33:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2017 8:17:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed0128c7-ca13-11e7-84df-204747d02364
Report Status: 0"
Warning	11/15/2017 8:15:54 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 7:19:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 7:14:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/15/2017 7:14:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53200)(?)])(1 )(2 )]

"
Information	11/15/2017 7:14:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53200)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 7:14:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/15/2017 7:14:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 7:14:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/15/2017 6:18:45 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 6:18:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 6:13:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/15/2017 6:13:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 6:13:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/15/2017 5:48:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2017 5:48:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/15/2017 4:43:40 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 4:43:12 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/15/2017 3:18:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 237ded71-c9ea-11e7-84df-204747d02364
Report Status: 0"
Information	11/15/2017 3:08:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 3:08:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:34:48Z. Reason: GVLK.
Information	11/15/2017 3:03:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 3:03:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 3:03:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 3:03:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2017 2:57:36 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 1:48:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2017 1:48:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/15/2017 1:23:12 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/15/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53625)(?)])(1 )(2 )]

"
Information	11/15/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53625)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/15/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/15/2017 12:08:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8715.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/15/2017 12:05:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 12:05:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:34:47Z. Reason: GVLK.
Information	11/15/2017 12:00:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 12:00:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 12:00:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 12:00:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2017 11:47:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 10:28:13 AM	GE Software	0	(1)	++Installation complete
Information	11/15/2017 10:28:13 AM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++Started the installation of GE Skype Plugin Fix 1.0 V01 with the following commandline: /Q
Information	11/15/2017 10:28:10 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	11/15/2017 10:28:09 AM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	11/15/2017 10:24:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 10:24:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:25Z. Reason: GVLK.
Error	11/15/2017 10:21:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/15/2017 10:19:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 10:19:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 10:19:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 10:19:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/15/2017 10:18:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 396193e9-c9c0-11e7-84df-204747d02364
Report Status: 0"
Information	11/15/2017 10:18:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 396193e8-c9c0-11e7-84df-204747d02364
Report Status: 0"
Information	11/15/2017 10:18:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 396193e7-c9c0-11e7-84df-204747d02364
Report Status: 0"
Information	11/15/2017 10:16:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/15/2017 10:15:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/15/2017 10:12:21 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	11/15/2017 10:08:35 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/15/2017 9:58:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 621c0712-c9bd-11e7-84df-204747d02364
Report Status: 0"
Information	11/15/2017 9:56:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/15/2017 9:56:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:01Z. Reason: GVLK.
Error	11/15/2017 9:51:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/15/2017 9:51:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/15/2017 9:51:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/15/2017 9:51:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/15/2017 9:50:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/15/2017 9:49:59 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/15/2017 9:48:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/15/2017 9:48:18 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/15/2017 9:48:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/14/2017 7:17:14 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 6:13:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 6:13:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/14/2017 5:33:35 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 4:24:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2a6f83f5-c92a-11e7-84df-204747d02364
Report Status: 0"
Error	11/14/2017 4:07:20 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Warning	11/14/2017 3:59:53 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 2:13:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 2:13:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/14/2017 2:11:04 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/14/2017 12:33:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 12:20:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8714.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/14/2017 12:18:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2017 12:18:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:35:10Z. Reason: GVLK.
Information	11/14/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/14/2017 12:13:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2017 12:13:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2017 12:13:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2017 12:13:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/14/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/14/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]

"
Information	11/14/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/14/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/14/2017 11:24:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3e49223c-c900-11e7-84df-204747d02364
Report Status: 0"
Warning	11/14/2017 10:56:26 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 10:55:42 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/14/2017 10:55:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/14/2017 10:31:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/14/2017 10:13:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 10:13:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 10:10:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/14/2017 10:10:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-21T04:34:30Z. Reason: GVLK.
Information	11/14/2017 10:05:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2017 10:05:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2017 10:05:30 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/11/14 04:35"
Information	11/14/2017 10:05:29 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/11/14 04:35, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/14/2017 10:00:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/14/2017 10:00:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/14/2017 10:00:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2017 10:00:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/14/2017 9:08:47 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/14/2017 7:17:04 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 6:24:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5424fce9-c8d6-11e7-84df-204747d02364
Report Status: 0"
Information	11/14/2017 6:13:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 6:13:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/14/2017 5:32:23 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 4:01:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/14/2017 3:56:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/14/2017 3:56:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/14/2017 3:56:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/14/2017 3:47:39 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 2:13:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/14/2017 2:13:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/14/2017 1:59:50 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/14/2017 1:24:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 69fdb967-c8ac-11e7-84df-204747d02364
Report Status: 0"
Warning	11/14/2017 12:03:11 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 10:28:26 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 10:28:26 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:26Z. Reason: GVLK.
Warning	11/13/2017 10:23:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 10:23:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2017 10:23:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 10:23:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 10:23:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2017 10:13:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 10:12:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2017 8:25:52 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 8:24:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 801d45e7-c882-11e7-84df-204747d02364
Report Status: 0"
Warning	11/13/2017 6:51:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 6:13:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 6:12:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/13/2017 4:54:31 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 3:24:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 95dec6f6-c858-11e7-84df-204747d02364
Report Status: 0"
Warning	11/13/2017 3:23:51 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 2:13:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 2:12:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 1:57:27 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Warning	11/13/2017 1:36:10 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 1:25:11 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/13/2017 1:25:11 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/13/2017 1:24:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/13/2017 1:23:56 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 14718, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/13/2017 1:23:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/13/2017 1:23:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/13/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 12:11:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 12:11:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:36Z. Reason: GVLK.
Information	11/13/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]

"
Information	11/13/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/13/2017 12:06:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2017 12:06:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 12:06:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 12:06:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/13/2017 12:04:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 12:02:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8713.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/13/2017 10:39:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 10:39:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:31:10Z. Reason: GVLK.
Information	11/13/2017 10:34:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2017 10:34:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 10:34:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 10:34:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/13/2017 10:33:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fe50b4a9-c82f-11e7-84df-204747d02364
Report Status: 0"
Information	11/13/2017 10:33:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fe50b4a8-c82f-11e7-84df-204747d02364
Report Status: 0"
Information	11/13/2017 10:33:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fe50b4a7-c82f-11e7-84df-204747d02364
Report Status: 0"
Error	11/13/2017 10:30:23 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/13/2017 10:24:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aae5d427-c82e-11e7-84df-204747d02364
Report Status: 0"
Information	11/13/2017 10:22:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 10:22:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:31:00Z. Reason: GVLK.
Information	11/13/2017 10:18:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/13/2017 10:17:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/13/2017 10:16:46 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Error	11/13/2017 10:15:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/13/2017 10:14:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/13/2017 10:14:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 10:14:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 10:14:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/13/2017 10:13:49 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/13/2017 10:12:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 10:12:41 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/13/2017 10:12:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	11/13/2017 10:12:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/13/2017 10:12:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/13/2017 10:12:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/13/2017 10:12:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56623)(?)])(1 )(2 )]

"
Information	11/13/2017 10:12:08 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56623)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/13/2017 10:12:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/13/2017 10:12:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/13/2017 10:12:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	11/10/2017 8:05:16 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 7:30:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 772cc8f1-c61f-11e7-84df-204747d02364
Report Status: 0"
Warning	11/10/2017 6:24:30 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 5:20:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/10/2017 4:51:47 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Warning	11/10/2017 2:53:03 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 2:30:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c635fe5-c5f5-11e7-84df-204747d02364
Report Status: 0"
Information	11/10/2017 1:20:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	11/10/2017 1:06:23 PM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 12:23:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8710.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/10/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60825)(?)])(1 )(2 )]

"
Information	11/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/10/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/10/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/10/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/10/2017 11:11:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/10/2017 11:10:42 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	11/10/2017 11:09:42 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 10:53:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/10/2017 10:14:49 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/10/2017 9:52:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/10/2017 9:52:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:24Z. Reason: GVLK.
Error	11/10/2017 9:50:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/10/2017 9:47:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/10/2017 9:47:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/10/2017 9:47:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/10/2017 9:47:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/10/2017 9:46:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5acc386-c5cd-11e7-84df-204747d02364
Report Status: 0"
Information	11/10/2017 9:46:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5acc385-c5cd-11e7-84df-204747d02364
Report Status: 0"
Information	11/10/2017 9:46:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f5acc384-c5cd-11e7-84df-204747d02364
Report Status: 0"
Error	11/10/2017 9:40:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/10/2017 9:36:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/10/2017 9:36:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:54Z. Reason: GVLK.
Information	11/10/2017 9:31:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/10/2017 9:31:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/10/2017 9:31:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/10/2017 9:31:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/10/2017 9:30:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a1b4c404-c5cb-11e7-84df-204747d02364
Report Status: 0"
Information	11/10/2017 9:28:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/10/2017 9:28:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:31:10Z. Reason: GVLK.
Information	11/10/2017 9:25:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	11/10/2017 9:24:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/10/2017 9:23:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/10/2017 9:23:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/10/2017 9:23:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/10/2017 9:23:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	11/10/2017 9:21:57 AM	SceCli	1202	None	"Security policies were propagated with warning. 0x534 : No mapping between account names and security IDs was done.

Advanced help for this problem is available on http://support.microsoft.com. Query for ""troubleshooting 1202 events"". 

Error 0x534 occurs when a user account in one or more Group Policy objects (GPOs) could not be resolved to a SID.  This error is possibly caused by a mistyped or deleted user account referenced in either the User Rights or Restricted Groups branch of a GPO.  To resolve this event, contact an administrator in the domain to perform the following actions: 

1.	Identify accounts that could not be resolved to a SID:

From the command prompt, type: FIND /I ""Cannot find""  %SYSTEMROOT%\Security\Logs\winlogon.log

The string following ""Cannot find"" in the FIND output identifies the problem account names.

Example: Cannot find JohnDough.

In this case, the SID for username ""JohnDough"" could not be determined. This most likely occurs because the account was deleted, renamed, or is spelled differently (e.g. ""JohnDoe""). 

2.	Use RSoP to identify the specific User Rights, Restricted Groups, and Source GPOs that contain the problem accounts:

a.	Start -> Run -> RSoP.msc
b.	Review the results for Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment and Computer Configuration\Windows Settings\Security Settings\Local Policies\Restricted Groups for any errors flagged with a red X.
c.	For any User Right or Restricted Group marked with a red X, the corresponding GPO that contains the problem policy setting is listed under the column entitled ""Source GPO"". Note the specific User Rights, Restricted Groups and containing Source GPOs that are generating errors. 

3.	Remove unresolved accounts from Group Policy

a.	Start -> Run -> MMC.EXE
b.	From the File menu select ""Add/Remove Snap-in...""
c.	From the ""Add/Remove Snap-in"" dialog box select ""Add...""
d.	In the ""Add Standalone Snap-in"" dialog box select ""Group Policy"" and click ""Add""
e.	In the ""Select Group Policy Object"" dialog box click the ""Browse"" button.
f.	On the ""Browse for a Group Policy Object"" dialog box choose the ""All"" tab
g.	For each source GPO identified in step 2, correct the specific User Rights or Restricted Groups that were flagged with a red X in step 2. These User Rights or Restricted Groups can be corrected by removing or correcting any references to the problem accounts that were identified in step 1."
Information	11/10/2017 9:20:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/10/2017 9:20:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/10/2017 9:20:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/10/2017 9:20:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 7:30:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 7:25:17 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/9/2017 7:25:14 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 109

Information	11/9/2017 7:25:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 7:24:50 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	11/9/2017 7:24:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/9/2017 7:24:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61830)(?)])(1 )(2 )]

"
Information	11/9/2017 7:24:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61830)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 7:24:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/9/2017 7:24:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 7:24:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 6:56:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 6:56:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 6:05:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 79912083-c54a-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 2:56:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 2:56:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 1:08:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 1:08:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:50Z. Reason: GVLK.
Information	11/9/2017 1:05:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8f2e52cc-c520-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/9/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 1:03:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 1:00:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8709.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/9/2017 12:19:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 12:19:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:48Z. Reason: GVLK.
Information	11/9/2017 12:14:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 12:14:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/9/2017 12:14:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 12:14:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 12:14:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/9/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62265)(?)])(1 )(2 )]

"
Information	11/9/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/9/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 11:25:24 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/9/2017 11:25:02 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/9/2017 10:56:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 10:56:46 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/9/2017 10:56:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 10:56:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 10:49:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/9/2017 9:52:41 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/9/2017 9:52:41 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/9/2017 9:52:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/9/2017 9:52:22 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/9/2017 9:52:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 2, Compared: 14553, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/9/2017 9:51:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Error	11/9/2017 9:50:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/9/2017 8:01:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c013367-c4f6-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 6:56:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 6:56:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 5:32:44 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/9/2017 4:29:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 4:29:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:31:09Z. Reason: GVLK.
Information	11/9/2017 4:24:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/9/2017 4:24:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 4:24:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 4:24:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 4:23:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a59fea5b-c4d7-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 4:23:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a59fea5a-c4d7-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 4:23:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a59fea59-c4d7-11e7-84df-204747d02364
Report Status: 0"
Error	11/9/2017 4:20:28 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/9/2017 4:11:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/9/2017 4:11:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:39Z. Reason: GVLK.
Error	11/9/2017 4:07:10 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/9/2017 4:05:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/9/2017 4:05:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/9/2017 4:05:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/9/2017 4:05:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/9/2017 3:01:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 21e7106e-c4cc-11e7-84df-204747d02364
Report Status: 0"
Information	11/9/2017 2:56:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 2:56:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/9/2017 2:07:16 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/9/2017 2:06:33 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/9/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/8/2017 10:56:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 10:56:31 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/8/2017 10:56:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 10:01:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37c5b22f-c4a2-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 6:56:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 6:56:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	11/8/2017 6:15:12 PM	Application Error	1000	(100)	"Faulting application name: pgAdmin3.exe, version: 1.22.1.1, time stamp: 0x57316441
Faulting module name: wxbase28u_vc_custom.dll, version: 2.8.12.0, time stamp: 0x5359fda3
Exception code: 0xc0000005
Fault offset: 0x0000000000056384
Faulting process id: 0x2804
Faulting application start time: 0x01d35884cc1ba34a
Faulting application path: C:\Program Files\PostgreSQL\9.5\bin\pgAdmin3.exe
Faulting module path: C:\Program Files\PostgreSQL\9.5\bin\wxbase28u_vc_custom.dll
Report Id: a8cb9e0f-c482-11e7-84df-204747d02364"
Information	11/8/2017 5:01:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4cc68beb-c478-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 2:56:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 2:56:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 1:05:22 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/8/2017 12:48:21 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8708.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/8/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63705)(?)])(1 )(2 )]

"
Information	11/8/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/8/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/8/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/8/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/8/2017 12:00:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61bfbd8e-c44e-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 11:15:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/8/2017 11:15:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/8/2017 10:56:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 10:55:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 10:49:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	11/8/2017 9:50:38 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/8/2017 9:17:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/8/2017 9:17:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:41Z. Reason: GVLK.
Information	11/8/2017 9:12:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/8/2017 9:12:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/8/2017 9:12:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/8/2017 9:12:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/8/2017 7:00:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 77b455c7-c424-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 6:56:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 6:55:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 3:56:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/8/2017 3:56:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:41Z. Reason: GVLK.
Information	11/8/2017 3:51:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/8/2017 3:51:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/8/2017 3:51:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/8/2017 3:51:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/8/2017 3:51:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f40bd58c-c409-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 3:51:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f40bd58b-c409-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 3:51:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f40bd58a-c409-11e7-84df-204747d02364
Report Status: 0"
Error	11/8/2017 3:47:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/8/2017 3:39:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/8/2017 3:39:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:51Z. Reason: GVLK.
Error	11/8/2017 3:35:16 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/8/2017 3:34:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/8/2017 3:34:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/8/2017 3:34:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/8/2017 3:34:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/8/2017 3:03:49 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/8/2017 3:03:11 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/8/2017 2:56:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 2:55:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/8/2017 2:51:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/8/2017 2:51:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:56Z. Reason: GVLK.
Information	11/8/2017 2:46:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/8/2017 2:46:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/8/2017 2:46:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/8/2017 2:46:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/8/2017 2:00:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8cb5348a-c3fa-11e7-84df-204747d02364
Report Status: 0"
Information	11/8/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/7/2017 11:16:19 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 11:16:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:31:19Z. Reason: GVLK.
Information	11/7/2017 11:11:19 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 11:11:19 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 11:11:19 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 11:11:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 10:56:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 10:55:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 9:00:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2a35e9e-c3d0-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 7:33:06 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/7/2017 6:55:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 6:55:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 4:00:49 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b88f3ccb-c3a6-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 3:57:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 3:57:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:57Z. Reason: GVLK.
Information	11/7/2017 3:52:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 3:52:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 3:52:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 3:52:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 2:55:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 2:55:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 12:36:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8707.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/7/2017 12:14:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]

"
Information	11/7/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/7/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 11:56:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/7/2017 11:56:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/7/2017 11:27:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/7/2017 11:19:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/7/2017 11:00:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cdf5c1b4-c37c-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 10:56:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/7/2017 10:55:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 10:55:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 10:06:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 10:06:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-14T04:30:22Z. Reason: GVLK.
Information	11/7/2017 10:01:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 10:01:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 10:01:21 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/11/07 04:31"
Information	11/7/2017 10:01:21 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/11/07 04:31, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	11/7/2017 9:56:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 9:56:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 9:56:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 9:56:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	11/7/2017 9:50:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/7/2017 6:55:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 6:53:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 6:48:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/7/2017 6:48:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 6:48:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 6:00:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e3fb45e3-c352-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 4:17:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 4:17:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:18Z. Reason: GVLK.
Information	11/7/2017 4:12:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 4:12:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 4:12:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 4:12:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 4:12:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3f83492-c343-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 4:12:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3f83491-c343-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 4:12:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3f83490-c343-11e7-84df-204747d02364
Report Status: 0"
Error	11/7/2017 4:08:04 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/7/2017 4:01:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 4:01:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:15Z. Reason: GVLK.
Error	11/7/2017 3:56:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/7/2017 3:56:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 3:56:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 3:56:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 3:56:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 2:55:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/7/2017 2:54:22 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/7/2017 2:54:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/7/2017 2:54:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:20Z. Reason: GVLK.
Information	11/7/2017 2:49:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/7/2017 2:49:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/7/2017 2:49:20 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/7/2017 2:49:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/7/2017 1:00:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f91b8db1-c328-11e7-84df-204747d02364
Report Status: 0"
Information	11/7/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/6/2017 10:54:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2017 9:49:08 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	11/6/2017 9:47:41 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	11/6/2017 8:00:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0f1fe4ab-c2ff-11e7-84df-204747d02364
Report Status: 0"
Information	11/6/2017 6:54:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2017 4:47:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 4:42:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 4:42:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 4:42:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 3:00:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25015a71-c2d5-11e7-84df-204747d02364
Report Status: 0"
Information	11/6/2017 2:54:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2017 1:57:45 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/6/2017 12:31:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8706.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/6/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66585)(?)])(1 )(2 )]

"
Information	11/6/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 12:09:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 12:09:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 12:09:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 12:06:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 12:01:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 12:01:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 12:01:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 11:37:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 11:37:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:09Z. Reason: GVLK.
Information	11/6/2017 11:36:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 11:32:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2017 11:32:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 11:32:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 11:32:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 11:31:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 11:31:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 11:31:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 11:06:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 11:01:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 11:01:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 11:01:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 10:59:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 10:56:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 10:56:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:10Z. Reason: GVLK.
Information	11/6/2017 10:54:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2017 10:54:37 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/6/2017 10:54:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/6/2017 10:53:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2017 10:53:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66661)(?)])(1 )(2 )]

"
Information	11/6/2017 10:53:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66661)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 10:53:52 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 1279

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 13635

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 358

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 671

Information	11/6/2017 10:50:20 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	11/6/2017 10:50:19 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	11/6/2017 10:50:06 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2017 10:50:05 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2017 10:50:03 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Error	11/6/2017 10:49:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/6/2017 10:49:03 AM	ESENT	302	Logging/Recovery	Windows (6592) Windows: The database engine has successfully completed recovery steps.
Information	11/6/2017 10:49:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2017 10:49:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 10:49:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 10:48:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 10:48:39 AM	ESENT	301	Logging/Recovery	Windows (6592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	11/6/2017 10:48:38 AM	ESENT	300	Logging/Recovery	Windows (6592) Windows: The database engine is initiating recovery steps.
Information	11/6/2017 10:48:37 AM	ESENT	102	General	Windows (6592) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	11/6/2017 10:48:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2017 10:48:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66667)(?)])(1 )(2 )]

"
Information	11/6/2017 10:48:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66667)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 10:48:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 10:48:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 10:48:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 10:48:00 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8703.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/6/2017 10:46:12 AM	Service1	0	None	Service started successfully.
Error	11/6/2017 10:46:08 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	11/6/2017 10:46:06 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	11/6/2017 10:45:52 AM	PostgreSQL	0	None	Server started and accepting connections

Information	11/6/2017 10:45:50 AM	PostgreSQL	0	None	"2017-11-06 10:45:50 IST LOG:  redirecting log output to logging collector process
2017-11-06 10:45:50 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	11/6/2017 10:45:46 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	11/6/2017 10:45:41 AM	PostgreSQL	0	None	Waiting for server startup...

Information	11/6/2017 10:45:38 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	11/6/2017 10:45:34 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	11/6/2017 10:45:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	11/6/2017 10:45:28 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	11/6/2017 10:45:28 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	11/6/2017 10:45:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	11/6/2017 10:45:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	11/6/2017 10:45:22 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:22 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	11/6/2017 10:45:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	11/6/2017 10:45:22 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	11/6/2017 10:45:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	11/6/2017 10:45:21 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	11/6/2017 10:45:20 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	11/6/2017 10:45:17 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:16 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	11/6/2017 10:45:16 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	11/6/2017 10:45:16 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3904 at 11/6/2017 10:41:01 AM (local) 11/6/2017 5:11:01 AM (UTC). This is an informational message only; no user action is required.
Information	11/6/2017 10:45:16 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	11/6/2017 10:45:13 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	11/6/2017 10:45:13 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	11/6/2017 10:45:13 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	11/6/2017 10:45:13 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	11/6/2017 10:45:13 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3708.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	11/6/2017 10:45:12 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	11/6/2017 10:44:23 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	11/6/2017 10:44:07 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	11/6/2017 10:44:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	11/6/2017 10:44:07 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	11/6/2017 10:41:29 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	11/6/2017 10:41:00 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	11/6/2017 10:40:18 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 176 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2360 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2360 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2032 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	11/6/2017 10:40:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	11/6/2017 10:40:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	11/6/2017 10:40:13 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	11/6/2017 10:35:06 AM	Outlook	51	None	A provider took longer than expected (5 seconds) to close during fast shutdown.
Provider: EMSMDB.DLL
Type: MAPI Store Provider
Duration: 17784 milliseconds
Information	11/6/2017 10:03:52 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/6/2017 10:03:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/6/2017 10:03:48 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/6/2017 10:00:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3a671e5f-c2ab-11e7-89b3-204747d02364
Report Status: 0"
Information	11/6/2017 10:00:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/6/2017 10:00:08 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/6/2017 9:59:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 9:59:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:46Z. Reason: GVLK.
Information	11/6/2017 9:59:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 5, Deleted: 0, Modified: 2, Compared: 14330, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Error	11/6/2017 9:58:13 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/6/2017 9:57:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/6/2017 9:56:34 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8703.0000.
Information	11/6/2017 9:52:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/6/2017 9:52:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 9:52:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 9:52:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 9:52:32 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66722)(?)])(1 )(2 )]

"
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66722)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109922  Grace type=8.
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=96b4f899-2613-4226-88af-182583a019fb"
Information	11/6/2017 9:52:12 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=86a4434e-b502-4a95-ae96-f12d45778cb7"
Information	11/6/2017 9:52:10 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	11/6/2017 9:51:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/6/2017 9:51:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20643)(?)])(1 )(2 )]

"
Information	11/6/2017 9:51:56 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20643)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/6/2017 9:51:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/6/2017 9:51:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/6/2017 9:51:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/6/2017 9:51:31 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft VS Code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8703.0000.
Information	11/6/2017 9:51:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/6/2017 9:50:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	11/6/2017 9:49:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/6/2017 9:49:58 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	11/3/2017 5:47:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 5:47:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 5:43:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63d494d4-c090-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 5:34:55 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	11/3/2017 5:34:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	11/3/2017 1:47:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 1:21:08 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/3/2017 12:58:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 12:58:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:21Z. Reason: GVLK.
Information	11/3/2017 12:53:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2017 12:53:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2017 12:53:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 12:53:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 12:43:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 784c6524-c066-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 12:41:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8703.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/3/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/3/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]

"
Information	11/3/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24825)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/3/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 10:37:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/3/2017 10:37:32 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/3/2017 10:37:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/3/2017 9:46:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 7:43:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8cbc617c-c03c-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 5:46:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 4:50:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 4:50:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:41Z. Reason: GVLK.
Information	11/3/2017 4:45:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2017 4:45:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2017 4:45:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 4:45:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 4:44:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e032862-c023-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 4:44:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e032861-c023-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 4:44:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e032860-c023-11e7-89b3-204747d02364
Report Status: 0"
Error	11/3/2017 4:39:40 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/3/2017 4:30:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 4:30:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:51Z. Reason: GVLK.
Error	11/3/2017 4:26:24 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/3/2017 4:25:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2017 4:25:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2017 4:25:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 4:25:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 3:20:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 3:20:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:39Z. Reason: GVLK.
Information	11/3/2017 3:15:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/3/2017 3:15:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/3/2017 3:15:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 3:15:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 3:13:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/3/2017 3:08:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/3/2017 3:08:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/3/2017 3:08:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/3/2017 2:43:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0136394-c012-11e7-89b3-204747d02364
Report Status: 0"
Information	11/3/2017 1:46:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/3/2017 12:03:04 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	11/2/2017 9:46:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 9:46:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 9:43:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b52f3bd0-bfe8-11e7-89b3-204747d02364
Report Status: 0"
Information	11/2/2017 8:19:45 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/2/2017 5:46:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 5:46:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 5:26:24 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 38, Compared: 14260, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/2/2017 5:25:47 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	11/2/2017 4:43:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c9bfc630-bfbe-11e7-89b3-204747d02364
Report Status: 0"
Information	11/2/2017 3:53:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 3:53:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:46Z. Reason: GVLK.
Information	11/2/2017 3:48:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/2/2017 3:48:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 3:48:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 3:48:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 3:32:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 3:26:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2017 3:26:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26068)(?)])(1 )(2 )]

"
Information	11/2/2017 3:26:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26068)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 3:26:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2017 3:26:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 3:26:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 2:17:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 2:17:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:45Z. Reason: GVLK.
Information	11/2/2017 2:12:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/2/2017 2:12:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 2:12:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 2:12:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 1:46:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 1:46:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	11/2/2017 1:46:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 1:29:35 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/2/2017 1:29:30 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	11/2/2017 12:14:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 12:12:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8702.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/2/2017 12:09:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2017 12:09:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]

"
Information	11/2/2017 12:09:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26265)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 12:09:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2017 12:09:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 12:09:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 11:42:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df568c45-bf94-11e7-89b3-204747d02364
Report Status: 0"
Information	11/2/2017 10:38:57 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 10:33:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2017 10:33:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26361)(?)])(1 )(2 )]

"
Information	11/2/2017 10:33:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26361)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 10:32:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/2/2017 10:32:26 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/2/2017 10:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2017 10:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26363)(?)])(1 )(2 )]

"
Information	11/2/2017 10:32:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26363)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 10:32:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2017 10:32:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 10:32:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 10:31:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/2/2017 9:51:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/2/2017 9:46:19 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 172

Information	11/2/2017 9:46:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/2/2017 9:45:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/2/2017 9:45:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26409)(?)])(1 )(2 )]

"
Information	11/2/2017 9:45:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26409)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/2/2017 9:45:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/2/2017 9:45:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/2/2017 9:45:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/2/2017 6:42:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f3b4d809-bf6a-11e7-89b3-204747d02364
Report Status: 0"
Information	11/2/2017 3:03:12 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/2/2017 1:42:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0992c48a-bf41-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 9:07:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2017 9:07:31 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:31Z. Reason: GVLK.
Information	11/1/2017 9:02:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2017 9:02:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2017 9:02:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2017 9:02:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2017 8:42:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1e7c6b34-bf17-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 6:32:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/1/2017 6:27:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/1/2017 6:27:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27328)(?)])(1 )(2 )]

"
Information	11/1/2017 6:27:06 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27328)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2017 6:27:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/1/2017 6:27:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2017 6:27:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/1/2017 3:42:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 338a613c-beed-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 2:31:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2017 2:31:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2017 12:27:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8701.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	11/1/2017 12:14:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	11/1/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	11/1/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27705)(?)])(1 )(2 )]

"
Information	11/1/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	11/1/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	11/1/2017 11:13:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2017 11:13:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:25:56Z. Reason: GVLK.
Information	11/1/2017 11:08:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2017 11:08:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2017 11:08:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2017 11:08:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2017 11:08:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d35b8d3c-bec6-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 11:08:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d35b8d3b-bec6-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 11:08:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d35b8d3a-bec6-11e7-89b3-204747d02364
Report Status: 0"
Error	11/1/2017 11:02:05 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	11/1/2017 10:51:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	11/1/2017 10:41:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 23bd0863-bec3-11e7-89b3-204747d02364
Report Status: 0"
Information	11/1/2017 10:41:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	11/1/2017 10:41:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:18Z. Reason: GVLK.
Information	11/1/2017 10:37:22 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Error	11/1/2017 10:37:11 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	11/1/2017 10:36:33 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8700.0000.
Information	11/1/2017 10:35:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	11/1/2017 10:35:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	11/1/2017 10:35:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	11/1/2017 10:35:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	11/1/2017 10:33:41 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	11/1/2017 10:32:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	11/1/2017 10:31:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	11/1/2017 10:31:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	11/1/2017 10:31:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	11/1/2017 10:31:38 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/31/2017 8:33:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a11e80aa-be4c-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 7:23:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 7:23:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.660364500Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.660364500Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.556354100Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.556354100Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.413339800Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.413339800Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.285327000Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.285327000Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.147313200Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.147313200Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:19.021300600Z.
Information	10/31/2017 4:09:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:19.021300600Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:18.884286900Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:18.884286900Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:18.741272600Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:18.741272600Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:18.013199800Z.
Information	10/31/2017 4:09:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:18.013199800Z.
Information	10/31/2017 4:09:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎10‎-‎31T10:39:16.253023800Z.
Information	10/31/2017 4:09:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎31T10:39:16.253023800Z.
Information	10/31/2017 3:33:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6efebc0-be22-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 3:23:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 3:23:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 1:39:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 1:39:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:26:50Z. Reason: GVLK.
Information	10/31/2017 1:34:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2017 1:34:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 1:34:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 1:34:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 1:00:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8700.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	10/31/2017 12:48:42 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/31/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/31/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]

"
Information	10/31/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 11:23:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 11:23:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 11:15:28 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/31/2017 11:15:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/31/2017 10:33:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cbb4bd36-bdf8-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 10:01:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 10:01:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-11-07T04:25:55Z. Reason: GVLK.
Information	10/31/2017 9:56:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 9:56:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 9:56:54 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/10/31 04:26"
Information	10/31/2017 9:56:53 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/10/31 04:26, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/31/2017 9:51:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2017 9:51:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 9:51:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 9:51:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 8:37:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/31/2017 7:23:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 7:23:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 5:33:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1742676-bdce-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 5:04:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 4:59:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/31/2017 4:59:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 4:59:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 4:51:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 4:51:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:50Z. Reason: GVLK.
Information	10/31/2017 4:46:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2017 4:46:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 4:46:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 4:46:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 4:39:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 4:39:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:36Z. Reason: GVLK.
Information	10/31/2017 4:34:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2017 4:34:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 4:34:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 4:34:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 4:33:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96f0090d-bdc6-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 4:33:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96f0090c-bdc6-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 4:33:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96f0090b-bdc6-11e7-89b3-204747d02364
Report Status: 0"
Error	10/31/2017 4:30:54 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/31/2017 4:28:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/31/2017 4:27:54 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/31/2017 4:24:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/31/2017 4:24:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:29Z. Reason: GVLK.
Error	10/31/2017 4:19:49 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/31/2017 4:19:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/31/2017 4:19:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/31/2017 4:19:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/31/2017 4:19:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/31/2017 3:23:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 3:23:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/31/2017 12:33:08 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6f7daa6-bda4-11e7-89b3-204747d02364
Report Status: 0"
Information	10/31/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/30/2017 11:40:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 11:40:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:32Z. Reason: GVLK.
Information	10/30/2017 11:35:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 11:35:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 11:35:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 11:35:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 11:23:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 11:23:13 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/30/2017 11:23:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 7:37:42 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/30/2017 7:33:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0ca960db-bd7b-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 7:22:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 5:44:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 5:44:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:14Z. Reason: GVLK.
Information	10/30/2017 5:39:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 5:39:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 5:39:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 5:39:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 4:35:54 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 14052, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/30/2017 4:35:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/30/2017 4:15:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/30/2017 4:14:56 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/30/2017 3:22:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 3:12:41 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 3:07:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2017 3:07:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30407)(?)])(1 )(2 )]

"
Information	10/30/2017 3:07:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30407)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 3:06:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2017 3:06:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30408)(?)])(1 )(2 )]

"
Information	10/30/2017 3:06:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30408)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 3:06:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2017 3:06:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30409)(?)])(1 )(2 )]

"
Information	10/30/2017 3:06:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30409)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 3:06:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2017 3:06:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 3:06:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 2:34:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 2:34:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:39Z. Reason: GVLK.
Information	10/30/2017 2:33:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2214d8f1-bd51-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 2:29:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 2:29:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 2:29:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 2:29:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30585)(?)])(1 )(2 )]

"
Information	10/30/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/30/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 12:01:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8699.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	10/30/2017 11:22:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 11:22:50 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/30/2017 11:22:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 10:20:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/30/2017 9:30:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec51378b-bd26-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 9:30:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/30/2017 9:30:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/30/2017 9:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/30/2017 7:22:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 7:22:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 6:40:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/30/2017 5:16:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 5:16:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:18Z. Reason: GVLK.
Information	10/30/2017 5:11:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 5:11:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 5:11:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 5:11:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 5:11:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9f9876cc-bd02-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 5:11:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9f9876cb-bd02-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 5:11:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9f9876ca-bd02-11e7-89b3-204747d02364
Report Status: 0"
Error	10/30/2017 5:08:18 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/30/2017 5:02:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 5:02:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:13Z. Reason: GVLK.
Error	10/30/2017 4:57:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/30/2017 4:57:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 4:57:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 4:57:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 4:57:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 4:30:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0244353d-bcfd-11e7-89b3-204747d02364
Report Status: 0"
Information	10/30/2017 3:52:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/30/2017 3:52:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:20:53Z. Reason: GVLK.
Information	10/30/2017 3:47:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/30/2017 3:47:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/30/2017 3:47:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/30/2017 3:47:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/30/2017 3:22:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 3:22:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/30/2017 2:07:01 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/30/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/29/2017 11:30:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 185d939a-bcd3-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 11:22:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 11:22:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 7:22:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 7:22:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 6:30:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e7187ba-bca9-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 3:22:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 1:30:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 446b257e-bc7f-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 1:08:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 1:08:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:47Z. Reason: GVLK.
Information	10/29/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2017 1:03:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 1:03:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 12:32:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8698.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	10/29/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/29/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32025)(?)])(1 )(2 )]

"
Information	10/29/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32025)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2017 12:09:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/29/2017 12:09:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 11:22:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 10:30:14 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/29/2017 10:30:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/29/2017 10:30:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/29/2017 8:30:43 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5a0f3ec3-bc55-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 8:27:54 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/29/2017 7:23:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/29/2017 7:22:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 7:22:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 6:05:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 6:05:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:15Z. Reason: GVLK.
Information	10/29/2017 6:00:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2017 6:00:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2017 6:00:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 6:00:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 4:36:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 4:31:43 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/29/2017 4:31:43 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 4:31:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 3:57:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 3:57:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:32Z. Reason: GVLK.
Information	10/29/2017 3:52:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2017 3:52:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2017 3:52:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 3:52:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 3:52:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 73898011-bc2e-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 3:52:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 73898010-bc2e-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 3:52:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7389800f-bc2e-11e7-89b3-204747d02364
Report Status: 0"
Error	10/29/2017 3:49:24 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/29/2017 3:42:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/29/2017 3:42:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:29Z. Reason: GVLK.
Error	10/29/2017 3:37:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/29/2017 3:37:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/29/2017 3:37:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/29/2017 3:37:29 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/29/2017 3:37:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/29/2017 3:30:41 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 70295cc7-bc2b-11e7-89b3-204747d02364
Report Status: 0"
Information	10/29/2017 3:22:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 3:22:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/29/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/28/2017 11:22:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 11:22:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 10:30:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86187402-bc01-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 8:17:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 8:17:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:11Z. Reason: GVLK.
Information	10/28/2017 8:12:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2017 8:12:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 8:12:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 8:12:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 7:22:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 7:22:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 5:30:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c0d1930-bbd7-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 5:23:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 5:23:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:49Z. Reason: GVLK.
Information	10/28/2017 5:18:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2017 5:18:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 5:18:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 5:18:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 4:26:17 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/28/2017 3:22:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 3:22:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 2:01:18 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8697.0000
 
 Number of signatures in EXTRA.DAT : 5
 Names of threats that EXTRA.DAT can detect : PS/Agent.c (ED)
Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
W97M/Dropper (ED)
"
Information	10/28/2017 12:30:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1f19319-bbad-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/28/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]

"
Information	10/28/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33465)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/28/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 12:01:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8697.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
"
Information	10/28/2017 11:22:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 11:22:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 7:30:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c7ba7c8d-bb83-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 7:22:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 7:21:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 6:24:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/28/2017 6:24:32 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/28/2017 6:18:46 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/28/2017 5:04:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/28/2017 5:04:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/28/2017 4:31:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 4:31:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:31Z. Reason: GVLK.
Information	10/28/2017 4:26:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2017 4:26:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 4:26:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 4:26:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 4:26:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e9f7cd5-bb6a-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 4:26:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e9f7cd4-bb6a-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 4:26:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0e9f7cd3-bb6a-11e7-89b3-204747d02364
Report Status: 0"
Error	10/28/2017 4:25:01 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/28/2017 4:23:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 4:23:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:25Z. Reason: GVLK.
Error	10/28/2017 4:18:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/28/2017 4:18:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2017 4:18:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 4:18:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 4:18:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 3:29:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/28/2017 3:29:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:33Z. Reason: GVLK.
Information	10/28/2017 3:24:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/28/2017 3:24:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/28/2017 3:24:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/28/2017 3:24:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/28/2017 3:22:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 3:21:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/28/2017 2:30:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ddc9c263-bb59-11e7-89b3-204747d02364
Report Status: 0"
Information	10/28/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/27/2017 11:22:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 11:22:03 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/27/2017 11:21:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 11:12:29 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/27/2017 9:30:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f3d03bd9-bb2f-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 7:21:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 4:43:58 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 13978, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/27/2017 4:43:05 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/27/2017 4:39:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 4:39:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:32Z. Reason: GVLK.
Information	10/27/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 4:34:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 4:30:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0990717d-bb06-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 3:21:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 3:21:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 12:49:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 12:49:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:15Z. Reason: GVLK.
Information	10/27/2017 12:44:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2017 12:44:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 12:44:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 12:44:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]

"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34905)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/27/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 11:30:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f65e86d-badc-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 11:21:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 11:21:40 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/27/2017 11:21:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 9:30:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/27/2017 9:30:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/27/2017 7:21:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 6:40:47 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/27/2017 6:28:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee8d0218-bab1-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 5:59:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 5:55:42 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6524.
Information	10/27/2017 5:55:42 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/27/2017 5:55:42 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/27/2017 5:55:42 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/27/2017 5:55:41 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 6524.
Information	10/27/2017 5:55:41 AM	ESENT	102	General	Windows (8924) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/27/2017 5:55:41 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6524.
Information	10/27/2017 5:55:41 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/27/2017 5:55:41 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/27/2017 5:55:21 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 6524.
Information	10/27/2017 5:55:17 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/27/2017 5:55:17 AM	ESENT	103	General	Windows (11800) Windows: The database engine stopped the instance (0).
Information	10/27/2017 5:55:15 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/27/2017 5:54:59 AM	ESENT	102	General	Windows (11800) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/27/2017 5:54:56 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/27/2017 5:54:56 AM	ESENT	103	General	Windows (7296) Windows: The database engine stopped the instance (0).
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:55 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:54 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/27/2017 5:54:39 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	10/27/2017 5:54:38 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/27/2017 5:54:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/27/2017 5:53:59 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Information	10/27/2017 5:53:53 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎27T00:23:53.516572000Z.
Information	10/27/2017 5:50:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/27/2017 5:50:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 5:50:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 5:11:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 5:11:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:38Z. Reason: GVLK.
Information	10/27/2017 5:06:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2017 5:06:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 5:06:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 5:06:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 5:06:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d8f024a-baa6-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 5:06:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d8f0249-baa6-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 5:06:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d8f0248-baa6-11e7-89b3-204747d02364
Report Status: 0"
Error	10/27/2017 5:02:25 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/27/2017 4:56:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 4:56:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:31Z. Reason: GVLK.
Error	10/27/2017 4:51:46 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/27/2017 4:51:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2017 4:51:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 4:51:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 4:51:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 3:21:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/27/2017 2:11:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/27/2017 2:11:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:40Z. Reason: GVLK.
Information	10/27/2017 2:06:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/27/2017 2:06:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/27/2017 2:06:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/27/2017 2:06:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/27/2017 1:28:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0447af47-ba88-11e7-89b3-204747d02364
Report Status: 0"
Information	10/27/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/26/2017 11:21:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2017 8:28:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1a53dbad-ba5e-11e7-89b3-204747d02364
Report Status: 0"
Information	10/26/2017 7:21:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2017 7:18:04 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/26/2017 7:17:31 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/26/2017 3:28:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 303ca6e7-ba34-11e7-89b3-204747d02364
Report Status: 0"
Information	10/26/2017 3:21:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2017 2:55:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/26/2017 2:50:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/26/2017 2:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/26/2017 2:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36185)(?)])(1 )(2 )]

"
Information	10/26/2017 2:50:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 2:50:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 2:50:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 2:50:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/26/2017 2:50:10 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/26/2017 2:23:17 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/26/2017 1:34:44 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/26/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]

"
Information	10/26/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36345)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 11:34:28 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8695.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
"
Information	10/26/2017 11:26:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 11:21:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2200.
Information	10/26/2017 11:21:09 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 500

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 62

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	10/26/2017 11:21:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/26/2017 11:20:38 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/26/2017 11:20:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/26/2017 11:20:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36394)(?)])(1 )(2 )]

"
Information	10/26/2017 11:20:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36394)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 11:20:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 11:20:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 11:20:37 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 11:15:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 11:15:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:10Z. Reason: GVLK.
Information	10/26/2017 11:10:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2017 11:10:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 11:10:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 11:10:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 11:09:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0df38d7d-ba10-11e7-89b3-204747d02364
Report Status: 0"
Information	10/26/2017 11:09:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0df38d7c-ba10-11e7-89b3-204747d02364
Report Status: 0"
Information	10/26/2017 11:09:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0df38d7b-ba10-11e7-89b3-204747d02364
Report Status: 0"
Error	10/26/2017 11:00:31 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/26/2017 10:56:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 10:52:01 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 5748.
Information	10/26/2017 10:52:01 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/26/2017 10:52:01 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	10/26/2017 10:52:01 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/26/2017 10:51:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36423)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 10:51:58 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/26/2017 10:51:58 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/26/2017 10:51:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:51:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 10:51:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:51:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 10:51:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 10:51:46 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:46 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:46 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/26/2017 10:51:46 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/26/2017 10:51:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:43 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:43 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/26/2017 10:51:43 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/26/2017 10:51:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/26/2017 10:51:39 AM	ESENT	102	General	Windows (7296) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/26/2017 10:51:39 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:39 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:39 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/26/2017 10:51:39 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/26/2017 10:51:19 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:15 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/26/2017 10:51:15 AM	ESENT	103	General	Windows (5744) Windows: The database engine stopped the instance (0).
Information	10/26/2017 10:51:15 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:51:15 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2200. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/26/2017 10:51:15 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/26/2017 10:50:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 5748.
Information	10/26/2017 10:49:50 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/26/2017 10:49:43 AM	ESENT	102	General	Windows (5744) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/26/2017 10:49:41 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/26/2017 10:49:41 AM	ESENT	103	General	Windows (6420) Windows: The database engine stopped the instance (0).
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:40 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:38 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:38 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/26/2017 10:49:38 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:38 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:38 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/26/2017 10:49:04 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 10:49:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:49:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 10:48:18 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	10/26/2017 10:47:50 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Information	10/26/2017 10:47:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎26T05:17:48.978723200Z.
Information	10/26/2017 10:45:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 10:40:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 10:40:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:06Z. Reason: GVLK.
Information	10/26/2017 10:40:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/26/2017 10:40:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:39:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 10:35:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2017 10:35:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 10:35:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:35:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 10:33:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/26/2017 10:33:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:20:56Z. Reason: GVLK.
Error	10/26/2017 10:28:25 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/26/2017 10:28:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4239d0a9-ba0a-11e7-89b3-204747d02364
Report Status: 0"
Information	10/26/2017 10:27:17 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/26/2017 10:26:10 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/26/2017 10:26:09 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/26/2017 10:26:07 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/26/2017 10:26:05 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/26/2017 10:25:45 AM	ESENT	302	Logging/Recovery	Windows (6420) Windows: The database engine has successfully completed recovery steps.
Information	10/26/2017 10:25:42 AM	ESENT	301	Logging/Recovery	Windows (6420) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/26/2017 10:25:41 AM	ESENT	300	Logging/Recovery	Windows (6420) Windows: The database engine is initiating recovery steps.
Information	10/26/2017 10:25:41 AM	ESENT	102	General	Windows (6420) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/26/2017 10:25:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/26/2017 10:25:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/26/2017 10:25:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/26/2017 10:25:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/26/2017 10:25:12 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8694.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
"
Information	10/26/2017 10:24:28 AM	Service1	0	None	Service started successfully.
Error	10/26/2017 10:24:24 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/26/2017 10:24:23 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/26/2017 10:24:10 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/26/2017 10:24:10 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/26/2017 10:24:04 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/26/2017 10:23:59 AM	PostgreSQL	0	None	"2017-10-26 10:23:59 IST LOG:  redirecting log output to logging collector process
2017-10-26 10:23:59 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/26/2017 10:23:57 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/26/2017 10:23:56 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/26/2017 10:23:52 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/26/2017 10:23:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/26/2017 10:23:51 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/26/2017 10:23:51 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/26/2017 10:23:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/26/2017 10:23:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/26/2017 10:23:46 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:46 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/26/2017 10:23:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/26/2017 10:23:46 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/26/2017 10:23:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/26/2017 10:23:45 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/26/2017 10:23:45 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:45 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/26/2017 10:23:44 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/26/2017 10:23:43 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/26/2017 10:23:42 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:42 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:42 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3524 at 10/18/2017 11:16:34 AM (local) 10/18/2017 5:46:34 AM (UTC). This is an informational message only; no user action is required.
Information	10/26/2017 10:23:41 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/26/2017 10:23:39 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/26/2017 10:23:39 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/26/2017 10:23:39 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/26/2017 10:23:39 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/26/2017 10:23:39 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3904.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/26/2017 10:23:38 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/26/2017 10:23:08 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/26/2017 10:22:55 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/26/2017 10:22:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/26/2017 10:22:55 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/25/2017 8:56:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e60bb2d7-b998-11e7-868b-204747d02364
Report Status: 0"
Information	10/25/2017 8:18:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 7:55:22 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/25/2017 7:21:57 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎25T13:50:26.435901800Z.
Information	10/25/2017 7:21:57 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/25/2017 7:21:57 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/25/2017 7:21:57 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	10/25/2017 7:20:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎25T13:50:26.435901800Z.
Information	10/25/2017 7:19:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/25/2017 4:59:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8694.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : Ransom-Badrabbit-FFT (ED)
Ransom-Badrabbit-FGD (ED)
Ransom-Badrabbit-FID (ED)
"
Information	10/25/2017 4:30:53 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/25/2017 4:30:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/25/2017 4:30:40 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/25/2017 4:18:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 4:18:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 3:56:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: fbc031b8-b96e-11e7-868b-204747d02364
Report Status: 0"
Information	10/25/2017 3:05:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/25/2017 3:05:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:15Z. Reason: GVLK.
Information	10/25/2017 3:00:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/25/2017 3:00:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2017 3:00:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2017 3:00:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/25/2017 1:00:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8694.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/25/2017 12:18:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 12:18:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 12:14:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/25/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/25/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]

"
Information	10/25/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/25/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/25/2017 11:55:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/25/2017 11:50:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/25/2017 11:50:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37805)(?)])(1 )(2 )]

"
Information	10/25/2017 11:50:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37805)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/25/2017 11:50:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/25/2017 11:50:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/25/2017 11:50:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/25/2017 11:36:19 AM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Information	10/25/2017 10:56:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 106ea9ac-b945-11e7-868b-204747d02364
Report Status: 0"
Information	10/25/2017 9:17:58 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/25/2017 9:17:58 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	10/25/2017 9:17:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎25T03:44:59.297542900Z.
Information	10/25/2017 9:17:49 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{6CA12C67-F4C8-4BC3-818D-27997FDBBD96}\4Sight™ 2.msi. Client Process Id: 12812.
Information	10/25/2017 9:14:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎25T03:44:59.297542900Z.
Information	10/25/2017 9:14:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{6CA12C67-F4C8-4BC3-818D-27997FDBBD96}\4Sight™ 2.msi. Client Process Id: 12812.
Information	10/25/2017 8:53:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎25T03:22:08.794284500Z.
Information	10/25/2017 8:53:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/25/2017 8:53:33 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/25/2017 8:53:33 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	10/25/2017 8:52:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎25T03:22:08.794284500Z.
Information	10/25/2017 8:50:33 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/25/2017 8:18:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 8:18:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 5:56:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2649c920-b91b-11e7-868b-204747d02364
Report Status: 0"
Information	10/25/2017 4:18:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 4:18:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 3:29:11 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/25/2017 3:00:43 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/25/2017 3:00:04 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/25/2017 12:56:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3b8d4a50-b8f1-11e7-868b-204747d02364
Report Status: 0"
Information	10/25/2017 12:18:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/25/2017 12:17:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 10:09:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 10:09:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:20:55Z. Reason: GVLK.
Information	10/24/2017 10:04:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2017 10:04:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 10:04:55 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 10:04:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 9:50:15 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/24/2017 9:46:40 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/24/2017 8:29:50 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/24/2017 8:29:50 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	10/24/2017 8:29:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎24T14:56:32.139645600Z.
Information	10/24/2017 8:29:14 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{326C5267-F9ED-4CEE-9520-D6E73C21A5A1}\4Sight™ 2.msi. Client Process Id: 1924.
Information	10/24/2017 8:26:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎24T14:56:32.139645600Z.
Information	10/24/2017 8:26:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{326C5267-F9ED-4CEE-9520-D6E73C21A5A1}\4Sight™ 2.msi. Client Process Id: 1924.
Information	10/24/2017 8:21:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎24T14:50:29.170645600Z.
Information	10/24/2017 8:21:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/24/2017 8:21:50 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/24/2017 8:21:50 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	10/24/2017 8:20:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎24T14:50:29.170645600Z.
Information	10/24/2017 8:20:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9316.
Information	10/24/2017 8:17:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 8:17:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/24/2017 8:17:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 7:56:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 51a39448-b8c7-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 7:51:16 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.75. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/24/2017 7:51:16 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	10/24/2017 7:48:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎24T14:14:17.348098400Z.
Information	10/24/2017 7:48:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{164670E5-7049-479C-94A7-6C954A8FDBB7}\4Sight™ 2.msi. Client Process Id: 17640.
Information	10/24/2017 7:44:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎24T14:14:17.348098400Z.
Information	10/24/2017 7:44:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{164670E5-7049-479C-94A7-6C954A8FDBB7}\4Sight™ 2.msi. Client Process Id: 17640.
Information	10/24/2017 6:23:40 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/24/2017 5:55:35 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/24/2017 4:37:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 4:32:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2017 4:32:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38963)(?)])(1 )(2 )]

"
Information	10/24/2017 4:32:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38963)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 4:32:21 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/24/2017 4:32:21 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 4:32:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 4:22:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 4:20:30 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 2, Deleted: 0, Modified: 13, Compared: 13865, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/24/2017 4:17:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 203

Information	10/24/2017 4:17:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 4:16:53 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/24/2017 4:16:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2017 4:16:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38978)(?)])(1 )(2 )]

"
Information	10/24/2017 4:16:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38978)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 4:16:52 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/24/2017 4:16:52 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/24/2017 4:16:36 PM	GE Software	0	(1)	++Installation complete
Information	10/24/2017 4:16:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: SkyDriveClientError
Response: Not available
Cab Id: 0

Problem signature:
P1: OneDriveSetup.exe
P2: 17.3.4604.0120
P3: OneDriveSetup.exe
P4: 17.3.4604.0120
P5: 0x80040691
P6: Installer
P7: application.cpp
P8: 151
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9b0e471e-b8a8-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 4:16:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: SkyDriveClientError
Response: Not available
Cab Id: 0

Problem signature:
P1: OneDriveSetup.exe
P2: 17.3.4604.0120
P3: OneDriveSetup.exe
P4: 17.3.4604.0120
P5: 0x80040691
P6: Installer
P7: setupengineimpl.cpp
P8: 815
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9b0e471d-b8a8-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 4:16:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: SkyDriveClientError
Response: Not available
Cab Id: 0

Problem signature:
P1: OneDriveSetup.exe
P2: 17.3.4604.0120
P3: OneDriveSetup.exe
P4: 17.3.4604.0120
P5: 0x80040691
P6: Installer
P7: application.cpp
P8: 151
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ab59fce-b8a8-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 4:16:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: SkyDriveClientError
Response: Not available
Cab Id: 0

Problem signature:
P1: OneDriveSetup.exe
P2: 17.3.4604.0120
P3: OneDriveSetup.exe
P4: 17.3.4604.0120
P5: 0x80004004
P6: Installer
P7: setupengineimpl.cpp
P8: 815
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ab59fcd-b8a8-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 4:16:33 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	10/24/2017 4:16:21 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/24/2017 4:16:21 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:16:21 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/24/2017 4:16:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:21 PM	ESENT	102	General	Windows (13824) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/24/2017 4:16:21 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:21 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:16:21 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/24/2017 4:16:08 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:04 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/24/2017 4:16:04 PM	ESENT	103	General	Windows (17912) Windows: The database engine stopped the instance (0).
Information	10/24/2017 4:16:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Microsoft Office\root\Integration\C2RInt64.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:04 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:16:04 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/24/2017 4:16:04 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/24/2017 4:16:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Microsoft Office\root\Integration\C2RInt64.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:04 PM	ESENT	102	General	Windows (17912) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/24/2017 4:16:03 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Microsoft Office\root\Integration\C2RInt.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:16:03 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:16:03 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/24/2017 4:15:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Microsoft Office\root\Integration\C2RInt.16.msi. Client Process Id: 16700.
Information	10/24/2017 4:15:47 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/24/2017 4:15:47 PM	ESENT	103	General	Windows (17988) Windows: The database engine stopped the instance (0).
Information	10/24/2017 4:15:43 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/24/2017 4:15:42 PM	ESENT	102	General	Windows (17988) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/24/2017 4:15:39 PM	ESENT	103	General	Windows (10904) Windows: The database engine stopped the instance (0).
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:15:39 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	10/24/2017 4:12:24 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	10/24/2017 4:12:23 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	10/24/2017 4:12:22 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/24/2017 4:12:21 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/24/2017 4:12:20 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/24/2017 4:12:20 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/24/2017 4:12:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/24/2017 4:12:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 4:12:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 4:11:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 15280.
Information	10/24/2017 4:11:54 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:11:54 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/24/2017 4:11:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 15280.
Information	10/24/2017 4:11:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 15280.
Information	10/24/2017 4:11:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/24/2017 4:11:53 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/24/2017 4:11:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 15280.
Information	10/24/2017 4:11:30 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/24/2017 4:11:20 PM	ESENT	102	General	Windows (10904) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/24/2017 4:11:18 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/24/2017 4:11:17 PM	ESENT	103	General	Windows (6936) Windows: The database engine stopped the instance (0).
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:16 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:15 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:15 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/24/2017 4:11:15 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:15 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:11:15 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/24/2017 4:07:20 PM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Information	10/24/2017 4:07:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎24T10:37:18.202617300Z.
Information	10/24/2017 4:05:15 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	10/24/2017 4:05:15 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	10/24/2017 4:05:14 PM	GE Software	0	(1)	++No Install Check was performed.
Information	10/24/2017 4:05:09 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	10/24/2017 4:05:09 PM	GE Software	0	(1)	++Started the installation of Microsoft Skype For Business 2016 V08 with the following commandline: /P /IC
Information	10/24/2017 4:05:09 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: 212558710.
Information	10/24/2017 2:56:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 66596997-b89d-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 2:51:24 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/24/2017 2:50:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/24/2017 2:39:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 2:33:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2017 2:33:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39081)(?)])(1 )(2 )]

"
Information	10/24/2017 2:33:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39081)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 2:33:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/24/2017 2:33:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 2:33:51 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 1:48:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 1:46:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 12:31:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8693.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/24/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39225)(?)])(1 )(2 )]

"
Information	10/24/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39225)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/24/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 10:51:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 10:51:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:21:17Z. Reason: GVLK.
Information	10/24/2017 10:46:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2017 10:46:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 10:46:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 10:46:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 10:34:20 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎24T05:04:20.755007300Z.
Information	10/24/2017 9:56:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 9:56:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-31T04:20:52Z. Reason: GVLK.
Information	10/24/2017 9:56:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7a4bb342-b873-11e7-868b-204747d02364
Report Status: 0"
Information	10/24/2017 9:56:07 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/24/2017 9:56:07 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/24/2017 9:56:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/24/2017 9:55:54 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/24/2017 9:55:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/24/2017 9:55:44 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 35, Deleted: 0, Modified: 550, Compared: 13853, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/24/2017 9:52:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/24/2017 9:51:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 9:51:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 9:51:52 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/10/24 04:21"
Information	10/24/2017 9:51:46 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/10/24 04:21, 0, 1, 242040, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/24/2017 9:48:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 9:48:14 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/24/2017 9:48:12 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/24/2017 9:47:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/24/2017 9:47:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39368)(?)])(1 )(2 )]

"
Information	10/24/2017 9:47:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39368)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 9:47:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/24/2017 9:47:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 9:47:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 9:46:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/24/2017 9:46:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/24/2017 9:46:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 242100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/24/2017 9:46:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/24/2017 9:46:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/24/2017 9:46:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/24/2017 9:46:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/24/2017 9:46:07 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/18/2017 4:19:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f77c3712-b3f1-11e7-868b-204747d02364
Report Status: 0"
Information	10/18/2017 3:28:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/18/2017 2:05:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 2:05:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:28Z. Reason: GVLK.
Information	10/18/2017 2:00:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2017 2:00:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 2:00:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 2:00:18 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 12:38:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 12:33:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2017 12:33:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 12:33:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 12:31:11 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8687.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/18/2017 12:22:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 12:22:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:44Z. Reason: GVLK.
Information	10/18/2017 12:17:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2017 12:17:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 12:17:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 12:17:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 12:16:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15a944a1-b3d0-11e7-868b-204747d02364
Report Status: 0"
Information	10/18/2017 12:16:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15a944a0-b3d0-11e7-868b-204747d02364
Report Status: 0"
Information	10/18/2017 12:16:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15a9449f-b3d0-11e7-868b-204747d02364
Report Status: 0"
Information	10/18/2017 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/18/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47865)(?)])(1 )(2 )]

"
Information	10/18/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47865)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 12:09:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2017 12:09:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 12:08:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 12:03:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2017 12:03:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 12:03:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/18/2017 11:57:19 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/18/2017 11:38:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 11:32:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 11:32:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:35Z. Reason: GVLK.
Information	10/18/2017 11:29:01 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 15

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 234

Information	10/18/2017 11:28:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/18/2017 11:28:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/18/2017 11:28:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47907)(?)])(1 )(2 )]

"
Information	10/18/2017 11:28:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47907)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 11:28:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/18/2017 11:28:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 11:28:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 11:27:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2017 11:27:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 11:27:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 11:27:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 11:25:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/18/2017 11:25:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:04Z. Reason: GVLK.
Error	10/18/2017 11:20:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/18/2017 11:19:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bf71510-b3c8-11e7-868b-204747d02364
Report Status: 0"
Information	10/18/2017 11:19:02 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/18/2017 11:18:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/18/2017 11:18:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/18/2017 11:18:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/18/2017 11:18:35 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2017 11:18:33 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2017 11:18:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/18/2017 11:18:31 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2017 11:18:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/18/2017 11:18:01 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/18/2017 11:18:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/18/2017 11:18:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	10/18/2017 11:17:51 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <GPClient> took 118 second(s) to handle the notification event (CreateSession).
Information	10/18/2017 11:17:37 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/18/2017 11:17:28 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/18/2017 11:17:21 AM	ESENT	302	Logging/Recovery	Windows (6936) Windows: The database engine has successfully completed recovery steps.
Information	10/18/2017 11:17:20 AM	ESENT	301	Logging/Recovery	Windows (6936) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/18/2017 11:17:18 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8686.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/18/2017 11:17:17 AM	ESENT	301	Logging/Recovery	Windows (6936) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0555D.log.
Information	10/18/2017 11:17:17 AM	ESENT	300	Logging/Recovery	Windows (6936) Windows: The database engine is initiating recovery steps.
Information	10/18/2017 11:17:17 AM	ESENT	102	General	Windows (6936) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/18/2017 11:16:57 AM	Service1	0	None	Service started successfully.
Warning	10/18/2017 11:16:53 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession).
Error	10/18/2017 11:16:52 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/18/2017 11:16:50 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/18/2017 11:16:44 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/18/2017 11:16:44 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/18/2017 11:16:43 AM	PostgreSQL	0	None	"2017-10-18 11:16:43 IST LOG:  redirecting log output to logging collector process
2017-10-18 11:16:43 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/18/2017 11:16:43 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/18/2017 11:16:42 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/18/2017 11:16:41 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/18/2017 11:16:38 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/18/2017 11:16:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/18/2017 11:16:36 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/18/2017 11:16:36 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/18/2017 11:16:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/18/2017 11:16:34 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3380 at 10/17/2017 8:37:44 PM (local) 10/17/2017 3:07:44 PM (UTC). This is an informational message only; no user action is required.
Information	10/18/2017 11:16:32 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/18/2017 11:16:32 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/18/2017 11:16:32 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/18/2017 11:16:32 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/18/2017 11:16:32 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3524.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/18/2017 11:16:31 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/18/2017 11:16:04 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/18/2017 11:15:52 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/18/2017 11:15:53 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/18/2017 11:15:52 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/17/2017 8:38:01 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/17/2017 8:37:44 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/17/2017 8:37:41 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 908 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1904 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/17/2017 8:37:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/17/2017 8:37:40 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/17/2017 8:37:40 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/17/2017 8:37:35 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/17/2017 8:26:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4dc39c06-b34b-11e7-af47-0205857feb80
Report Status: 0"
Information	10/17/2017 7:06:11 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Error	10/17/2017 6:56:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/17/2017 6:56:17 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/17/2017 5:36:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2017 5:24:21 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/17/2017 5:23:41 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/17/2017 5:23:41 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/17/2017 3:26:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 63e91375-b321-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 3:20:52 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceManager. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	10/17/2017 1:36:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2017 12:54:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8686.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/17/2017 12:14:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49305)(?)])(1 )(2 )]

"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49305)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 11:01:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 11:01:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:34Z. Reason: GVLK.
Information	10/17/2017 10:56:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2017 10:56:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 10:56:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 10:56:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 10:52:29 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 10:47:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/17/2017 10:47:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49388)(?)])(1 )(2 )]

"
Information	10/17/2017 10:47:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49388)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 10:47:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/17/2017 10:47:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 10:47:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 10:26:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 791b47fb-b2f7-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 9:36:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2017 6:47:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 6:47:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:16Z. Reason: GVLK.
Information	10/17/2017 6:42:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2017 6:42:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 6:42:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 6:42:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 5:36:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2017 5:26:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8eb7c3f7-b2cd-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 4:47:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 4:42:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/17/2017 4:42:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 4:42:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 4:00:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 4:00:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:02Z. Reason: GVLK.
Information	10/17/2017 3:55:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2017 3:55:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 3:55:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 3:55:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 3:54:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cba485d4-b2c0-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 3:54:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cba485d3-b2c0-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 3:54:38 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cba485d2-b2c0-11e7-af47-204747d02364
Report Status: 0"
Error	10/17/2017 3:51:34 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/17/2017 3:44:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/17/2017 3:44:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:42Z. Reason: GVLK.
Error	10/17/2017 3:39:57 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/17/2017 3:39:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/17/2017 3:39:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/17/2017 3:39:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/17/2017 3:39:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/17/2017 1:46:28 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/17/2017 1:35:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/17/2017 12:25:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a441103a-b2a3-11e7-af47-204747d02364
Report Status: 0"
Information	10/17/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/16/2017 10:06:11 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/16/2017 9:35:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2017 9:00:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 9:00:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:16Z. Reason: GVLK.
Information	10/16/2017 8:55:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 8:55:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 8:55:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 8:55:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 8:02:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 7:57:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50278)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 7:57:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50278)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 7:57:14 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/16/2017 7:57:14 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/16/2017 7:57:14 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	10/16/2017 7:57:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 7:57:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 7:57:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 7:25:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ba37942c-b279-11e7-af47-204747d02364
Report Status: 0"
Information	10/16/2017 6:43:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 6:38:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 6:38:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 6:38:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 6:13:37 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 6:08:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 6:08:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 6:08:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 5:43:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 5:35:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 374

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 671

Information	10/16/2017 5:35:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2017 5:35:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 5:35:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50420)(?)])(1 )(2 )]

"
Information	10/16/2017 5:35:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50420)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 5:35:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 5:35:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 5:35:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 5:31:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 5:31:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:13Z. Reason: GVLK.
Information	10/16/2017 5:25:27 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/16/2017 5:24:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8685.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/16/2017 5:24:09 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 5:24:09 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 5:24:08 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 5:24:07 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/16/2017 5:23:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 5:23:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 5:23:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 5:23:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 5:23:32 PM	ESENT	302	Logging/Recovery	Windows (7344) Windows: The database engine has successfully completed recovery steps.
Information	10/16/2017 5:23:29 PM	ESENT	301	Logging/Recovery	Windows (7344) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/16/2017 5:23:26 PM	ESENT	301	Logging/Recovery	Windows (7344) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05556.log.
Information	10/16/2017 5:23:25 PM	ESENT	300	Logging/Recovery	Windows (7344) Windows: The database engine is initiating recovery steps.
Information	10/16/2017 5:23:25 PM	ESENT	102	General	Windows (7344) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/16/2017 5:23:11 PM	Service1	0	None	Service started successfully.
Error	10/16/2017 5:23:08 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/16/2017 5:23:07 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/16/2017 5:23:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/16/2017 5:23:07 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/16/2017 5:23:07 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/16/2017 5:23:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/16/2017 5:23:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/16/2017 5:23:05 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/16/2017 5:23:05 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/16/2017 5:23:04 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/16/2017 5:23:01 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/16/2017 5:23:00 PM	PostgreSQL	0	None	"2017-10-16 17:23:00 IST LOG:  redirecting log output to logging collector process
2017-10-16 17:23:00 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/16/2017 5:22:59 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/16/2017 5:22:57 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3680 at 10/16/2017 1:52:19 PM (local) 10/16/2017 8:22:19 AM (UTC). This is an informational message only; no user action is required.
Information	10/16/2017 5:22:56 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/16/2017 5:22:55 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/16/2017 5:22:55 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/16/2017 5:22:55 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/16/2017 5:22:55 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/16/2017 5:22:55 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3380.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/16/2017 5:22:54 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/16/2017 5:22:47 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/16/2017 5:22:42 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 5:22:36 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/16/2017 5:22:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/16/2017 5:22:36 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/16/2017 4:56:54 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/16/2017 4:56:52 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/16/2017 3:13:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 3:08:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 3:08:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 3:08:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 2:43:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 2:38:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 2:38:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 2:38:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 2:25:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d05b55b7-b24f-11e7-8559-204747d02364
Report Status: 0"
Information	10/16/2017 2:13:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 2:08:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 2:08:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 2:08:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 2:06:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/16/2017 2:03:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	10/16/2017 2:03:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/16/2017 2:03:35 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/16/2017 2:02:59 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 7, Deleted: 0, Modified: 13, Compared: 13704, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/16/2017 2:01:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50633)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 2:01:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50633)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 2:01:55 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/16/2017 2:01:54 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/16/2017 2:01:53 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	10/16/2017 2:01:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 2:01:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:55Z. Reason: GVLK.
Information	10/16/2017 2:00:51 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 109

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 203

Information	10/16/2017 2:00:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2017 2:00:10 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/16/2017 2:00:09 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/16/2017 2:00:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 2:00:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50635)(?)])(1 )(2 )]

"
Information	10/16/2017 2:00:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50635)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 1:59:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 1:59:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 1:59:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 1:55:09 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/16/2017 1:53:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8685.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/16/2017 1:53:18 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 1:53:18 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 1:53:17 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 1:53:16 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/16/2017 1:53:08 PM	ESENT	302	Logging/Recovery	Windows (7304) Windows: The database engine has successfully completed recovery steps.
Information	10/16/2017 1:53:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 1:53:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 1:53:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 1:53:03 PM	ESENT	301	Logging/Recovery	Windows (7304) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/16/2017 1:53:03 PM	ESENT	300	Logging/Recovery	Windows (7304) Windows: The database engine is initiating recovery steps.
Information	10/16/2017 1:53:03 PM	ESENT	102	General	Windows (7304) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/16/2017 1:53:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 1:52:48 PM	Service1	0	None	Service started successfully.
Error	10/16/2017 1:52:41 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/16/2017 1:52:41 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/16/2017 1:52:36 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/16/2017 1:52:31 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/16/2017 1:52:31 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/16/2017 1:52:30 PM	PostgreSQL	0	None	"2017-10-16 13:52:30 IST LOG:  redirecting log output to logging collector process
2017-10-16 13:52:30 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/16/2017 1:52:29 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/16/2017 1:52:28 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/16/2017 1:52:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/16/2017 1:52:27 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/16/2017 1:52:27 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/16/2017 1:52:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/16/2017 1:52:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/16/2017 1:52:24 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/16/2017 1:52:23 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/16/2017 1:52:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/16/2017 1:52:23 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:23 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/16/2017 1:52:22 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/16/2017 1:52:22 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/16/2017 1:52:22 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/16/2017 1:52:20 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:20 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3824 at 10/16/2017 9:23:58 AM (local) 10/16/2017 3:53:58 AM (UTC). This is an informational message only; no user action is required.
Information	10/16/2017 1:52:19 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/16/2017 1:52:18 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/16/2017 1:52:18 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/16/2017 1:52:18 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/16/2017 1:52:18 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/16/2017 1:52:18 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3680.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/16/2017 1:52:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/16/2017 1:52:03 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/16/2017 1:52:00 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 1:51:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/16/2017 1:51:38 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/16/2017 1:51:38 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/16/2017 12:19:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 12:14:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 12:14:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50741)(?)])(1 )(2 )]

"
Information	10/16/2017 12:14:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50741)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 12:09:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 12:09:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50745)(?)])(1 )(2 )]

"
Information	10/16/2017 12:09:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50745)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 12:09:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 12:09:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 12:09:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 12:09:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8685.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Exploit-CVE2017-11826 (ED)
"
Information	10/16/2017 11:45:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 11:45:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:47Z. Reason: GVLK.
Information	10/16/2017 11:40:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 11:40:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 11:40:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 11:40:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 10:44:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 10:39:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 10:39:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 10:39:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 10:21:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 10:21:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:09Z. Reason: GVLK.
Information	10/16/2017 10:20:50 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/16/2017 10:20:38 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 65, Deleted: 0, Modified: 759, Compared: 13701, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/16/2017 10:19:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 10:16:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2017 10:16:31 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/16/2017 10:16:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 10:16:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 10:16:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 10:16:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 10:15:08 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 32

Information	10/16/2017 10:14:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/16/2017 10:14:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/16/2017 10:14:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/16/2017 10:14:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 10:14:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50861)(?)])(1 )(2 )]

"
Information	10/16/2017 10:14:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50861)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 10:12:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ba4c758-b22c-11e7-bd3c-204747d02364
Report Status: 0"
Information	10/16/2017 10:12:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ba4c757-b22c-11e7-bd3c-204747d02364
Report Status: 0"
Information	10/16/2017 10:12:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ba4c756-b22c-11e7-bd3c-204747d02364
Report Status: 0"
Information	10/16/2017 10:11:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8685.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/16/2017 10:09:47 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 10:09:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 10:09:47 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	10/16/2017 10:04:32 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/16/2017 9:44:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 9:39:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 9:39:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:47Z. Reason: GVLK.
Information	10/16/2017 9:39:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 9:39:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 9:39:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 9:38:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/16/2017 9:34:46 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/16/2017 9:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/16/2017 9:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50901)(?)])(1 )(2 )]

"
Information	10/16/2017 9:33:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50901)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 9:33:54 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/16/2017 9:33:54 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 9:33:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 9:32:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 9:32:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 9:32:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 9:32:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 9:30:36 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/16/2017 9:30:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:31Z. Reason: GVLK.
Information	10/16/2017 9:26:35 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/16/2017 9:25:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e5c9c2f8-b225-11e7-bd3c-204747d02364
Report Status: 0"
Information	10/16/2017 9:25:33 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8684.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/16/2017 9:25:22 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 9:25:21 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 9:25:21 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 9:25:20 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/16/2017 9:24:46 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/16/2017 9:24:45 AM	ESENT	302	Logging/Recovery	Windows (7268) Windows: The database engine has successfully completed recovery steps.
Information	10/16/2017 9:24:44 AM	ESENT	301	Logging/Recovery	Windows (7268) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/16/2017 9:24:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/16/2017 9:24:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/16/2017 9:24:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/16/2017 9:24:34 AM	ESENT	301	Logging/Recovery	Windows (7268) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0553F.log.
Information	10/16/2017 9:24:33 AM	ESENT	300	Logging/Recovery	Windows (7268) Windows: The database engine is initiating recovery steps.
Information	10/16/2017 9:24:33 AM	ESENT	102	General	Windows (7268) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/16/2017 9:24:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/16/2017 9:24:15 AM	Service1	0	None	Service started successfully.
Error	10/16/2017 9:24:10 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/16/2017 9:24:10 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/16/2017 9:24:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/16/2017 9:24:07 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/16/2017 9:24:07 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/16/2017 9:24:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/16/2017 9:24:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/16/2017 9:24:07 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/16/2017 9:24:04 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/16/2017 9:24:04 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/16/2017 9:24:04 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/16/2017 9:24:04 AM	PostgreSQL	0	None	"2017-10-16 09:24:04 IST LOG:  redirecting log output to logging collector process
2017-10-16 09:24:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/16/2017 9:24:02 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/16/2017 9:24:01 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 9:24:00 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 9:23:59 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3644 at 10/15/2017 9:36:51 AM (local) 10/15/2017 4:06:51 AM (UTC). This is an informational message only; no user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/16/2017 9:23:58 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3824.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/16/2017 9:23:56 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/16/2017 9:23:45 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/16/2017 9:23:36 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/16/2017 9:23:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/16/2017 9:23:36 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/15/2017 10:57:27 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/15/2017 10:52:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/15/2017 10:52:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2017 10:52:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/15/2017 10:38:10 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8684.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/15/2017 10:27:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/15/2017 10:22:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/15/2017 10:22:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2017 10:22:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/15/2017 9:57:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/15/2017 9:51:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2017 9:51:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:59Z. Reason: GVLK.
Information	10/15/2017 9:47:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/15/2017 9:47:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52328)(?)])(1 )(2 )]

"
Information	10/15/2017 9:47:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52328)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2017 9:47:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/15/2017 9:47:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2017 9:47:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/15/2017 9:45:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2017 9:45:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2017 9:45:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2017 9:45:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/15/2017 9:45:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/15/2017 9:45:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:04Z. Reason: GVLK.
Information	10/15/2017 9:40:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c7954fe6-b15e-11e7-93b5-204747d02364
Report Status: 0"
Information	10/15/2017 9:39:19 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/15/2017 9:38:36 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/15/2017 9:38:35 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/15/2017 9:38:34 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/15/2017 9:38:32 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/15/2017 9:38:26 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8682.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/15/2017 9:38:08 AM	ESENT	302	Logging/Recovery	Windows (3192) Windows: The database engine has successfully completed recovery steps.
Information	10/15/2017 9:38:05 AM	ESENT	301	Logging/Recovery	Windows (3192) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/15/2017 9:37:57 AM	ESENT	301	Logging/Recovery	Windows (3192) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0553E.log.
Information	10/15/2017 9:37:57 AM	ESENT	300	Logging/Recovery	Windows (3192) Windows: The database engine is initiating recovery steps.
Information	10/15/2017 9:37:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/15/2017 9:37:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/15/2017 9:37:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/15/2017 9:37:57 AM	ESENT	102	General	Windows (3192) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/15/2017 9:37:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/15/2017 9:37:17 AM	Service1	0	None	Service started successfully.
Information	10/15/2017 9:37:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/15/2017 9:37:09 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/15/2017 9:37:09 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/15/2017 9:37:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/15/2017 9:37:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	10/15/2017 9:37:08 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/15/2017 9:37:08 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/15/2017 9:37:04 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/15/2017 9:37:03 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/15/2017 9:37:03 AM	PostgreSQL	0	None	"2017-10-15 09:37:03 IST LOG:  redirecting log output to logging collector process
2017-10-15 09:37:03 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/15/2017 9:37:02 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/15/2017 9:37:00 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/15/2017 9:36:57 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:56 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/15/2017 9:36:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/15/2017 9:36:54 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:54 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/15/2017 9:36:54 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/15/2017 9:36:54 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/15/2017 9:36:54 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/15/2017 9:36:52 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:52 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:52 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3612 at 10/13/2017 4:52:49 PM (local) 10/13/2017 11:22:49 AM (UTC). This is an informational message only; no user action is required.
Information	10/15/2017 9:36:51 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/15/2017 9:36:50 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/15/2017 9:36:46 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/15/2017 9:36:46 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/15/2017 9:36:46 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/15/2017 9:36:46 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3644.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/15/2017 9:36:45 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/15/2017 9:36:32 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/15/2017 9:36:26 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/15/2017 9:36:16 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/15/2017 9:36:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/15/2017 9:36:16 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/13/2017 4:52:49 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/13/2017 4:52:49 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/13/2017 4:52:48 PM	McLogEvent	257	None	The scan of C:\Windows\System32\en-US\tzres.dll.mui has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8682.0000.
Warning	10/13/2017 4:52:46 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 28 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 940 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/13/2017 4:52:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/13/2017 4:52:44 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/13/2017 4:52:44 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/13/2017 4:52:42 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: chrome.exe.
Information	10/13/2017 4:52:39 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/13/2017 4:03:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 4:03:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:47Z. Reason: GVLK.
Information	10/13/2017 3:58:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2017 3:58:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 3:58:47 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 3:58:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 2:58:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 2:58:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:23Z. Reason: GVLK.
Information	10/13/2017 2:53:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2017 2:53:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 2:53:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 2:53:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 2:38:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 083295a1-aff6-11e7-acc8-204747d02364
Report Status: 0"
Information	10/13/2017 12:34:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8682.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/13/2017 12:14:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/13/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]

"
Information	10/13/2017 12:09:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55065)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/13/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 12:09:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 9:38:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b9ed56a-afcc-11e7-acc8-204747d02364
Report Status: 0"
Information	10/13/2017 8:19:05 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/13/2017 7:26:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 7:26:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:56Z. Reason: GVLK.
Information	10/13/2017 7:21:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2017 7:21:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 7:21:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 7:21:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 4:38:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 312868eb-afa2-11e7-acc8-204747d02364
Report Status: 0"
Information	10/13/2017 4:29:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 4:24:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/13/2017 4:24:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 4:24:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 4:14:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 4:14:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:43Z. Reason: GVLK.
Information	10/13/2017 4:09:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2017 4:09:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 4:09:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 4:09:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 4:09:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 260300fd-af9e-11e7-acc8-204747d02364
Report Status: 0"
Information	10/13/2017 4:09:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 260300fc-af9e-11e7-acc8-204747d02364
Report Status: 0"
Information	10/13/2017 4:09:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 260300fb-af9e-11e7-acc8-204747d02364
Report Status: 0"
Error	10/13/2017 4:06:07 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/13/2017 3:58:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/13/2017 3:58:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:17:10Z. Reason: GVLK.
Error	10/13/2017 3:53:40 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/13/2017 3:53:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/13/2017 3:53:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/13/2017 3:53:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/13/2017 3:53:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/13/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/12/2017 11:37:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46c9be24-af78-11e7-acc8-204747d02364
Report Status: 0"
Information	10/12/2017 9:13:49 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/12/2017 7:55:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 7:50:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 7:50:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 7:50:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 7:25:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 7:20:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 7:20:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 7:20:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 6:55:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 6:50:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 6:50:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 6:50:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 6:41:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 6:41:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:46Z. Reason: GVLK.
Information	10/12/2017 6:40:32 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	10/12/2017 6:40:31 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	10/12/2017 6:37:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5becc158-af4e-11e7-acc8-204747d02364
Report Status: 0"
Information	10/12/2017 6:36:00 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/12/2017 6:35:48 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/12/2017 6:35:46 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/12/2017 6:35:44 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/12/2017 6:35:13 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/12/2017 6:35:13 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/12/2017 6:35:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/12/2017 6:35:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/12/2017 6:34:21 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/12/2017 6:34:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 6:34:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 6:34:01 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	10/12/2017 6:34:00 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	10/12/2017 6:34:00 PM	ESENT	302	Logging/Recovery	Windows (6932) Windows: The database engine has successfully completed recovery steps.
Information	10/12/2017 6:34:00 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	10/12/2017 6:33:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 6:33:57 PM	ESENT	301	Logging/Recovery	Windows (6932) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/12/2017 6:33:57 PM	ESENT	300	Logging/Recovery	Windows (6932) Windows: The database engine is initiating recovery steps.
Information	10/12/2017 6:33:57 PM	ESENT	102	General	Windows (6932) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/12/2017 6:33:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 6:33:41 PM	Service1	0	None	Service started successfully.
Error	10/12/2017 6:33:34 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/12/2017 6:33:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8681.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/12/2017 6:33:33 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/12/2017 6:33:32 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/12/2017 6:33:14 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/12/2017 6:33:13 PM	PostgreSQL	0	None	"2017-10-12 18:33:13 IST LOG:  redirecting log output to logging collector process
2017-10-12 18:33:13 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/12/2017 6:33:13 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/12/2017 6:33:12 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/12/2017 6:33:11 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/12/2017 6:33:11 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/12/2017 6:33:06 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/12/2017 6:33:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/12/2017 6:33:04 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/12/2017 6:33:03 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3484 at 10/10/2017 11:26:36 AM (local) 10/10/2017 5:56:36 AM (UTC). This is an informational message only; no user action is required.
Information	10/12/2017 6:32:58 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/12/2017 6:32:55 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/12/2017 6:32:55 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/12/2017 6:32:55 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/12/2017 6:32:55 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/12/2017 6:32:55 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3612.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/12/2017 6:32:54 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/12/2017 6:32:11 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/12/2017 6:31:24 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/12/2017 6:30:57 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/12/2017 6:30:25 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/12/2017 4:55:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 4:50:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2017 4:50:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56225)(?)])(1 )(2 )]

"
Information	10/12/2017 4:50:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56225)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 4:50:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 4:50:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 4:50:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 4:05:56 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/12/2017 3:09:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2017 1:31:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 859b195d-af23-11e7-9823-204747d02364
Report Status: 0"
Information	10/12/2017 1:11:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 1:06:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2017 1:06:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56449)(?)])(1 )(2 )]

"
Information	10/12/2017 1:06:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56449)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 1:06:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 1:06:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 1:06:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 1:00:26 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/12/2017 12:16:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8681.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/12/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]

"
Information	10/12/2017 12:09:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56505)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 12:09:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 12:09:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 12:09:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 11:52:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 11:52:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-19T06:16:26Z. Reason: GVLK.
Information	10/12/2017 11:47:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 11:47:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 11:47:25 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/10/12 06:17"
Information	10/12/2017 11:47:25 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/10/12 06:17, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/12/2017 11:42:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 11:42:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 11:42:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 11:42:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 11:33:34 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/12/2017 11:28:06 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/12/2017 11:09:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2017 11:09:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2017 10:55:44 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 10:50:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/12/2017 10:50:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56584)(?)])(1 )(2 )]

"
Information	10/12/2017 10:50:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56584)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 10:50:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/12/2017 10:50:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 10:50:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 9:34:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 9:34:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:21Z. Reason: GVLK.
Information	10/12/2017 9:29:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 9:29:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 9:29:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 9:29:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 8:31:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 99614c94-aef9-11e7-9823-204747d02364
Report Status: 0"
Information	10/12/2017 7:51:08 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/12/2017 7:50:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/12/2017 7:09:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2017 5:56:58 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/12/2017 5:56:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/12/2017 4:51:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 4:51:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:47Z. Reason: GVLK.
Information	10/12/2017 4:46:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 4:46:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 4:46:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 4:46:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 4:46:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2819bf91-aeda-11e7-9823-204747d02364
Report Status: 0"
Information	10/12/2017 4:46:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2819bf90-aeda-11e7-9823-204747d02364
Report Status: 0"
Information	10/12/2017 4:46:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2819bf8f-aeda-11e7-9823-204747d02364
Report Status: 0"
Error	10/12/2017 4:39:29 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/12/2017 4:30:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 4:30:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:13Z. Reason: GVLK.
Error	10/12/2017 4:25:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/12/2017 4:25:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 4:25:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 4:25:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 4:25:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 3:31:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: afd76988-aecf-11e7-9823-204747d02364
Report Status: 0"
Information	10/12/2017 3:09:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/12/2017 3:01:45 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/12/2017 3:00:59 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	10/12/2017 2:49:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/12/2017 2:49:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:52Z. Reason: GVLK.
Information	10/12/2017 2:44:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/12/2017 2:44:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/12/2017 2:44:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/12/2017 2:44:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/12/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/11/2017 11:13:14 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/11/2017 11:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 10:31:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c620233d-aea5-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 7:09:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 6:01:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 5:55:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/11/2017 5:55:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57599)(?)])(1 )(2 )]

"
Information	10/11/2017 5:55:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57599)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 5:55:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/11/2017 5:55:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 5:55:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 5:48:11 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 5:48:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:11Z. Reason: GVLK.
Information	10/11/2017 5:43:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 5:43:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 5:43:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 5:43:10 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 5:34:30 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/11/2017 5:30:59 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7be873a-ae7b-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 5:23:57 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/11/2017 5:20:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 5:20:29 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:26Z. Reason: GVLK.
Information	10/11/2017 5:15:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 5:15:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 5:15:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 5:15:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 3:09:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 3:09:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 12:42:26 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8680.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/11/2017 12:30:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d882042c-ae51-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 12:14:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57945)(?)])(1 )(2 )]

"
Information	10/11/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 57945)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/11/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 11:47:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/11/2017 11:47:04 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/11/2017 11:47:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/11/2017 11:09:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 11:09:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 10:37:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 10:37:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:33Z. Reason: GVLK.
Information	10/11/2017 10:32:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 10:32:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 10:32:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 10:32:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 10:00:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58079)(?)])(1 )(2 )]

"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58079)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 9:55:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 9:29:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 9:29:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:52Z. Reason: GVLK.
Information	10/11/2017 9:24:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 9:24:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 9:24:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 9:24:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 7:30:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: edab82f8-ae27-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 7:09:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 7:09:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 5:34:55 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/11/2017 5:27:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 5:27:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:28Z. Reason: GVLK.
Information	10/11/2017 5:22:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 5:22:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 5:22:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 5:22:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 5:18:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8db71c49-ae15-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 5:18:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8db71c48-ae15-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 5:18:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8db71c47-ae15-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 5:09:58 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	10/11/2017 5:04:51 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Error	10/11/2017 4:50:56 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/11/2017 3:51:18 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/11/2017 3:51:10 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/11/2017 3:41:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 3:41:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:00Z. Reason: GVLK.
Information	10/11/2017 3:36:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 3:36:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 3:36:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 3:35:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 3:23:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/11/2017 3:23:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:34Z. Reason: GVLK.
Error	10/11/2017 3:20:19 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/11/2017 3:18:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/11/2017 3:18:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/11/2017 3:18:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/11/2017 3:18:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/11/2017 3:09:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 3:08:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/11/2017 2:30:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0375b477-adfe-11e7-9823-204747d02364
Report Status: 0"
Information	10/11/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/10/2017 11:09:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 11:08:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 9:30:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18fcc639-add4-11e7-9823-204747d02364
Report Status: 0"
Information	10/10/2017 8:30:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/10/2017 8:30:19 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/10/2017 7:09:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 7:08:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 7:05:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 7:00:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 7:00:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58974)(?)])(1 )(2 )]

"
Information	10/10/2017 7:00:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58974)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 7:00:51 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 7:00:51 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 7:00:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 5:22:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/10/2017 5:22:31 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/10/2017 4:30:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2e97ff35-adaa-11e7-9823-204747d02364
Report Status: 0"
Information	10/10/2017 3:25:44 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/10/2017 3:25:44 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/10/2017 3:13:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 3:09:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 78

Information	10/10/2017 3:09:43 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 54, Deleted: 1, Modified: 4, Compared: 12714, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/10/2017 3:08:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 3:08:50 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/10/2017 3:08:48 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 671

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 1841

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 374

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 265

Warning	10/10/2017 3:08:48 PM	Outlook	59	None	Outlook disabled the following add-in(s):



ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
Load Behavior: 3
HKLM: 1
Location: c:\program files (x86)\microsoft office\root\office16\ucaddin.dll
Threshold Time (Milliseconds): 1000
Time Taken (Milliseconds): 1217
Disable Reason: This add-in caused Outlook to start slowly.
Policy Exception (Allow List): 0 
Information	10/10/2017 3:08:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/10/2017 3:08:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 3:08:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59207)(?)])(1 )(2 )]

"
Information	10/10/2017 3:08:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59207)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59209)(?)])(1 )(2 )]

"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59209)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 3:05:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 2:45:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 2:39:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 2:39:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59235)(?)])(1 )(2 )]

"
Information	10/10/2017 2:39:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59235)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 2:39:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 2:39:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 2:39:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 2:25:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 2:20:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 2:20:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59254)(?)])(1 )(2 )]

"
Information	10/10/2017 2:20:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59254)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 2:20:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 2:20:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 2:20:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 1:46:20 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/10/2017 1:15:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 1:15:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:21Z. Reason: GVLK.
Information	10/10/2017 1:10:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2017 1:10:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 1:10:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 1:10:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 1:06:15 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/10/2017 12:57:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 12:51:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 12:51:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59343)(?)])(1 )(2 )]

"
Information	10/10/2017 12:51:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59343)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 12:51:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 12:51:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 12:51:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 12:47:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 12:42:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 12:42:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 12:42:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 12:24:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8679.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/10/2017 12:17:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59385)(?)])(1 )(2 )]

"
Information	10/10/2017 12:09:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59385)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 12:09:43 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 12:09:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 12:09:42 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 12:00:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 12:00:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:33Z. Reason: GVLK.
Information	10/10/2017 11:52:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2017 11:52:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 11:52:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 11:52:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 11:52:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 55e6a363-ad83-11e7-9823-204747d02364
Report Status: 0"
Information	10/10/2017 11:52:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 55e6a362-ad83-11e7-9823-204747d02364
Report Status: 0"
Information	10/10/2017 11:52:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 55e6a361-ad83-11e7-9823-204747d02364
Report Status: 0"
Error	10/10/2017 11:49:35 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/10/2017 11:47:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 11:42:25 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 11:42:25 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 11:42:25 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 11:42:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 11:42:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:19Z. Reason: GVLK.
Information	10/10/2017 11:41:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/10/2017 11:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/10/2017 11:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 11:36:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 11:34:26 AM	McLogEvent	257	None	The scan of D:\installs\SetUpFile_2017_09_29_Fr_10_29_43_45\DISK1\ISSetupPrerequisites\{39B44035-64F8-485C-902E-7A79A185BE70}\postgresql-9.5.3-1-windows-x64.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8677.0000.
Error	10/10/2017 11:34:12 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/10/2017 11:33:27 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8677.0000.
Information	10/10/2017 11:29:13 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/10/2017 11:27:34 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/10/2017 11:27:33 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/10/2017 11:27:32 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/10/2017 11:27:31 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/10/2017 11:27:24 AM	ESENT	302	Logging/Recovery	Windows (7460) Windows: The database engine has successfully completed recovery steps.
Information	10/10/2017 11:27:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8677.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/10/2017 11:27:18 AM	ESENT	301	Logging/Recovery	Windows (7460) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/10/2017 11:27:17 AM	ESENT	300	Logging/Recovery	Windows (7460) Windows: The database engine is initiating recovery steps.
Information	10/10/2017 11:27:17 AM	ESENT	102	General	Windows (7460) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/10/2017 11:27:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/10/2017 11:27:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/10/2017 11:27:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/10/2017 11:27:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/10/2017 11:27:07 AM	Service1	0	None	Service started successfully.
Error	10/10/2017 11:27:04 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/10/2017 11:27:04 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/10/2017 11:26:53 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/10/2017 11:26:52 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/10/2017 11:26:52 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/10/2017 11:26:47 AM	PostgreSQL	0	None	"2017-10-10 11:26:47 IST LOG:  redirecting log output to logging collector process
2017-10-10 11:26:47 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/10/2017 11:26:47 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/10/2017 11:26:45 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/10/2017 11:26:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/10/2017 11:26:43 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/10/2017 11:26:43 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/10/2017 11:26:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/10/2017 11:26:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/10/2017 11:26:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/10/2017 11:26:38 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:38 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/10/2017 11:26:38 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/10/2017 11:26:38 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/10/2017 11:26:38 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/10/2017 11:26:37 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:37 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/10/2017 11:26:36 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3488 at 10/9/2017 6:01:52 PM (local) 10/9/2017 12:31:52 PM (UTC). This is an informational message only; no user action is required.
Information	10/10/2017 11:26:35 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/10/2017 11:26:34 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/10/2017 11:26:34 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/10/2017 11:26:34 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/10/2017 11:26:34 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3484.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/10/2017 11:26:33 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/10/2017 11:26:20 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/10/2017 11:26:16 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/10/2017 11:26:09 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/10/2017 11:26:08 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/10/2017 11:26:05 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/9/2017 6:22:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:17:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2017 6:17:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:17:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:16:52 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:11:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/9/2017 6:11:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60463)(?)])(1 )(2 )]

"
Information	10/9/2017 6:11:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60463)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2017 6:10:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2017 6:10:28 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/9/2017 6:10:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:10:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:54Z. Reason: GVLK.
Information	10/9/2017 6:09:37 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/9/2017 6:08:53 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 156

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 1560

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 297

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 62

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 905

Information	10/9/2017 6:08:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2017 6:07:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/9/2017 6:07:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60468)(?)])(1 )(2 )]

"
Information	10/9/2017 6:07:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60468)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2017 6:07:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2017 6:07:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:07:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:07:18 PM	RasClient	20225	None	CoId={3FD64663-1842-4888-BD76-E90C0BE82968}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.234.82
TunnelIpv6Address = None
Dial-in User = .
Information	10/9/2017 6:07:14 PM	RasClient	20224	None	CoId={3FD64663-1842-4888-BD76-E90C0BE82968}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	10/9/2017 6:07:14 PM	RasClient	20223	None	CoId={3FD64663-1842-4888-BD76-E90C0BE82968}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/9/2017 6:07:14 PM	RasClient	20222	None	CoId={3FD64663-1842-4888-BD76-E90C0BE82968}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/9/2017 6:07:14 PM	RasClient	20221	None	CoId={3FD64663-1842-4888-BD76-E90C0BE82968}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/9/2017 6:05:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53faf283-acee-11e7-9c83-204747d02364
Report Status: 0"
Information	10/9/2017 6:04:09 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/9/2017 6:02:34 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:02:33 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:02:32 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:02:31 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/9/2017 6:02:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2017 6:02:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2017 6:02:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:02:24 PM	ESENT	302	Logging/Recovery	Windows (7844) Windows: The database engine has successfully completed recovery steps.
Information	10/9/2017 6:02:23 PM	ESENT	301	Logging/Recovery	Windows (7844) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/9/2017 6:02:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:02:20 PM	ESENT	301	Logging/Recovery	Windows (7844) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0551C.log.
Information	10/9/2017 6:02:20 PM	ESENT	300	Logging/Recovery	Windows (7844) Windows: The database engine is initiating recovery steps.
Information	10/9/2017 6:02:20 PM	ESENT	102	General	Windows (7844) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/9/2017 6:02:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8677.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/9/2017 6:02:07 PM	Service1	0	None	Service started successfully.
Information	10/9/2017 6:02:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/9/2017 6:02:06 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/9/2017 6:02:06 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/9/2017 6:02:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/9/2017 6:02:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	10/9/2017 6:02:02 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/9/2017 6:02:02 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/9/2017 6:01:58 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/9/2017 6:01:58 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/9/2017 6:01:58 PM	PostgreSQL	0	None	"2017-10-09 18:01:58 IST LOG:  redirecting log output to logging collector process
2017-10-09 18:01:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/9/2017 6:01:58 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/9/2017 6:01:57 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/9/2017 6:01:54 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3548 at 10/9/2017 7:00:18 AM (local) 10/9/2017 1:30:18 AM (UTC). This is an informational message only; no user action is required.
Information	10/9/2017 6:01:52 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/9/2017 6:01:51 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/9/2017 6:01:51 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/9/2017 6:01:51 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/9/2017 6:01:51 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/9/2017 6:01:51 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Warning	10/9/2017 6:01:50 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3488.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/9/2017 6:01:50 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/9/2017 6:01:39 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:01:33 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/9/2017 6:01:33 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/9/2017 6:01:33 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/9/2017 7:00:27 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/9/2017 7:00:18 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/9/2017 7:00:18 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/9/2017 7:00:16 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 200 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2036 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/9/2017 7:00:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/9/2017 7:00:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/9/2017 7:00:15 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/9/2017 7:00:10 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/9/2017 7:00:09 AM	RasClient	20226	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	10/9/2017 6:55:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:50:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2017 6:50:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:50:45 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:25:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:20:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2017 6:20:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:20:45 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:15:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:13:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/9/2017 6:13:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:18Z. Reason: GVLK.
Information	10/9/2017 6:13:15 AM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8677.0000.
Information	10/9/2017 6:10:46 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 109

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 749

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 172

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	10/9/2017 6:10:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/9/2017 6:09:38 AM	RasClient	20225	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.252.213
TunnelIpv6Address = None
Dial-in User = .
Information	10/9/2017 6:09:36 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/9/2017 6:09:35 AM	RasClient	20224	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	10/9/2017 6:09:35 AM	RasClient	20223	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/9/2017 6:09:34 AM	RasClient	20222	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/9/2017 6:09:34 AM	RasClient	20221	None	CoId={6F03A85D-E3DC-43B4-8AE1-6CC16B22E5D7}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/9/2017 6:09:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/9/2017 6:09:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61185)(?)])(1 )(2 )]

"
Information	10/9/2017 6:09:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2017 6:09:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/9/2017 6:09:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:09:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:08:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 390e27e3-ac8a-11e7-a728-204747d02364
Report Status: 0"
Information	10/9/2017 6:07:31 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/9/2017 6:06:00 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8677.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/9/2017 6:05:43 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:05:43 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:05:43 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:05:43 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/9/2017 6:05:35 AM	ESENT	302	Logging/Recovery	Windows (6900) Windows: The database engine has successfully completed recovery steps.
Information	10/9/2017 6:05:32 AM	ESENT	301	Logging/Recovery	Windows (6900) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/9/2017 6:05:32 AM	ESENT	300	Logging/Recovery	Windows (6900) Windows: The database engine is initiating recovery steps.
Information	10/9/2017 6:05:32 AM	ESENT	102	General	Windows (6900) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/9/2017 6:05:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/9/2017 6:05:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/9/2017 6:05:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/9/2017 6:05:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/9/2017 6:05:19 AM	Service1	0	None	Service started successfully.
Information	10/9/2017 6:05:14 AM	PostgreSQL	0	None	Server started and accepting connections

Error	10/9/2017 6:05:14 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/9/2017 6:05:12 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/9/2017 6:05:12 AM	PostgreSQL	0	None	"2017-10-09 06:05:12 IST LOG:  redirecting log output to logging collector process
2017-10-09 06:05:12 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/9/2017 6:05:11 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/9/2017 6:05:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/9/2017 6:05:11 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/9/2017 6:05:11 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/9/2017 6:05:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/9/2017 6:05:11 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/9/2017 6:05:11 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/9/2017 6:05:10 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/9/2017 6:05:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/9/2017 6:05:04 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3652 at 10/8/2017 11:23:40 PM (local) 10/8/2017 5:53:40 PM (UTC). This is an informational message only; no user action is required.
Information	10/9/2017 6:05:02 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/9/2017 6:05:00 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/9/2017 6:05:00 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/9/2017 6:05:00 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/9/2017 6:05:00 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/9/2017 6:05:00 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3548.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/9/2017 6:04:58 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/9/2017 6:04:54 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/9/2017 6:04:46 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/9/2017 6:04:38 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/9/2017 6:04:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/9/2017 6:04:38 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/8/2017 11:23:49 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/8/2017 11:23:40 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/8/2017 11:23:40 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/8/2017 11:23:38 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 172 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 2004 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/8/2017 11:23:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/8/2017 11:23:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/8/2017 11:23:37 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/8/2017 11:23:34 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/8/2017 10:59:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2017 10:59:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:10Z. Reason: GVLK.
Information	10/8/2017 10:54:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 817af92a-ac4d-11e7-b32b-204747d02364
Report Status: 0"
Information	10/8/2017 10:54:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2017 10:54:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2017 10:54:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 10:54:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	10/8/2017 10:44:31 PM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: f5fpapi.dll, version: 7132.2017.404.2206, time stamp: 0x58e419a1
Exception code: 0x40000015
Fault offset: 0x000dfbae
Faulting process id: 0xba4
Faulting application start time: 0x01d34022756ee125
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: C:\Program Files (x86)\F5 VPN\f5fpapi.dll
Report Id: 255eb35b-ac4c-11e7-b32b-204747d02364"
Error	10/8/2017 7:37:45 PM	RasClient	20227	None	CoId={DB4156CC-3A61-43A6-96F3-06A4A7B992C2}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	10/8/2017 7:37:45 PM	RasClient	20221	None	CoId={DB4156CC-3A61-43A6-96F3-06A4A7B992C2}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	10/8/2017 7:37:45 PM	RasClient	20227	None	CoId={F6FE8FBE-6AA7-463D-8E1A-6E4B9130BAC6}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 633.
Information	10/8/2017 7:37:45 PM	RasClient	20221	None	CoId={F6FE8FBE-6AA7-463D-8E1A-6E4B9130BAC6}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/8/2017 7:37:41 PM	RasClient	20226	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	10/8/2017 5:31:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2017 5:26:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2017 5:26:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 5:26:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2017 5:01:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/8/2017 4:56:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2017 4:56:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 4:56:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2017 4:51:50 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8677.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/8/2017 4:39:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2017 4:39:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:32Z. Reason: GVLK.
Information	10/8/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 4:34:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2017 4:34:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d7cbe01-ac18-11e7-b32b-204747d02364
Report Status: 0"
Information	10/8/2017 4:34:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d7cbe00-ac18-11e7-b32b-204747d02364
Report Status: 0"
Information	10/8/2017 4:34:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d7cbdff-ac18-11e7-b32b-204747d02364
Report Status: 0"
Error	10/8/2017 4:31:48 PM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/8/2017 4:31:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/8/2017 4:23:44 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	10/8/2017 4:23:44 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {A6E16719-D4ED-433F-BC94-BEB779A5E8F6}
Error	10/8/2017 4:23:44 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {A6E16719-D4ED-433F-BC94-BEB779A5E8F6}
Information	10/8/2017 4:23:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/8/2017 4:23:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62011)(?)])(1 )(2 )]

"
Information	10/8/2017 4:23:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62011)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2017 4:22:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/8/2017 4:22:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 4:22:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/8/2017 4:21:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/8/2017 4:21:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:51Z. Reason: GVLK.
Information	10/8/2017 4:20:02 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Error	10/8/2017 4:18:11 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/8/2017 4:16:19 PM	RasClient	20225	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.247.81
TunnelIpv6Address = None
Dial-in User = .
Information	10/8/2017 4:16:14 PM	RasClient	20224	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	10/8/2017 4:16:14 PM	RasClient	20223	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/8/2017 4:16:14 PM	RasClient	20222	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/8/2017 4:16:14 PM	RasClient	20221	None	CoId={4FB32FD3-7B2F-4426-8646-791C6411C94C}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/8/2017 4:14:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0be2e48-ac15-11e7-b32b-204747d02364
Report Status: 0"
Information	10/8/2017 4:13:05 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/8/2017 4:11:35 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8676.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/8/2017 4:11:29 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2017 4:11:29 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2017 4:11:29 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2017 4:11:29 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/8/2017 4:11:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/8/2017 4:11:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/8/2017 4:11:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/8/2017 4:11:14 PM	ESENT	302	Logging/Recovery	Windows (6348) Windows: The database engine has successfully completed recovery steps.
Information	10/8/2017 4:11:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/8/2017 4:11:04 PM	ESENT	301	Logging/Recovery	Windows (6348) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/8/2017 4:11:04 PM	ESENT	300	Logging/Recovery	Windows (6348) Windows: The database engine is initiating recovery steps.
Information	10/8/2017 4:11:04 PM	ESENT	102	General	Windows (6348) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/8/2017 4:11:04 PM	Service1	0	None	Service started successfully.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/8/2017 4:11:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/8/2017 4:11:02 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3460 at 10/7/2017 11:58:34 PM (local) 10/7/2017 6:28:34 PM (UTC). This is an informational message only; no user action is required.
Information	10/8/2017 4:10:59 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/8/2017 4:10:57 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/8/2017 4:10:57 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/8/2017 4:10:57 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/8/2017 4:10:57 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/8/2017 4:10:57 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/8/2017 4:10:57 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Error	10/8/2017 4:10:56 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/8/2017 4:10:56 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/8/2017 4:10:56 PM	PostgreSQL	0	None	"2017-10-08 16:10:56 IST LOG:  redirecting log output to logging collector process
2017-10-08 16:10:56 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/8/2017 4:10:55 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/8/2017 4:10:55 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/8/2017 4:10:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/8/2017 4:10:54 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/8/2017 4:10:54 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/8/2017 4:10:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/8/2017 4:10:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	10/8/2017 4:10:49 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3652.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/8/2017 4:10:49 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/8/2017 4:10:43 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/8/2017 4:10:34 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/8/2017 4:10:34 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/8/2017 4:10:34 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/7/2017 11:58:41 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	10/7/2017 11:58:35 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/7/2017 11:58:34 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	10/7/2017 11:58:32 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 19 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 188 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 888 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 888 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 888 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 888 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 888 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1680 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/7/2017 11:58:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/7/2017 11:58:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/7/2017 11:58:31 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/7/2017 11:58:28 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	10/7/2017 11:58:27 PM	RasClient	20226	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	10/7/2017 11:57:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/7/2017 11:57:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62998)(?)])(1 )(2 )]

"
Information	10/7/2017 11:57:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62998)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 11:57:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 11:57:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 11:57:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 11:38:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 11:33:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/7/2017 11:33:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63022)(?)])(1 )(2 )]

"
Information	10/7/2017 11:33:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63022)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 11:33:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 11:33:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 11:33:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 11:08:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 11:03:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 11:03:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 11:03:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 10:46:23 PM	RasClient	20225	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.234.65
TunnelIpv6Address = None
Dial-in User = .
Information	10/7/2017 10:46:18 PM	RasClient	20224	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	10/7/2017 10:46:18 PM	RasClient	20223	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/7/2017 10:46:18 PM	RasClient	20222	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/7/2017 10:46:18 PM	RasClient	20221	None	CoId={5D46A94D-D732-4E82-9629-1E25D37E6E59}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/7/2017 10:38:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 10:33:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 10:33:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 10:33:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 10:08:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 10:03:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 10:03:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 10:03:05 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 9:55:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 9:55:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:41Z. Reason: GVLK.
Information	10/7/2017 9:49:55 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/7/2017 9:48:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8676.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/7/2017 9:48:05 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 9:48:05 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 9:48:05 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 9:48:05 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/7/2017 9:48:01 PM	ESENT	302	Logging/Recovery	Windows (7592) Windows: The database engine has successfully completed recovery steps.
Information	10/7/2017 9:48:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2017 9:48:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 9:48:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 9:48:01 PM	ESENT	301	Logging/Recovery	Windows (7592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/7/2017 9:47:56 PM	ESENT	301	Logging/Recovery	Windows (7592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0550E.log.
Information	10/7/2017 9:47:56 PM	ESENT	300	Logging/Recovery	Windows (7592) Windows: The database engine is initiating recovery steps.
Information	10/7/2017 9:47:56 PM	ESENT	102	General	Windows (7592) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/7/2017 9:47:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 9:47:48 PM	Service1	0	None	Service started successfully.
Error	10/7/2017 9:47:44 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/7/2017 9:47:44 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/7/2017 9:47:35 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/7/2017 9:47:34 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/7/2017 9:47:29 PM	PostgreSQL	0	None	"2017-10-07 21:47:29 IST LOG:  redirecting log output to logging collector process
2017-10-07 21:47:29 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/7/2017 9:47:29 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/7/2017 9:47:29 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/7/2017 9:47:28 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/7/2017 9:47:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/7/2017 9:47:26 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/7/2017 9:47:26 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/7/2017 9:47:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/7/2017 9:47:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/7/2017 9:47:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/7/2017 9:47:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/7/2017 9:47:21 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/7/2017 9:47:20 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:20 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:20 PM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3520 at 10/7/2017 8:25:52 PM (local) 10/7/2017 2:55:52 PM (UTC). This is an informational message only; no user action is required.
Information	10/7/2017 9:47:19 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/7/2017 9:47:17 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/7/2017 9:47:17 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/7/2017 9:47:17 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/7/2017 9:47:17 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/7/2017 9:47:17 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3460.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/7/2017 9:47:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/7/2017 9:47:04 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/7/2017 9:47:02 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 9:46:57 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/7/2017 9:46:56 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/7/2017 9:46:54 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/7/2017 9:32:25 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/7/2017 9:16:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 9:11:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 9:11:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 9:11:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 9:01:29 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/7/2017 9:01:26 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/7/2017 8:56:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 8:51:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2017 8:51:52 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/7/2017 8:51:34 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 1217

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 530

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 218

Information	10/7/2017 8:51:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/7/2017 8:50:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/7/2017 8:50:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63185)(?)])(1 )(2 )]

"
Information	10/7/2017 8:50:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63185)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 8:50:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 8:50:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 8:50:21 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 8:46:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 8:41:35 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 8:41:35 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 8:41:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 8:40:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 8:40:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:39Z. Reason: GVLK.
Information	10/7/2017 8:37:39 PM	RasClient	20225	None	CoId={56438618-A776-4F79-9147-DA69B3C89649}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.234.50
TunnelIpv6Address = None
Dial-in User = .
Information	10/7/2017 8:37:36 PM	RasClient	20224	None	CoId={56438618-A776-4F79-9147-DA69B3C89649}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	10/7/2017 8:37:36 PM	RasClient	20223	None	CoId={56438618-A776-4F79-9147-DA69B3C89649}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/7/2017 8:37:36 PM	RasClient	20222	None	CoId={56438618-A776-4F79-9147-DA69B3C89649}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	10/7/2017 8:37:36 PM	RasClient	20221	None	CoId={56438618-A776-4F79-9147-DA69B3C89649}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	10/7/2017 8:35:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2017 8:35:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 8:35:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 8:35:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 8:34:13 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 8:34:13 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:08Z. Reason: GVLK.
Information	10/7/2017 8:29:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1ef2c423-ab70-11e7-8e2d-204747d02364
Report Status: 0"
Information	10/7/2017 8:28:22 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/7/2017 8:26:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8676.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/7/2017 8:26:47 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 8:26:47 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 8:26:46 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 8:26:45 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/7/2017 8:26:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2017 8:26:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 8:26:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 8:26:24 PM	ESENT	302	Logging/Recovery	Windows (7592) Windows: The database engine has successfully completed recovery steps.
Information	10/7/2017 8:26:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 8:26:23 PM	ESENT	301	Logging/Recovery	Windows (7592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/7/2017 8:26:23 PM	ESENT	300	Logging/Recovery	Windows (7592) Windows: The database engine is initiating recovery steps.
Information	10/7/2017 8:26:23 PM	ESENT	102	General	Windows (7592) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/7/2017 8:26:10 PM	Service1	0	None	Service started successfully.
Error	10/7/2017 8:26:05 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/7/2017 8:26:05 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/7/2017 8:26:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/7/2017 8:26:03 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/7/2017 8:26:03 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/7/2017 8:26:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/7/2017 8:26:03 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	10/7/2017 8:26:02 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/7/2017 8:26:02 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/7/2017 8:26:01 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/7/2017 8:25:58 PM	PostgreSQL	0	None	"2017-10-07 20:25:58 IST LOG:  redirecting log output to logging collector process
2017-10-07 20:25:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/7/2017 8:25:58 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/7/2017 8:25:57 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:54 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/7/2017 8:25:53 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/7/2017 8:25:53 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/7/2017 8:25:53 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3640 at 10/7/2017 1:24:31 PM (local) 10/7/2017 7:54:31 AM (UTC). This is an informational message only; no user action is required.
Information	10/7/2017 8:25:52 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/7/2017 8:25:51 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/7/2017 8:25:51 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/7/2017 8:25:51 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/7/2017 8:25:51 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/7/2017 8:25:51 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3520.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/7/2017 8:25:50 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/7/2017 8:25:42 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/7/2017 8:25:37 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 8:25:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/7/2017 8:25:29 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/7/2017 8:25:26 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/7/2017 2:45:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 2:44:28 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8676.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/7/2017 2:40:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 2:40:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 2:40:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 2:15:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 2:10:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 2:10:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 2:10:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 1:45:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/7/2017 1:35:09 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485947
"
Error	10/7/2017 1:35:09 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {06C92FF1-EAD6-4387-A440-83D6BE61111E}
Information	10/7/2017 1:35:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/7/2017 1:35:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63620)(?)])(1 )(2 )]

"
Information	10/7/2017 1:35:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63620)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 1:35:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/7/2017 1:35:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 1:35:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 1:32:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/7/2017 1:32:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:38Z. Reason: GVLK.
Information	10/7/2017 1:26:52 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/7/2017 1:26:00 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 1:25:59 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 1:25:58 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 1:25:57 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/7/2017 1:25:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8675.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/7/2017 1:25:37 PM	ESENT	302	Logging/Recovery	Windows (7592) Windows: The database engine has successfully completed recovery steps.
Information	10/7/2017 1:25:36 PM	ESENT	301	Logging/Recovery	Windows (7592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/7/2017 1:25:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/7/2017 1:25:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/7/2017 1:25:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/7/2017 1:25:29 PM	ESENT	301	Logging/Recovery	Windows (7592) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS05503.log.
Information	10/7/2017 1:25:29 PM	ESENT	300	Logging/Recovery	Windows (7592) Windows: The database engine is initiating recovery steps.
Information	10/7/2017 1:25:28 PM	ESENT	102	General	Windows (7592) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/7/2017 1:25:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/7/2017 1:24:50 PM	Service1	0	None	Service started successfully.
Information	10/7/2017 1:24:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/7/2017 1:24:47 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/7/2017 1:24:47 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/7/2017 1:24:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/7/2017 1:24:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	10/7/2017 1:24:44 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/7/2017 1:24:44 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/7/2017 1:24:44 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/7/2017 1:24:42 PM	PostgreSQL	0	None	Server started and accepting connections

Information	10/7/2017 1:24:41 PM	PostgreSQL	0	None	"2017-10-07 13:24:41 IST LOG:  redirecting log output to logging collector process
2017-10-07 13:24:41 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/7/2017 1:24:40 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/7/2017 1:24:39 PM	PostgreSQL	0	None	Waiting for server startup...

Information	10/7/2017 1:24:35 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:35 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/7/2017 1:24:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/7/2017 1:24:35 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/7/2017 1:24:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/7/2017 1:24:34 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/7/2017 1:24:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/7/2017 1:24:33 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/7/2017 1:24:32 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/7/2017 1:24:32 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 1:24:32 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4076 at 10/6/2017 5:46:50 PM (local) 10/6/2017 12:16:50 PM (UTC). This is an informational message only; no user action is required.
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Warning	10/7/2017 1:24:31 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/7/2017 1:24:31 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/7/2017 1:24:30 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/7/2017 1:24:30 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/7/2017 1:24:30 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/7/2017 1:24:30 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3640.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/7/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/7/2017 1:24:20 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/7/2017 1:24:17 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/7/2017 1:24:17 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/7/2017 1:24:17 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/6/2017 5:46:50 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	10/6/2017 5:46:50 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	10/6/2017 5:46:49 PM	McLogEvent	257	None	The scan of C:\Windows\System32\hnetcfg.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8675.0000.
Information	10/6/2017 5:46:48 PM	McLogEvent	257	None	The scan of C:\Windows\System32\wlanhlp.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8675.0000.
Warning	10/6/2017 5:46:48 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 30 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2284 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 904 (\Device\HarddiskVolume1\Windows\System32\services.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1976 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	10/6/2017 5:46:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	10/6/2017 5:46:47 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	10/6/2017 5:46:47 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	10/6/2017 4:46:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/6/2017 4:46:27 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/6/2017 4:15:04 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/6/2017 4:14:52 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/6/2017 4:07:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2017 4:06:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/6/2017 2:57:38 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 2:52:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 2:52:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64982)(?)])(1 )(2 )]

"
Information	10/6/2017 2:52:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64982)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 2:52:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 2:52:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 2:52:32 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 2:15:29 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13469, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/6/2017 2:08:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bce5b867-aa71-11e7-b8a8-0205857feb80
Report Status: 0"
Information	10/6/2017 12:55:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8675.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/6/2017 12:14:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]

"
Information	10/6/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65145)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 12:07:00 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 452

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	10/6/2017 12:06:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2017 12:06:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 12:06:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65149)(?)])(1 )(2 )]

"
Information	10/6/2017 12:06:31 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/6/2017 12:06:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65149)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 12:06:31 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 12:06:31 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 12:06:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 11:16:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 11:11:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 11:11:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 11:11:10 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65204)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 11:11:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 11:11:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 10:58:10 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/6/2017 9:31:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 9:30:45 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11180.
Information	10/6/2017 9:30:45 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/6/2017 9:30:45 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/6/2017 9:30:44 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/6/2017 9:30:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11180.
Information	10/6/2017 9:30:44 AM	ESENT	102	General	Windows (7812) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/6/2017 9:30:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11180.
Information	10/6/2017 9:30:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/6/2017 9:30:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/6/2017 9:30:10 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11180.
Information	10/6/2017 9:30:04 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/6/2017 9:30:04 AM	ESENT	103	General	Windows (11124) Windows: The database engine stopped the instance (0).
Information	10/6/2017 9:29:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/6/2017 9:29:38 AM	ESENT	102	General	Windows (11124) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/6/2017 9:29:37 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/6/2017 9:29:37 AM	ESENT	103	General	Windows (7808) Windows: The database engine stopped the instance (0).
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:31 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:31 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/6/2017 9:29:31 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:31 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:29:31 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/6/2017 9:26:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/6/2017 9:26:31 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 9:26:31 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 9:26:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 9:25:21 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎06T03:55:21.021764000Z.
Information	10/6/2017 9:25:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 9:21:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 9:21:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:24Z. Reason: GVLK.
Information	10/6/2017 9:20:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 9:20:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 9:20:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 9:19:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 9:16:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2017 9:16:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 9:16:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 9:16:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 9:14:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/6/2017 9:14:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 9:14:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 9:13:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 9:13:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:27Z. Reason: GVLK.
Information	10/6/2017 9:08:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cfca4c74-aa47-11e7-b8a8-0205857feb80
Report Status: 0"
Information	10/6/2017 9:07:36 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/6/2017 9:06:24 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/6/2017 9:06:24 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/6/2017 9:06:23 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/6/2017 9:06:21 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/6/2017 9:05:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2017 9:05:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 9:05:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 9:05:38 AM	ESENT	302	Logging/Recovery	Windows (7808) Windows: The database engine has successfully completed recovery steps.
Information	10/6/2017 9:05:35 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 9:05:35 AM	ESENT	301	Logging/Recovery	Windows (7808) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/6/2017 9:05:35 AM	ESENT	300	Logging/Recovery	Windows (7808) Windows: The database engine is initiating recovery steps.
Information	10/6/2017 9:05:35 AM	ESENT	102	General	Windows (7808) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/6/2017 9:05:32 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8674.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/6/2017 9:05:28 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/6/2017 9:05:24 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:24 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/6/2017 9:05:24 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/6/2017 9:05:24 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/6/2017 9:05:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/6/2017 9:05:23 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/6/2017 9:05:23 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/6/2017 9:05:23 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/6/2017 9:05:22 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:22 AM	Service1	0	None	Service started successfully.
Information	10/6/2017 9:05:21 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/6/2017 9:05:20 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/6/2017 9:05:20 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/6/2017 9:05:20 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/6/2017 9:05:19 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/6/2017 9:05:15 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:15 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:15 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4052 at 10/5/2017 10:09:27 AM (local) 10/5/2017 4:39:27 AM (UTC). This is an informational message only; no user action is required.
Information	10/6/2017 9:05:13 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Error	10/6/2017 9:05:12 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/6/2017 9:05:12 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/6/2017 9:05:07 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/6/2017 9:05:06 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/6/2017 9:05:06 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/6/2017 9:05:06 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/6/2017 9:05:06 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/6/2017 9:04:54 AM	PostgreSQL	0	None	"2017-10-06 09:04:54 IST LOG:  redirecting log output to logging collector process
2017-10-06 09:04:54 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/6/2017 9:04:49 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/6/2017 9:04:49 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/6/2017 9:04:48 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4076.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/6/2017 9:04:32 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	10/6/2017 9:04:23 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/6/2017 9:04:23 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/6/2017 9:04:23 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/6/2017 9:04:23 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/6/2017 9:04:23 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	10/6/2017 9:04:01 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/6/2017 9:03:53 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/6/2017 9:03:36 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/6/2017 9:03:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/6/2017 9:03:36 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/6/2017 3:50:03 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 3:50:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:03Z. Reason: GVLK.
Error	10/6/2017 3:45:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/6/2017 3:45:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2017 3:45:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 3:45:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 3:45:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 2:33:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/6/2017 1:16:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/6/2017 1:16:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:15Z. Reason: GVLK.
Information	10/6/2017 1:14:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8b6ea37-aa05-11e7-8313-0205857feb80
Report Status: 0"
Information	10/6/2017 1:11:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/6/2017 1:11:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/6/2017 1:11:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/6/2017 1:11:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/6/2017 12:15:49 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/5/2017 10:33:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 9:33:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2017 9:33:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:12:02Z. Reason: GVLK.
Information	10/5/2017 9:28:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2017 9:28:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 9:28:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 9:27:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 8:14:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: be8fa505-a9db-11e7-8313-0205857feb80
Report Status: 0"
Information	10/5/2017 6:33:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 5:11:02 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 5:11:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66284)(?)])(1 )(2 )]

"
Information	10/5/2017 5:11:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66284)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 3:57:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 3:57:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66358)(?)])(1 )(2 )]

"
Information	10/5/2017 3:57:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66358)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 3:43:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 3:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66372)(?)])(1 )(2 )]

"
Information	10/5/2017 3:43:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66372)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 3:20:18 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/5/2017 3:14:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d48f67f4-a9b1-11e7-8313-0205857feb80
Report Status: 0"
Information	10/5/2017 2:33:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 1:54:51 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/5/2017 12:30:27 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8674.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/5/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66585)(?)])(1 )(2 )]

"
Information	10/5/2017 12:09:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66585)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 11:47:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2017 11:47:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-12T06:11:43Z. Reason: GVLK.
Information	10/5/2017 11:42:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 11:42:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 11:42:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/10/05 06:12"
Information	10/5/2017 11:42:42 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/10/05 06:12, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	10/5/2017 11:37:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2017 11:37:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 11:37:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 11:37:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 10:35:27 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/5/2017 10:35:26 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 40, Deleted: 0, Modified: 0, Compared: 13399, Queries: 0, Results: 0, Version: 16.0.8201.2193.
Information	10/5/2017 10:34:36 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 2262

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1514

Information	10/5/2017 10:33:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 10:33:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66681)(?)])(1 )(2 )]

"
Information	10/5/2017 10:33:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66681)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 10:33:37 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66681)(?)])(1 )(2 )]

"
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109881  Grace type=8.
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=51782453-b0d6-4e09-ac39-c4bf532e7645"
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=bfa6ebb9-60a8-4607-99dc-91a853acdebf"
Information	10/5/2017 10:33:32 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/5/2017 10:32:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 10:32:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	10/5/2017 10:32:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	10/5/2017 10:32:34 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 10:32:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20602)(?)])(1 )(2 )]

"
Information	10/5/2017 10:32:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20602)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 10:32:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2017 10:32:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 10:32:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 10:31:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	10/5/2017 10:25:59 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	10/5/2017 10:25:59 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {9D89915F-D73E-4643-A8C9-D06C4B7EF668}
Error	10/5/2017 10:25:59 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {9D89915F-D73E-4643-A8C9-D06C4B7EF668}
Information	10/5/2017 10:25:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/5/2017 10:25:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20609)(?)])(1 )(2 )]

"
Information	10/5/2017 10:25:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20609)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 10:24:19 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:19 AM	MsiInstaller	1029	None	Product: Office 16 Click-to-Run Licensing Component. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	10/5/2017 10:24:19 AM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	10/5/2017 10:24:19 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:24:19 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	10/5/2017 10:24:19 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/5/2017 10:24:17 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20611)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 10:24:17 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	10/5/2017 10:24:17 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	10/5/2017 10:24:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 10:24:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2017 10:24:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 10:24:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 10:24:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 7888.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 9028.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: explorer , Id 5648.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 3112.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\SysWOW64\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 7888.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\SysWOW64\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 9028.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\SysWOW64\vcruntime140.dll is being used by the following process: Name: explorer , Id 5648.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\SysWOW64\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 3112.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 7888.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 9028.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: explorer , Id 5648.
Information	10/5/2017 10:24:12 AM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 3112.
Information	10/5/2017 10:24:06 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:06 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:06 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.8201.2075. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:24:06 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:24:05 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:05 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:24:05 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	10/5/2017 10:24:03 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/5/2017 10:24:03 AM	ESENT	102	General	Windows (8316) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/5/2017 10:24:03 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:02 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:24:02 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:24:02 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/5/2017 10:23:48 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:23:44 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/5/2017 10:23:44 AM	ESENT	103	General	Windows (7684) Windows: The database engine stopped the instance (0).
Information	10/5/2017 10:23:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 4536.
Information	10/5/2017 10:23:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.8201.2193. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/5/2017 10:23:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	10/5/2017 10:23:07 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 4536.
Warning	10/5/2017 10:22:58 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	10/5/2017 10:22:58 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/5/2017 10:22:58 AM	ESENT	102	General	Windows (7684) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/5/2017 10:22:54 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	10/5/2017 10:22:54 AM	ESENT	103	General	Windows (7380) Windows: The database engine stopped the instance (0).
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:52 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	10/5/2017 10:22:19 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=a29ae428-d4c3-40b5-b12a-1696fb106f93"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a7a3d8a0-987d-4aff-bba3-a5c17ad49617"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9964ac93-598f-42b6-b189-b1d749d598d4"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b53d8778-a9a3-4c03-aaa7-6ae3c4fbb417"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=26779234-6de3-4b8b-82da-62f8f3e5ee14"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=6ed506bc-a180-4feb-bd85-78a620658aab"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c5e80816-3c59-41f1-ad00-37bba926d9d0"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=a7c7db15-53e1-44f9-9bac-7d868839a828"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=2c8c273c-654c-411b-964d-c27c93e2eab9"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=cb2dfbf9-e2b7-4761-b346-bf3e8f9b1d8b"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=66bc27e5-2287-47f9-9700-97a6318fb43d"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=546969db-6fa7-42f5-8f39-465143b6169c"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6045dada-85c0-47db-b722-1d1340146620"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2a38ae66-6127-42c6-a1e9-da8b99e7d8f1"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7da52d3b-97d3-491e-8ce0-7928031ef94e"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=6afb1c7b-52fe-4252-bcfb-e864c1dadd55"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=8d92a08f-4fef-44bc-b4e1-3b45b6ef4db8"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3f0c6f36-1c63-4804-ba78-731bccf5d056"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8f9c8b50-af8a-4d2a-ade9-2878e1ce063f"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b821f40f-0237-4280-a952-a404cc57eb3d"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ff59bfc4-12ad-4a70-8bc0-a9b19c3f3899"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=03fd31a4-4c72-46e8-a846-32b4c866b9e4"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=15828610-6c7a-4ece-80a0-5d53b0b294a9"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=009d64c2-4aff-45d7-aca4-fc51b2b4cd5a"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=714797ae-ef2a-4df7-9916-8dd4086b0301"
Information	10/5/2017 10:22:19 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2969e4af-acc4-4acb-9af0-ce9925e5f080"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=58d00c25-30de-4ea1-bad3-a7addef5a4d8"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=1cdae5ac-830d-443b-8037-b86adad0ef86"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=57911a3e-99e1-410a-8763-ca04835db700"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=fa910c65-38a7-45e6-a9dd-618875632e72"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=c7f9fb4b-ed74-4bb2-a253-951300608aed"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5181bb0b-906a-404a-b09c-c8129313242b"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=9e785135-9970-4043-a096-9b6c7fc52c33"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a721f6f8-3e79-4ba0-aa79-7bb4f7bce72b"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=437edbf3-6398-4d1c-a2a8-384ff4c3d129"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f2836fd-0237-4d3d-90cd-1593d92a3d6e"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=1c096217-1410-4173-9ab1-806913529191"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ce41a4bb-eb57-4374-be02-f8da0eaa67c2"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=116937a6-aded-4ffc-a4dc-21b87716a77c"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0f441e8a-8680-4bae-8606-c7483855e07f"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e0b95036-e08f-43b1-8aec-1772d1e97e09"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=00b3813c-617f-4272-82ff-0f2f5acbf0ec"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ad1226d6-9175-4d4c-8440-f41ab8aec8c0"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=3e515e4a-f60f-44f7-9945-771a4754866b"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=b548364f-beac-4ee3-85b1-00bcf6dd28ef"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=40696d37-d32c-4b26-be2c-f507c56e9403"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=646e3b11-42c3-4d78-90b2-aeb46c094d95"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=41f1464c-4650-4c45-baf8-89eda530be0b"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=4ada7338-7558-4f50-8f8a-18c52c6e203e"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=e4c3e7f0-d166-4448-85f2-d7134f64a7ca"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bf425275-1696-43f4-aaef-e15082415dff"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=09e1a8ed-adc5-4089-a02f-ad7425027c30"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=905e969d-4426-477a-bbb1-10d44a136184"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=59aa4034-eeb4-4ca2-bfe0-246e01961afb"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=e7d3fc2d-307e-4998-83a0-6c76ff8f61c6"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=867042ad-dcdc-40c8-9955-7a2f2c3c7b67"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=9deb967e-51d7-40a0-904a-b3de7d362d54"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b9e4ab2b-6155-456e-b005-a1a422087329"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f5647902-5beb-4d2f-b1f1-3ee257ad27f5"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=750affcf-ac09-4afe-8e57-23bcb85a7a9e"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=7c53e433-837d-41b0-9788-1f9196196703"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=b46b567f-5a9d-4cd8-b926-ecc001a79448"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	10/5/2017 10:22:18 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	10/5/2017 10:22:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/5/2017 10:22:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 10:22:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 10:21:37 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	10/5/2017 10:18:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2017 10:18:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:39Z. Reason: GVLK.
Information	10/5/2017 10:12:53 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	10/5/2017 10:12:53 AM	SecurityCenter	11	None	Program C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe with instanceID={61FE6F34-F6E4-3642-CFEA-6AD93746FFEB} was removed from the Security Center reporting database because the program was either uninstalled, changed, or could not be verified.
Information	10/5/2017 10:12:53 AM	SecurityCenter	11	None	Program C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe with instanceID={DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} was removed from the Security Center reporting database because the program was either uninstalled, changed, or could not be verified.
Information	10/5/2017 10:12:53 AM	SecurityCenter	11	None	Program C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe with instanceID={E2A40FF5-9AB1-3894-DE05-F89EB212F22D} was removed from the Security Center reporting database because the program was either uninstalled, changed, or could not be verified.
Information	10/5/2017 10:12:01 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Microsoft Windows Search Protocol Host'.
Information	10/5/2017 10:12:01 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	10/5/2017 10:12:01 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Microsoft Windows Search Protocol Host' could not be shut down.
Information	10/5/2017 10:11:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎05T04:41:48.261672600Z.
Information	10/5/2017 10:11:38 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2017 10:11:36 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2017 10:11:36 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2017 10:11:34 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	10/5/2017 10:10:59 AM	ESENT	302	Logging/Recovery	Windows (7380) Windows: The database engine has successfully completed recovery steps.
Information	10/5/2017 10:10:58 AM	ESENT	301	Logging/Recovery	Windows (7380) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	10/5/2017 10:10:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2017 10:10:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 10:10:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 10:10:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 10:10:51 AM	ESENT	301	Logging/Recovery	Windows (7380) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS054EF.log.
Information	10/5/2017 10:10:51 AM	ESENT	300	Logging/Recovery	Windows (7380) Windows: The database engine is initiating recovery steps.
Information	10/5/2017 10:10:50 AM	ESENT	102	General	Windows (7380) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	10/5/2017 10:10:47 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8673.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/5/2017 10:10:16 AM	PostgreSQL	0	None	Server started and accepting connections

Information	10/5/2017 10:09:49 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	10/5/2017 10:09:49 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	10/5/2017 10:09:48 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	10/5/2017 10:09:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	10/5/2017 10:09:43 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	10/5/2017 10:09:42 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:42 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	10/5/2017 10:09:41 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	10/5/2017 10:09:40 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	10/5/2017 10:09:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	10/5/2017 10:09:40 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:39 AM	Service1	0	None	Service started successfully.
Information	10/5/2017 10:09:39 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	10/5/2017 10:09:37 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	10/5/2017 10:09:36 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	10/5/2017 10:09:36 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	10/5/2017 10:09:35 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	10/5/2017 10:09:29 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:29 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	10/5/2017 10:09:29 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	10/5/2017 10:09:29 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	10/5/2017 10:09:29 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	10/5/2017 10:09:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	10/5/2017 10:09:28 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	10/5/2017 10:09:28 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	10/5/2017 10:09:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	10/5/2017 10:09:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3552 at 9/19/2017 9:51:05 AM (local) 9/19/2017 4:21:05 AM (UTC). This is an informational message only; no user action is required.
Information	10/5/2017 10:09:20 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	10/5/2017 10:09:20 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	10/5/2017 10:09:20 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	10/5/2017 10:09:20 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	10/5/2017 10:09:20 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	10/5/2017 10:09:12 AM	PostgreSQL	0	None	"2017-10-05 10:09:12 IST LOG:  redirecting log output to logging collector process
2017-10-05 10:09:12 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	10/5/2017 10:09:11 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	10/5/2017 10:09:10 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	10/5/2017 10:09:09 AM	PostgreSQL	0	None	Waiting for server startup...

Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4052.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	10/5/2017 10:09:00 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	10/5/2017 10:08:20 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	10/5/2017 10:08:14 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	10/5/2017 10:08:01 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	10/5/2017 10:08:00 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	10/5/2017 10:08:00 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	10/5/2017 3:39:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/5/2017 3:39:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:52Z. Reason: GVLK.
Error	10/5/2017 3:35:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/5/2017 3:34:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/5/2017 3:34:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/5/2017 3:34:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/5/2017 3:34:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/5/2017 2:13:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 2:12:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 2:12:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 2:11:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/5/2017 1:00:32 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7be87c3a-a93a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/5/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/4/2017 10:55:39 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/4/2017 10:12:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 10:12:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 10:11:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 8:00:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 91201a1a-a910-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 6:12:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 6:11:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 6:11:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 5:49:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 5:49:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:45Z. Reason: GVLK.
Information	10/4/2017 5:44:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2017 5:44:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 5:44:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 5:44:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 5:34:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 337efeab-a8fc-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 3:00:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a140c3b3-a8e6-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 2:12:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 2:11:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 2:11:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 1:11:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 1:11:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:32Z. Reason: GVLK.
Information	10/4/2017 1:06:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2017 1:06:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 1:06:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 1:06:31 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 12:36:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8673.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/4/2017 10:24:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/4/2017 10:23:27 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/4/2017 10:12:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 10:11:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 10:11:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 9:59:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad84500b-a8bc-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 9:59:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/4/2017 9:30:47 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 13346, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	10/4/2017 9:30:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/4/2017 9:30:09 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	10/4/2017 9:30:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/4/2017 8:41:24 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/4/2017 6:12:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 6:11:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 5:41:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/4/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22338)(?)])(1 )(2 )]

"
Information	10/4/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22338)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/4/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 5:36:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 4:59:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c38f8d8f-a892-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 4:27:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 4:27:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:41Z. Reason: GVLK.
Information	10/4/2017 4:22:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2017 4:22:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 4:22:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 4:22:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 4:21:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74ae0625-a88d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 4:21:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74ae0624-a88d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/4/2017 4:21:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74ae0623-a88d-11e7-b5fc-0205857feb80
Report Status: 0"
Error	10/4/2017 4:18:42 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/4/2017 4:11:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 4:11:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:04Z. Reason: GVLK.
Error	10/4/2017 4:06:48 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/4/2017 4:06:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2017 4:06:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 4:06:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 4:06:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 2:46:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/4/2017 2:46:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:04Z. Reason: GVLK.
Information	10/4/2017 2:41:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/4/2017 2:41:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/4/2017 2:41:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/4/2017 2:41:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/4/2017 2:12:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 2:11:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 2:11:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/4/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/3/2017 11:59:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d86a5d55-a868-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 10:11:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:11:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:11:30 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/3/2017 10:11:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:11:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 7:04:44 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/3/2017 7:04:44 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	10/3/2017 7:04:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:33:41.383189900Z.
Information	10/3/2017 7:04:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F7E2C048-57DE-4626-88D4-EEEFD141223B}\DeviceManager.msi. Client Process Id: 18988.
Information	10/3/2017 7:03:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:33:41.383189900Z.
Information	10/3/2017 7:03:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F7E2C048-57DE-4626-88D4-EEEFD141223B}\DeviceManager.msi. Client Process Id: 18988.
Information	10/3/2017 7:03:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:32:29.068959200Z.
Information	10/3/2017 7:03:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AE936DC4-42BC-48CA-A606-1755A39B3873}\DeviceDriver.msi. Client Process Id: 13796.
Information	10/3/2017 7:03:19 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.1.0.51. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	10/3/2017 7:03:19 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	10/3/2017 7:02:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:32:29.068959200Z.
Information	10/3/2017 7:02:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AE936DC4-42BC-48CA-A606-1755A39B3873}\DeviceDriver.msi. Client Process Id: 13796.
Information	10/3/2017 6:59:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ee5bcb2f-a83e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 6:56:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:25:52.804336700Z.
Information	10/3/2017 6:56:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	10/3/2017 6:56:01 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/3/2017 6:56:01 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	10/3/2017 6:55:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:25:52.804336700Z.
Information	10/3/2017 6:55:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	10/3/2017 6:55:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:25:10.240080700Z.
Information	10/3/2017 6:55:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	10/3/2017 6:55:45 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/3/2017 6:55:45 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	10/3/2017 6:55:18 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	10/3/2017 6:55:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:25:10.240080700Z.
Information	10/3/2017 6:55:07 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	10/3/2017 6:44:04 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:13:31.635769300Z.
Information	10/3/2017 6:44:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	10/3/2017 6:44:04 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 1602.
Information	10/3/2017 6:44:04 PM	MsiInstaller	11725	None	Product: DeviceManager -- Removal failed.
Information	10/3/2017 6:43:54 PM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Information	10/3/2017 6:43:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:13:31.635769300Z.
Information	10/3/2017 6:43:25 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	10/3/2017 6:42:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎03T13:11:01.531728000Z.
Information	10/3/2017 6:42:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8448.
Information	10/3/2017 6:42:54 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	10/3/2017 6:42:54 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	10/3/2017 6:41:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎03T13:11:01.531728000Z.
Information	10/3/2017 6:40:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8448.
Information	10/3/2017 6:11:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 6:11:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 6:11:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 5:33:08 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 5:33:08 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:08Z. Reason: GVLK.
Information	10/3/2017 5:28:08 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2017 5:28:08 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 5:28:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 5:28:07 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 3:23:03 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/3/2017 2:11:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:11:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:11:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:11:04 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	10/3/2017 2:10:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 1:59:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 029e14f6-a815-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 12:57:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8672.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/3/2017 11:37:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	10/3/2017 11:37:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	10/3/2017 10:11:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:11:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:11:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:10:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 10:09:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	10/3/2017 10:09:07 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/3/2017 10:09:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/3/2017 8:59:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 17ad6c72-a7eb-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 6:11:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 6:11:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 6:10:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/3/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23778)(?)])(1 )(2 )]

"
Information	10/3/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23778)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 5:14:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 5:09:48 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎10‎-‎02T23:39:48.197637200Z.
Information	10/3/2017 5:09:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/3/2017 5:09:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 5:09:31 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 4:35:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 4:35:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:09Z. Reason: GVLK.
Information	10/3/2017 4:30:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2017 4:30:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 4:30:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 4:30:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 4:29:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e7a6b89-a7c5-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 4:29:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e7a6b88-a7c5-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 4:29:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e7a6b87-a7c5-11e7-b5fc-0205857feb80
Report Status: 0"
Error	10/3/2017 4:26:04 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/3/2017 4:18:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 4:18:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:08Z. Reason: GVLK.
Error	10/3/2017 4:13:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/3/2017 4:13:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2017 4:13:07 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 4:13:07 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 4:13:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 4:13:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 4:13:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:06Z. Reason: GVLK.
Information	10/3/2017 4:08:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2017 4:08:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 4:08:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 4:08:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 3:59:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2d0e8bf5-a7c1-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/3/2017 2:11:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:11:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:10:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 2:10:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/3/2017 1:15:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/3/2017 1:15:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:19Z. Reason: GVLK.
Information	10/3/2017 1:10:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/3/2017 1:10:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/3/2017 1:10:18 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/3/2017 1:10:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/3/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/2/2017 11:17:40 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/2/2017 10:59:36 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 42b1eee3-a797-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 10:11:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 10:11:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 10:10:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 10:10:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 8:21:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 8:21:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:23Z. Reason: GVLK.
Information	10/2/2017 8:16:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2017 8:16:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 8:16:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 8:16:21 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Friday, September 22, 2017 9:27:10 PM.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Halcom CA FO, O=Halcom, C=SI> Sha1 thumbprint: <0409565B77DA582E6495AC0060A72354E64B0192>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4108	None	Successful auto delete of third-party root certificate:: Subject: <CN=Sonera Class1 CA, O=Sonera, C=FI> Sha1 thumbprint: <0747220199CE74B97CB03D79B264A2C855E933FF>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=VAS Latvijas Pasts SSI(RCA), OU=Sertifikacijas pakalpojumi, O=VAS Latvijas Pasts - Vien.reg.Nr.40003052790, C=LV> Sha1 thumbprint: <086418E906CEE89C2353B6E27FBD9E7439F76316>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=SSC Root CA C, OU=Certification Authority, O=Skaitmeninio sertifikavimo centras, C=LT> Sha1 thumbprint: <23E833233E7D0CC92B7C4279AC19C2F474D604CA>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=StartCom Certification Authority G2, O=StartCom Ltd., C=IL> Sha1 thumbprint: <31F1FD68226320EEC63B3F9DEA4A3E537C7C3917>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL> Sha1 thumbprint: <3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=SSC Root CA B, OU=Certification Authority, O=Skaitmeninio sertifikavimo centras, C=LT> Sha1 thumbprint: <3E84D3BCC544C0F6FA19435C851F3F2FCBA8E814>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <OU=FNMT Clase 2 CA, O=FNMT, C=ES> Sha1 thumbprint: <43F9B110D5BAFD48225231B0D0082B372FEF9A54>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU=""(c) 2006 VeriSign, Inc. - For authorized use only"", OU=VeriSign Trust Network, O=""VeriSign, Inc."", C=US> Sha1 thumbprint: <4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5>."
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=SSC Root CA A, OU=Certification Authority, O=Skaitmeninio sertifikavimo centras, C=LT> Sha1 thumbprint: <5A5A4DAF7861267C4B1F1E67586BAE6ED4FEB93F>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Swisscom Root CA 1, OU=Digital Certificate Services, O=Swisscom, C=ch> Sha1 thumbprint: <5F3AFC0A8B64F686673474DF7EA9A2FEF9FA7A51>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <O=""První certifikační autorita, a.s."", CN=I.CA - Qualified root certificate, C=CZ> Sha1 thumbprint: <64902AD7277AF3E32CD8CC1DC79DE1FD7F8069EA>."
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=ePKI Root Certification Authority, O=""Chunghwa Telecom Co., Ltd."", C=TW> Sha1 thumbprint: <67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0>."
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Swisscom Root CA 2, OU=Digital Certificate Services, O=Swisscom, C=ch> Sha1 thumbprint: <77474FC630E40F4C47643F84BAB8C6954A8A41EC>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Halcom CA PO 2, O=Halcom, C=SI> Sha1 thumbprint: <7FBB6ACD7E0AB438DAAF6FD50210D007C6C0829C>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=ComSign Advanced Security CA> Sha1 thumbprint: <80BF3DE9A41D768D194B293C85632CDBC8EA8CF7>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=I.CA - Provider of Certification Services, O=""První certifikační autorita, a.s."", CN=""I.CA - Standard Certification Authority, 09/2009"", C=CZ> Sha1 thumbprint: <90DECE77F8C825340E62EBD635E1BE20CF7327DD>."
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GeoTrust Global CA 2, O=GeoTrust Inc., C=US> Sha1 thumbprint: <A9E9780814375888F20519B06D2B0D2B6016907D>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <O=Prvni certifikacni autorita a.s., CN=I.CA - Standard root certificate, C=CZ> Sha1 thumbprint: <AB16DD144ECDC0FC4BAAB62ECF0408896FDE52B7>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB> Sha1 thumbprint: <AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <OU=AC RAIZ FNMT-RCM, O=FNMT-RCM, C=ES> Sha1 thumbprint: <B865130BEDCA38D27F69929420770BED86EFBC10>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=S-TRUST Authentication and Encryption Root CA 2005:PN, O=Deutscher Sparkassen Verlag GmbH, L=Stuttgart, S=Baden-Wuerttemberg (BW), C=DE> Sha1 thumbprint: <BEB5A995746B9EDF738B56E6DF437A77BE106B81>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=E-ME SSI (RCA), OU=Sertifikacijas pakalpojumu dala, C=LV> Sha1 thumbprint: <C9321DE6B5A82666CF6971A18A56F2D3A8675602>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	"Successful auto property update of third-party root certificate:: Subject: <OU=I.CA - Accredited Provider of Certification Services, O=""První certifikační autorita, a.s."", CN=""I.CA - Qualified Certification Authority, 09/2009"", C=CZ> Sha1 thumbprint: <D2441AA8C203AECAA96E501F124D52B68FE4C375>."
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=SZAFIR ROOT CA, O=Krajowa Izba Rozliczeniowa S.A., C=PL> Sha1 thumbprint: <D3EEFBCBBCF49867838626E23BB59CA01E305DB7>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE> Sha1 thumbprint: <D4DE20D05E66FC53FE1A50882C78DB2852CAE474>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <C=IL, O=ComSign, CN=ComSign CA> Sha1 thumbprint: <E1A45B141A21DA1A79F41A42A961D669CD0634C1>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Swisscom Root EV CA 2, OU=Digital Certificate Services, O=Swisscom, C=ch> Sha1 thumbprint: <E7A19029D3D552DC0D0FC692D3EA880D152E1A6B>.
Information	10/2/2017 6:16:44 PM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <C=IL, O=ComSign, CN=ComSign Secured CA> Sha1 thumbprint: <F9CD0E2CDA7624C18FBDF0F0ABB645B8F7FED57A>.
Information	10/2/2017 6:11:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 6:10:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 6:10:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 5:59:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58333a5b-a76d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 2:11:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 2:10:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 2:10:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 1:47:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 1:47:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:26Z. Reason: GVLK.
Information	10/2/2017 1:42:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2017 1:42:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 1:42:26 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 1:42:25 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 1:34:13 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/2/2017 12:59:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6deb90fe-a743-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 12:29:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8671.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/2/2017 10:10:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 10:10:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 7:59:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8306f9d4-a719-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 7:04:31 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/2/2017 6:40:47 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/2/2017 6:40:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/2/2017 6:10:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 6:10:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 5:41:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/2/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25218)(?)])(1 )(2 )]

"
Information	10/2/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25218)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/2/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 4:48:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 4:48:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:31Z. Reason: GVLK.
Information	10/2/2017 4:43:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2017 4:43:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 4:43:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 4:43:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 4:38:38 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	10/2/2017 4:38:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	10/2/2017 3:56:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 3:56:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:01Z. Reason: GVLK.
Information	10/2/2017 3:51:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2017 3:51:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 3:51:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 3:50:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 3:50:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b271b039-a6f6-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 3:50:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b271b038-a6f6-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 3:50:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b271b037-a6f6-11e7-b5fc-0205857feb80
Report Status: 0"
Error	10/2/2017 3:44:54 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/2/2017 3:25:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/2/2017 3:25:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:58Z. Reason: GVLK.
Error	10/2/2017 3:21:54 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/2/2017 3:20:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/2/2017 3:20:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/2/2017 3:20:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/2/2017 3:20:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/2/2017 2:59:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97b92fcd-a6ef-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/2/2017 2:10:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 2:10:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/2/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	10/1/2017 10:10:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 9:59:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad63e248-a6c5-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 6:25:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D2B9C003-A3CD-44A0-9DE5-52FE986C03E5}. Client Process Id: 10640.
Information	10/1/2017 6:25:48 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee Host Intrusion Prevention. Product Version: 8.00.0900. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	10/1/2017 6:25:48 PM	MsiInstaller	11728	None	Product: McAfee Host Intrusion Prevention -- Configuration completed successfully.
Information	10/1/2017 6:25:48 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: McAfee Host Intrusion Prevention. Product Version: 8.00.0900. Product Language: 1033. Manufacturer: McAfee, Inc.. Update Name: McAfee Host Intrusion Prevention 8.0 Patch 9 x64. Installation success or error status: 0.
Information	10/1/2017 6:25:48 PM	MsiInstaller	1022	None	Product: McAfee Host Intrusion Prevention - Update 'McAfee Host Intrusion Prevention 8.0 Patch 9 x64' installed successfully.
Information	10/1/2017 6:25:12 PM	Interactive Services detection	1000	None	A device or program has requested attention. Device or application: C:\Windows\SysWOW64\cmd.exe. Message title: C:\Windows\SysWOW64\cmd.exe.
Information	10/1/2017 6:25:12 PM	Interactive Services detection	1000	None	A device or program has requested attention. Device or application: C:\Windows\SysWOW64\cmd.exe. Message title: C:\Windows\SysWOW64\cmd.exe.
Information	10/1/2017 6:24:36 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8670.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/1/2017 6:23:33 PM	Interactive Services detection	1000	None	A device or program has requested attention. Device or application: C:\Windows\SysWOW64\reg.exe. Message title: C:\Windows\SysWOW64\reg.exe.
Information	10/1/2017 6:22:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎01T12:52:56.334371500Z.
Information	10/1/2017 6:22:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D2B9C003-A3CD-44A0-9DE5-52FE986C03E5}. Client Process Id: 10640.
Information	10/1/2017 6:22:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\19c366.msi. Client Process Id: 20052.
Information	10/1/2017 6:22:58 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/1/2017 6:22:58 PM	MsiInstaller	11728	None	Product: Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 -- Configuration completed successfully.
Information	10/1/2017 6:22:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎01T12:52:56.334371500Z.
Information	10/1/2017 6:22:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎01T12:52:55.647962700Z.
Information	10/1/2017 6:22:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎01T12:52:55.647962700Z.
Information	10/1/2017 6:22:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\19c366.msi. Client Process Id: 20052.
Information	10/1/2017 6:22:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: d:\e9eebb317b99c24c8e26\vc_red.msi. Client Process Id: 20052.
Information	10/1/2017 6:22:56 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/1/2017 6:22:56 PM	MsiInstaller	11728	None	Product: Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 -- Configuration completed successfully.
Information	10/1/2017 6:22:55 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: d:\e9eebb317b99c24c8e26\vc_red.msi. Client Process Id: 20052.
Information	10/1/2017 6:22:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎01T12:52:48.393869700Z.
Information	10/1/2017 6:22:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\19c37f.msi. Client Process Id: 7424.
Information	10/1/2017 6:22:51 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/1/2017 6:22:51 PM	MsiInstaller	11728	None	Product: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 -- Configuration completed successfully.
Information	10/1/2017 6:22:48 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎01T12:52:48.393869700Z.
Information	10/1/2017 6:22:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎10‎-‎01T12:52:47.801062100Z.
Information	10/1/2017 6:22:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎10‎-‎01T12:52:47.801062100Z.
Information	10/1/2017 6:22:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\19c37f.msi. Client Process Id: 7424.
Information	10/1/2017 6:22:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: d:\37b3ab7e55ae133a1623bbfdad9cd55f\vc_red.msi. Client Process Id: 7424.
Information	10/1/2017 6:22:48 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219. Product Version: 10.0.40219. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	10/1/2017 6:22:48 PM	MsiInstaller	11728	None	Product: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 -- Configuration completed successfully.
Information	10/1/2017 6:22:47 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: d:\37b3ab7e55ae133a1623bbfdad9cd55f\vc_red.msi. Client Process Id: 7424.
Information	10/1/2017 6:22:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}. Client Process Id: 18592.
Information	10/1/2017 6:22:16 PM	MsiInstaller	1029	None	Product: McAfee VirusScan Enterprise. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	10/1/2017 6:22:16 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: McAfee VirusScan Enterprise. Product Version: 8.8.09000. Product Language: 1033. Manufacturer: McAfee, Inc.. Type of System Restart: 2. Reason for Restart: 1.
Information	10/1/2017 6:22:16 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: McAfee VirusScan Enterprise. Product Version: 8.8.09000. Product Language: 1033. Manufacturer: McAfee, Inc.. Reconfiguration success or error status: 0.
Information	10/1/2017 6:22:16 PM	MsiInstaller	11728	None	Product: McAfee VirusScan Enterprise -- Configuration completed successfully.
Information	10/1/2017 6:22:16 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: McAfee VirusScan Enterprise. Product Version: 8.8.09000. Product Language: 1033. Manufacturer: McAfee, Inc.. Update Name: McAfee VirusScan Enterprise 8.8 Patch 9. Installation success or error status: 0.
Information	10/1/2017 6:22:16 PM	MsiInstaller	1022	None	Product: McAfee VirusScan Enterprise - Update 'McAfee VirusScan Enterprise 8.8 Patch 9' installed successfully.
Information	10/1/2017 6:22:06 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8670.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/1/2017 6:21:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8670.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/1/2017 6:21:07 PM	MsiInstaller	1025	None	Product: McAfee VirusScan Enterprise. The file C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\shext.dll is being used by the following process: Name: explorer , Id 5272.
Information	10/1/2017 6:20:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}. Client Process Id: 18592.
Information	10/1/2017 6:10:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 6:09:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 4:59:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2ae51e3-a69b-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 2:52:39 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	10/1/2017 2:10:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 2:09:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 12:30:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8670.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	10/1/2017 12:08:05 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	10/1/2017 11:59:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d7b878df-a671-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 10:10:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 10:09:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 9:30:51 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 13289, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	10/1/2017 9:30:17 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	10/1/2017 9:30:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	10/1/2017 9:30:10 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	10/1/2017 9:30:09 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	10/1/2017 8:52:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2017 8:52:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:37Z. Reason: GVLK.
Information	10/1/2017 8:47:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2017 8:47:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2017 8:47:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2017 8:47:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/1/2017 6:59:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed7a33c8-a647-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 6:10:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 6:09:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26658)(?)])(1 )(2 )]

"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26658)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2017 5:36:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/1/2017 4:01:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2017 4:01:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:57Z. Reason: GVLK.
Information	10/1/2017 3:56:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2017 3:56:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2017 3:56:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2017 3:56:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/1/2017 3:55:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 33e9aaeb-a62e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 3:55:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 33e9aaea-a62e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 3:55:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 33e9aae9-a62e-11e7-b5fc-0205857feb80
Report Status: 0"
Error	10/1/2017 3:52:07 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	10/1/2017 3:40:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	10/1/2017 3:40:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:54Z. Reason: GVLK.
Error	10/1/2017 3:36:43 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	10/1/2017 3:35:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	10/1/2017 3:35:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	10/1/2017 3:35:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2017 3:35:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	10/1/2017 3:25:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	10/1/2017 3:20:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎30T21:50:49.866269200Z.
Information	10/1/2017 3:20:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	10/1/2017 3:20:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	10/1/2017 3:20:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	10/1/2017 2:10:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 2:09:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	10/1/2017 1:59:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 034c23bc-a61e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	10/1/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/30/2017 10:09:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 10:09:57 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/30/2017 10:09:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 9:27:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2017 9:27:28 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:28Z. Reason: GVLK.
Information	9/30/2017 9:22:28 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2017 9:22:28 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2017 9:22:28 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2017 9:22:27 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2017 9:14:42 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/30/2017 8:59:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 182ff424-a5f4-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 6:09:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 5:54:53 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/30/2017 5:54:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/30/2017 4:13:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2017 4:13:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:01Z. Reason: GVLK.
Information	9/30/2017 4:08:01 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2017 4:08:01 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2017 4:08:01 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2017 4:08:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2017 3:59:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2da07e91-a5ca-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 2:09:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 2:09:32 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/30/2017 2:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 1:00:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/30/2017 1:00:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/30/2017 12:00:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8669.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	9/30/2017 11:30:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/30/2017 11:30:04 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/30/2017 11:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/30/2017 10:58:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4263060b-a5a0-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 10:09:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 10:09:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 9:55:01 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/30/2017 6:59:27 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/30/2017 6:59:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/30/2017 6:09:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 6:09:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 5:58:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5861982b-a576-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28098)(?)])(1 )(2 )]

"
Information	9/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28098)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/30/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/30/2017 5:03:43 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/30/2017 5:03:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/30/2017 4:13:47 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/30/2017 3:47:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2017 3:47:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:52Z. Reason: GVLK.
Information	9/30/2017 3:42:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2017 3:42:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2017 3:42:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2017 3:42:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2017 3:42:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37179234-a563-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 3:42:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37179233-a563-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 3:42:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 37179232-a563-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/30/2017 3:38:47 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/30/2017 3:30:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/30/2017 3:30:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:34Z. Reason: GVLK.
Error	9/30/2017 3:26:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/30/2017 3:25:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/30/2017 3:25:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/30/2017 3:25:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/30/2017 3:25:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/30/2017 2:09:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 2:09:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/30/2017 12:58:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d633ca2-a54c-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/30/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/29/2017 10:32:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 10:32:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:56Z. Reason: GVLK.
Information	9/29/2017 10:27:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 10:27:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 10:27:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 10:27:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 10:09:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 10:08:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 7:58:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8273f38f-a522-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 7:19:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 7:19:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:11Z. Reason: GVLK.
Information	9/29/2017 7:14:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 7:14:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 7:14:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 7:14:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 6:09:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 6:08:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 4:23:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 4:23:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:41Z. Reason: GVLK.
Information	9/29/2017 4:18:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 4:18:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 4:18:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 4:18:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 3:01:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 02fb7ba9-a4f9-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 3:00:14 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	9/29/2017 3:00:14 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	9/29/2017 2:58:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 986bd6bf-a4f8-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 2:57:18 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎29T09:25:23.676358600Z.
Information	9/29/2017 2:57:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{892BBE49-607C-4A35-BFDA-0842B50179F8}\DeviceManager.msi. Client Process Id: 4492.
Information	9/29/2017 2:55:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎29T09:25:23.676358600Z.
Information	9/29/2017 2:55:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{892BBE49-607C-4A35-BFDA-0842B50179F8}\DeviceManager.msi. Client Process Id: 4492.
Information	9/29/2017 2:53:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎29T09:20:22.297223700Z.
Information	9/29/2017 2:53:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B024B472-3A31-46B9-A88D-FD800C68CBE7}\DeviceDriver.msi. Client Process Id: 18684.
Information	9/29/2017 2:53:30 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	9/29/2017 2:53:30 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	9/29/2017 2:50:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎29T09:20:22.297223700Z.
Information	9/29/2017 2:50:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B024B472-3A31-46B9-A88D-FD800C68CBE7}\DeviceDriver.msi. Client Process Id: 18684.
Information	9/29/2017 2:16:44 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.1.0.45. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	9/29/2017 2:16:44 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	9/29/2017 2:14:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎29T08:40:28.165153800Z.
Information	9/29/2017 2:14:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{451A9075-3F8D-4C7F-AD94-FD1E5D08DBCA}\4Sight™ 2.msi. Client Process Id: 14692.
Information	9/29/2017 2:10:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎29T08:40:28.165153800Z.
Information	9/29/2017 2:10:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{451A9075-3F8D-4C7F-AD94-FD1E5D08DBCA}\4Sight™ 2.msi. Client Process Id: 14692.
Information	9/29/2017 2:10:13 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/29/2017 2:10:12 PM	PostgreSQL	0	None	"2017-09-29 14:10:12 IST LOG:  redirecting log output to logging collector process
2017-09-29 14:10:12 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/29/2017 2:10:12 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/29/2017 2:08:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 2:08:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 12:57:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 12:56:29 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8668.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	9/29/2017 12:52:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/29/2017 12:52:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29103)(?)])(1 )(2 )]

"
Information	9/29/2017 12:52:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29103)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 12:52:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/29/2017 12:52:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 12:52:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 12:40:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎29T07:10:07.668410800Z.
Information	9/29/2017 12:40:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	9/29/2017 12:40:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	9/29/2017 12:40:11 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	9/29/2017 12:40:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎29T07:10:07.668410800Z.
Information	9/29/2017 12:40:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	9/29/2017 12:39:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎29T07:08:40.602705100Z.
Information	9/29/2017 12:39:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	9/29/2017 12:39:27 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	9/29/2017 12:39:27 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	9/29/2017 12:38:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎29T07:08:40.602705100Z.
Information	9/29/2017 12:38:36 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 8448.
Information	9/29/2017 12:38:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	9/29/2017 12:38:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	9/29/2017 12:38:31 PM	MsiInstaller	11729	None	Product: DeviceDriver -- Configuration failed.
Information	9/29/2017 12:38:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 8448.
Information	9/29/2017 12:06:29 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/29/2017 11:35:06 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 239c11fd-a4dc-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 10:08:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 10:08:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 10:07:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/29/2017 10:07:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/29/2017 10:07:03 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/29/2017 9:58:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa8c0a49-a4ce-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 6:53:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 6:48:20 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎29T01:18:20.531920200Z.
Information	9/29/2017 6:48:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/29/2017 6:48:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 6:48:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 6:08:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 5:52:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 5:52:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:02Z. Reason: GVLK.
Information	9/29/2017 5:47:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 5:47:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 5:47:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 5:47:02 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/29/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29538)(?)])(1 )(2 )]

"
Information	9/29/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29538)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/29/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 4:58:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c0833bcf-a4a4-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 4:26:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 4:26:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:32Z. Reason: GVLK.
Information	9/29/2017 4:21:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 4:21:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 4:21:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 4:21:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 4:21:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 803a586b-a49f-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 4:21:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 803a586a-a49f-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/29/2017 4:21:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 803a5869-a49f-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/29/2017 4:17:55 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/29/2017 4:10:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 4:10:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:33Z. Reason: GVLK.
Error	9/29/2017 4:05:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/29/2017 4:05:33 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 4:05:33 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 4:05:33 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 4:05:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 2:49:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/29/2017 2:49:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:08:09Z. Reason: GVLK.
Information	9/29/2017 2:44:09 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/29/2017 2:44:09 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/29/2017 2:44:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/29/2017 2:44:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/29/2017 2:08:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/29/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/28/2017 11:58:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d5b862e5-a47a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 10:08:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Error	9/28/2017 8:31:40 PM	Outlook	35	None	Failed to determine if the store is in the crawl scope (error=0x80040150).
Error	9/28/2017 8:31:40 PM	Outlook	34	None	Failed to get the Crawl Scope Manager with error=0x80040150.
Information	9/28/2017 8:30:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 8:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 8:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30089)(?)])(1 )(2 )]

"
Information	9/28/2017 8:25:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30089)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 8:25:41 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 8:25:41 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 8:25:40 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 8:10:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 8:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 8:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30110)(?)])(1 )(2 )]

"
Information	9/28/2017 8:05:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30110)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 8:03:47 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 8:03:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30111)(?)])(1 )(2 )]

"
Information	9/28/2017 8:03:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30111)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 8:03:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 8:03:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 8:03:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 8:01:35 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 7:56:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 7:56:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30118)(?)])(1 )(2 )]

"
Information	9/28/2017 7:56:32 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30118)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 7:56:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 7:56:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 7:56:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 7:53:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 7:48:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 7:48:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30127)(?)])(1 )(2 )]

"
Information	9/28/2017 7:48:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30127)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 7:48:19 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 7:48:19 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 7:48:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 7:23:11 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/28/2017 7:20:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 7:15:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 7:15:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30160)(?)])(1 )(2 )]

"
Information	9/28/2017 7:15:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30160)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 7:15:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 7:15:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 7:15:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎28T13:44:54.878550200Z.
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎28T13:44:54.878550200Z.
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎28T13:44:54.692531600Z.
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎28T13:44:54.692531600Z.
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎28T13:44:54.525514900Z.
Information	9/28/2017 7:14:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎28T13:44:54.525514900Z.
Information	9/28/2017 7:14:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎28T13:44:53.918454200Z.
Information	9/28/2017 7:14:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎28T13:44:53.918454200Z.
Information	9/28/2017 7:14:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎28T13:44:49.949057300Z.
Information	9/28/2017 7:14:49 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎28T13:44:49.949057300Z.
Information	9/28/2017 6:58:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eb83aab4-a450-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 6:08:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 5:57:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 5:52:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 5:52:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30242)(?)])(1 )(2 )]

"
Information	9/28/2017 5:52:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30242)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 5:52:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 5:52:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 5:52:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 4:14:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30346)(?)])(1 )(2 )]

"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30346)(?)])(1 )(2 )]

"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30346)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 4:09:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30346)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 4:09:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 4:09:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 4:09:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 2:46:47 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 2:46:47 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:47Z. Reason: GVLK.
Information	9/28/2017 2:41:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2017 2:41:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 2:41:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 2:41:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 2:07:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 2:07:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 1:58:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 012f3d52-a427-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 12:48:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8667.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	9/28/2017 11:43:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 11:43:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-10-05T06:07:19Z. Reason: GVLK.
Information	9/28/2017 11:38:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 11:38:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 11:38:18 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/09/28 06:08"
Information	9/28/2017 11:38:17 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/09/28 06:08, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/28/2017 11:33:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2017 11:33:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 11:33:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 11:33:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 10:15:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/28/2017 10:15:39 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/28/2017 10:15:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/28/2017 10:07:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 10:07:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 9:31:06 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/28/2017 9:31:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/28/2017 9:30:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 13254, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/28/2017 9:30:06 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/28/2017 8:58:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 16e551cf-a3fd-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 6:07:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 6:07:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/28/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30978)(?)])(1 )(2 )]

"
Information	9/28/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30978)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/28/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 3:58:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2c74ac9f-a3d3-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 3:47:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 3:47:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:13Z. Reason: GVLK.
Information	9/28/2017 3:42:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2017 3:42:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 3:42:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 3:42:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 3:41:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d40e6f31-a3d0-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 3:41:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d40e6f30-a3d0-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/28/2017 3:41:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d40e6f2f-a3d0-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/28/2017 3:38:26 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/28/2017 3:29:53 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/28/2017 3:29:53 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:53Z. Reason: GVLK.
Error	9/28/2017 3:25:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/28/2017 3:24:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/28/2017 3:24:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/28/2017 3:24:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/28/2017 3:24:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/28/2017 2:50:34 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/28/2017 2:49:54 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/28/2017 2:22:04 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/28/2017 2:07:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 2:07:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/28/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/27/2017 10:58:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 424b6d7f-a3a9-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 10:07:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 10:07:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 8:52:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 8:52:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:50Z. Reason: GVLK.
Information	9/27/2017 8:47:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 8:47:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 8:47:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 8:47:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 6:07:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 6:07:44 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/27/2017 6:07:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 5:58:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58340aad-a37f-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 4:13:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 4:13:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:12Z. Reason: GVLK.
Information	9/27/2017 4:08:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 4:08:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 4:08:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 4:08:11 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 2:15:14 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8666.0000
 
 Number of signatures in EXTRA.DAT : 3
 Names of threats that EXTRA.DAT can detect : VBS/Autorun.FUST.c (ED)
VBS/Autorun.FUST.d (ED)
VBS/Autorun.worm.aakd (ED)
"
Information	9/27/2017 2:07:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 2:07:27 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/27/2017 2:07:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 12:58:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6c6ebe02-a355-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 12:14:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8666.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/27/2017 11:30:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/27/2017 11:30:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/27/2017 10:47:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 10:42:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32113)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 10:42:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32113)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 10:42:14 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/27/2017 10:42:14 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/27/2017 10:42:14 AM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	9/27/2017 10:42:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/27/2017 10:42:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 10:42:13 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 10:26:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/27/2017 10:26:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/27/2017 10:26:05 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/27/2017 10:07:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 10:07:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 9:10:47 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/27/2017 8:02:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 8:02:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:48Z. Reason: GVLK.
Information	9/27/2017 7:58:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 812b6f22-a32b-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 7:57:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 7:57:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 7:57:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 7:57:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 6:07:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 6:07:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/27/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32418)(?)])(1 )(2 )]

"
Information	9/27/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32418)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/27/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 3:23:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 3:23:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:48Z. Reason: GVLK.
Information	9/27/2017 3:18:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 3:18:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 3:18:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 3:18:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 3:18:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a70e7e5-a304-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 3:18:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a70e7e4-a304-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 3:18:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a70e7e3-a304-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/27/2017 3:15:21 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/27/2017 3:07:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 3:07:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:16Z. Reason: GVLK.
Error	9/27/2017 3:02:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/27/2017 3:02:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 3:02:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 3:02:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 3:02:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 2:58:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 96ecb0e3-a301-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/27/2017 2:07:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 2:06:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/27/2017 1:45:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/27/2017 1:45:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:19Z. Reason: GVLK.
Information	9/27/2017 1:40:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/27/2017 1:40:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/27/2017 1:40:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/27/2017 1:40:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/27/2017 12:08:55 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/26/2017 10:06:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 10:06:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 9:58:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad099de3-a2d7-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 8:06:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 8:01:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32993)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 8:01:34 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32993)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 8:01:34 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/26/2017 8:01:34 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/26/2017 8:01:34 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	9/26/2017 7:57:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2017 7:57:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32997)(?)])(1 )(2 )]

"
Information	9/26/2017 7:57:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32997)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 7:57:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2017 7:57:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 7:57:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 6:38:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 6:38:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:14Z. Reason: GVLK.
Information	9/26/2017 6:33:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2017 6:33:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 6:33:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 6:33:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 6:06:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 6:06:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 4:58:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c2c62f64-a2ad-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 4:03:43 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/26/2017 2:06:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 2:06:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 12:29:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8665.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/26/2017 12:11:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 12:06:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2017 12:06:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33469)(?)])(1 )(2 )]

"
Information	9/26/2017 12:06:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33469)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 12:06:05 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2017 12:06:05 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 12:06:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 11:58:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d885cfdf-a283-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 10:32:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/26/2017 10:32:22 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/26/2017 10:32:22 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/26/2017 10:06:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 10:06:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 9:18:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 9:18:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:45Z. Reason: GVLK.
Information	9/26/2017 9:13:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2017 9:13:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 9:13:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 9:13:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 6:58:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: eeb16992-a259-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 6:06:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 6:05:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 5:41:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33858)(?)])(1 )(2 )]

"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33858)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 4:42:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 4:37:49 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎25T23:07:49.282076600Z.
Information	9/26/2017 4:37:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/26/2017 4:37:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 4:37:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 3:30:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 3:30:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:31Z. Reason: GVLK.
Information	9/26/2017 3:25:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2017 3:25:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 3:25:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 3:25:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 3:25:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2d41e3ed-a23c-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 3:25:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2d41e3ec-a23c-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 3:25:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2d41e3eb-a23c-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/26/2017 3:21:49 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/26/2017 3:14:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/26/2017 3:14:24 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:24Z. Reason: GVLK.
Error	9/26/2017 3:09:35 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/26/2017 3:09:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/26/2017 3:09:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/26/2017 3:09:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/26/2017 3:09:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/26/2017 2:06:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 2:05:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/26/2017 1:56:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e030fb23-a22f-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/26/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/25/2017 11:57:42 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/25/2017 10:06:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 10:05:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 9:39:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 9:39:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:36Z. Reason: GVLK.
Information	9/25/2017 9:34:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 9:34:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 9:34:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 9:34:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 8:56:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: efa6dae4-a205-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 8:14:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 8:09:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/25/2017 8:09:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34426)(?)])(1 )(2 )]

"
Information	9/25/2017 8:09:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34426)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 8:09:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/25/2017 8:09:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 8:09:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 6:06:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 6:05:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 4:17:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 4:12:05 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/25/2017 4:12:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34663)(?)])(1 )(2 )]

"
Information	9/25/2017 4:12:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 34663)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 4:12:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/25/2017 4:12:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 4:12:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 3:56:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 059e48db-a1dc-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 3:37:46 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/25/2017 3:37:37 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/25/2017 2:05:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 2:05:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 12:05:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8664.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/25/2017 10:56:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1aa2a1bb-a1b2-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 10:05:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 10:05:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 9:53:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/25/2017 9:31:35 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/25/2017 9:31:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/25/2017 9:30:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 3, Compared: 13093, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/25/2017 9:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/25/2017 9:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/25/2017 8:14:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 8:14:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:28Z. Reason: GVLK.
Information	9/25/2017 8:09:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 8:09:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 8:09:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 8:09:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 7:16:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 7:16:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:14Z. Reason: GVLK.
Information	9/25/2017 7:11:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 7:11:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 7:11:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 7:11:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 6:31:51 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/25/2017 6:15:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 6:15:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:20Z. Reason: GVLK.
Information	9/25/2017 6:10:20 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 6:10:20 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 6:10:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 6:10:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 6:05:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 6:04:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 5:56:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30ba2dc0-a188-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/25/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35298)(?)])(1 )(2 )]

"
Information	9/25/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35298)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/25/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 3:57:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 3:57:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:45Z. Reason: GVLK.
Information	9/25/2017 3:52:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 3:52:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 3:52:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 3:52:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 3:52:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d16a5bf5-a176-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 3:52:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d16a5bf4-a176-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 3:52:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d16a5bf3-a176-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/25/2017 3:49:20 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/25/2017 3:41:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/25/2017 3:41:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:00Z. Reason: GVLK.
Error	9/25/2017 3:36:34 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/25/2017 3:35:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/25/2017 3:35:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/25/2017 3:35:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/25/2017 3:35:58 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/25/2017 2:05:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 2:04:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/25/2017 12:56:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 461c0b4b-a15e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/25/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/24/2017 10:05:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 10:04:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 7:56:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5c24e5e5-a134-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 6:05:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 6:04:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 4:25:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2017 4:25:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:21Z. Reason: GVLK.
Information	9/24/2017 4:20:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2017 4:20:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2017 4:20:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2017 4:20:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2017 2:56:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 722f3d15-a10a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 2:19:08 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/24/2017 2:08:22 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/24/2017 2:05:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 2:04:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/24/2017 2:04:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 12:22:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8663.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/24/2017 11:30:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/24/2017 11:30:33 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/24/2017 11:30:33 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/24/2017 10:04:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 9:56:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 876e364d-a0e0-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 6:04:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 5:47:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎24T00:17:23.870298600Z.
Information	9/24/2017 5:43:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/24/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/24/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36738)(?)])(1 )(2 )]

"
Information	9/24/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36738)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/24/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/24/2017 5:12:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2017 5:12:11 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:11Z. Reason: GVLK.
Information	9/24/2017 5:07:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2017 5:07:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2017 5:07:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2017 5:07:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2017 5:06:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bb27791-a0b8-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 5:06:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bb27790-a0b8-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 5:06:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bb2778f-a0b8-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/24/2017 5:03:39 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/24/2017 4:56:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d145d4f-a0b6-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/24/2017 4:55:18 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2017 4:55:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:17Z. Reason: GVLK.
Error	9/24/2017 4:50:51 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/24/2017 4:50:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2017 4:50:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2017 4:50:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2017 4:50:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2017 2:50:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/24/2017 2:50:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:20Z. Reason: GVLK.
Information	9/24/2017 2:43:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/24/2017 2:43:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/24/2017 2:43:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/24/2017 2:43:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/24/2017 2:04:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/24/2017 12:31:34 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/23/2017 11:56:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b2b1764e-a08c-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 10:03:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 9:02:02 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/23/2017 6:56:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c8a3b0d3-a062-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 6:03:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 5:38:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2017 5:38:52 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:52Z. Reason: GVLK.
Information	9/23/2017 5:33:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2017 5:33:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2017 5:33:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2017 5:33:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2017 2:18:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2017 2:18:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:07Z. Reason: GVLK.
Information	9/23/2017 2:13:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2017 2:13:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2017 2:13:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2017 2:13:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2017 2:04:54 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/23/2017 2:03:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 1:56:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: de7e1cd4-a038-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 12:22:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8662.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/23/2017 10:03:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 8:56:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f454fe07-a00e-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 6:03:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/23/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/23/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38178)(?)])(1 )(2 )]

"
Information	9/23/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38178)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/23/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2017 5:36:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/23/2017 3:58:49 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/23/2017 3:56:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0a4f2897-9fe5-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 3:33:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2017 3:33:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:47Z. Reason: GVLK.
Information	9/23/2017 3:28:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2017 3:28:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2017 3:28:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2017 3:28:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2017 3:28:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25e0f249-9fe1-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 3:28:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25e0f248-9fe1-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/23/2017 3:28:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 25e0f247-9fe1-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/23/2017 3:25:30 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/23/2017 3:17:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/23/2017 3:17:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:39Z. Reason: GVLK.
Error	9/23/2017 3:13:12 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/23/2017 3:12:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/23/2017 3:12:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/23/2017 3:12:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/23/2017 3:12:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/23/2017 2:02:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/23/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/22/2017 10:56:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f81467b-9fbb-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 10:02:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 9:49:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 9:49:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:05Z. Reason: GVLK.
Information	9/22/2017 9:44:05 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2017 9:44:05 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 9:44:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 9:44:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 6:02:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 5:56:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 346ba707-9f91-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/22/2017 3:03:18 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	9/22/2017 3:03:18 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/22/2017 2:06:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 2:01:42 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 15

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 328

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 46

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	9/22/2017 2:01:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 2:01:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/22/2017 2:01:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39114)(?)])(1 )(2 )]

"
Information	9/22/2017 2:01:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39114)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 2:01:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2017 2:01:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 2:01:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 12:56:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4a3a7822-9f67-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 12:40:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 12:40:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:55Z. Reason: GVLK.
Information	9/22/2017 12:35:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2017 12:35:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 12:35:54 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 12:35:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 12:26:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8661.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/22/2017 12:02:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 12:01:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 10:48:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 10:43:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/22/2017 10:43:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39311)(?)])(1 )(2 )]

"
Information	9/22/2017 10:43:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39311)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 10:43:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2017 10:43:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 10:43:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 10:23:39 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/22/2017 10:23:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/22/2017 10:23:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/22/2017 10:20:34 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/22/2017 9:31:38 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/22/2017 9:31:36 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/22/2017 9:31:07 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 12, Compared: 13060, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/22/2017 9:30:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/22/2017 8:01:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 8:01:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 7:56:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5f9c46ca-9f3d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/22/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39618)(?)])(1 )(2 )]

"
Information	9/22/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39618)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 4:07:56 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 4:02:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/22/2017 4:02:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 4:02:55 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 4:01:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 4:00:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 3:50:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 3:50:37 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:37Z. Reason: GVLK.
Information	9/22/2017 3:45:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2017 3:45:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 3:45:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 3:45:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 3:45:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57680ab9-9f1a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 3:45:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57680ab8-9f1a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 3:45:15 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 57680ab7-9f1a-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/22/2017 3:42:06 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/22/2017 3:33:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/22/2017 3:33:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:48Z. Reason: GVLK.
Error	9/22/2017 3:29:21 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/22/2017 3:28:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/22/2017 3:28:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/22/2017 3:28:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/22/2017 3:28:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/22/2017 2:55:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7525a79d-9f13-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/22/2017 12:23:56 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/22/2017 12:01:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/22/2017 12:00:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 9:55:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8ae7ae8a-9ee9-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 9:30:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 9:30:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:45Z. Reason: GVLK.
Information	9/21/2017 9:25:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2017 9:25:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 9:25:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 9:25:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 8:01:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 8:00:59 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/21/2017 8:00:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 5:07:40 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/21/2017 4:55:54 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0eb1f5f-9ebf-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 4:05:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 4:00:23 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 250

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 140

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 63

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 156

Information	9/21/2017 4:00:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 4:00:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2017 4:00:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40435)(?)])(1 )(2 )]

"
Information	9/21/2017 4:00:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40435)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 4:00:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2017 4:00:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 3:59:59 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	9/21/2017 3:57:25 PM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 10772 did not respond and is being forcibly terminated {filter host process 13844}. 

Error	9/21/2017 3:50:32 PM	Application Error	1005	(100)	"Windows cannot access the file  for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Microsoft Outlook because of this error.

Program: Microsoft Outlook
File: 

The error value is listed in the Additional Data section.
User Action
1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again.
2. If the file still cannot be accessed and
	- It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted.
	- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance.

Additional Data
Error value: 00640069
Disk type: 0"
Error	9/21/2017 3:50:32 PM	Application Error	1000	(100)	"Faulting application name: OUTLOOK.EXE, version: 16.0.7766.2099, time stamp: 0x5974fbea
Faulting module name: OUTLOOK.EXE, version: 16.0.7766.2099, time stamp: 0x5974fbea
Exception code: 0xc000001d
Fault offset: 0x004c0069
Faulting process id: 0xd98
Faulting application start time: 0x01d3310347603584
Faulting application path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
Faulting module path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
Report Id: 7f7a1cdf-9eb6-11e7-b5fc-0205857feb80"
Information	9/21/2017 2:27:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 2:27:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 1:37:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 1:37:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:03:40Z. Reason: GVLK.
Information	9/21/2017 1:32:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2017 1:32:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 1:32:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 1:32:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 12:30:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8660.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/21/2017 12:29:46 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/21/2017 12:29:46 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/21/2017 11:55:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6b6b192-9e95-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 11:38:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 11:38:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-28T06:02:44Z. Reason: GVLK.
Information	9/21/2017 11:33:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 11:33:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 11:33:43 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/09/21 06:03"
Information	9/21/2017 11:33:42 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/09/21 06:03, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/21/2017 11:28:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2017 11:28:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 11:28:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 11:28:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 10:42:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 10:36:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2017 10:36:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40758)(?)])(1 )(2 )]

"
Information	9/21/2017 10:36:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 40758)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 10:36:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2017 10:36:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 10:36:56 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 10:30:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/21/2017 10:27:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 10:27:26 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/21/2017 10:26:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 10:22:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/21/2017 10:00:29 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/21/2017 6:54:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9495ff6-9e6b-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 6:26:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/21/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41058)(?)])(1 )(2 )]

"
Information	9/21/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41058)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/21/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 5:17:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 5:17:39 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:39Z. Reason: GVLK.
Information	9/21/2017 5:12:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2017 5:12:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 5:12:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 5:12:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 5:12:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5aba2bc8-9e5d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 5:12:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5aba2bc7-9e5d-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 5:12:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5aba2bc6-9e5d-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/21/2017 5:08:20 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/21/2017 5:00:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/21/2017 5:00:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:32Z. Reason: GVLK.
Error	9/21/2017 4:55:58 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/21/2017 4:55:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/21/2017 4:55:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/21/2017 4:55:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/21/2017 4:55:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/21/2017 3:47:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/21/2017 3:47:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/21/2017 2:40:01 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/21/2017 2:39:29 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/21/2017 2:26:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/21/2017 1:54:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: be25a1b9-9e41-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/21/2017 12:36:16 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/21/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/20/2017 10:26:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 9:25:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 9:25:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:45Z. Reason: GVLK.
Information	9/20/2017 9:20:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 9:20:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 9:20:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 9:20:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 8:54:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d356ccd2-9e17-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 6:26:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 5:38:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎20T12:08:06.743870300Z.
Information	9/20/2017 5:38:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎20T12:08:06.743870300Z.
Information	9/20/2017 5:38:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎20T12:08:05.265870300Z.
Information	9/20/2017 5:38:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎20T12:08:05.265870300Z.
Information	9/20/2017 5:29:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2017 5:29:02 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2017 3:54:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 3:54:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:59Z. Reason: GVLK.
Information	9/20/2017 3:54:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e8fa528f-9ded-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 3:49:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 3:49:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 3:49:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 3:49:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 2:25:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 12:25:30 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8659.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/20/2017 11:30:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/20/2017 11:21:33 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/20/2017 11:00:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 11:00:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:33Z. Reason: GVLK.
Information	9/20/2017 10:55:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 10:55:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 10:55:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 10:55:32 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 10:54:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ff9cbcd9-9dc3-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 10:48:45 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/20/2017 10:25:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 7:12:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 7:12:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:27Z. Reason: GVLK.
Information	9/20/2017 7:07:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 7:07:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 7:07:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 7:07:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 7:04:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 7:04:52 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:52Z. Reason: GVLK.
Information	9/20/2017 7:02:12 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/20/2017 6:59:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 6:59:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 6:59:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 6:59:51 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 6:25:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 5:54:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1529b858-9d9a-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/20/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42498)(?)])(1 )(2 )]

"
Information	9/20/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42498)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/20/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 5:20:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2017 5:19:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2017 4:04:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/20/2017 4:04:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/20/2017 4:02:30 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 4:02:30 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:30Z. Reason: GVLK.
Information	9/20/2017 3:57:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 3:57:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 3:57:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 3:57:29 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 3:57:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a71e4725-9d89-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 3:57:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a71e4724-9d89-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 3:57:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a71e4723-9d89-11e7-b5fc-0205857feb80
Report Status: 0"
Error	9/20/2017 3:53:40 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/20/2017 3:44:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/20/2017 3:44:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:57Z. Reason: GVLK.
Error	9/20/2017 3:40:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/20/2017 3:39:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/20/2017 3:39:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/20/2017 3:39:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/20/2017 3:39:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/20/2017 2:45:06 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/20/2017 2:44:23 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/20/2017 2:25:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/20/2017 12:54:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2a63ac85-9d70-11e7-b5fc-0205857feb80
Report Status: 0"
Information	9/20/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/19/2017 10:25:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2017 7:54:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 40860d5e-9d46-11e7-b5fc-204747d02364
Report Status: 0"
Information	9/19/2017 6:24:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2017 5:59:40 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/19/2017 2:54:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 568346d8-9d1c-11e7-b5fc-204747d02364
Report Status: 0"
Information	9/19/2017 2:24:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2017 1:25:00 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/19/2017 11:11:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 11:06:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/19/2017 11:06:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 11:06:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 10:41:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 10:36:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/19/2017 10:36:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 10:36:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 10:29:42 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8658.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/19/2017 10:29:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 10:25:23 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/19/2017 10:25:08 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 31, Deleted: 0, Modified: 0, Compared: 12904, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/19/2017 10:24:15 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 62

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 93

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 265

Information	9/19/2017 10:24:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/19/2017 10:24:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	9/19/2017 10:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/19/2017 10:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43651)(?)])(1 )(2 )]

"
Information	9/19/2017 10:23:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43651)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2017 10:23:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/19/2017 10:23:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 10:23:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 10:23:50 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	9/19/2017 10:11:32 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 10:07:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 10:07:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:57Z. Reason: GVLK.
Information	9/19/2017 10:06:32 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/19/2017 10:06:32 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 10:06:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 10:06:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 10:01:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/19/2017 10:01:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43674)(?)])(1 )(2 )]

"
Information	9/19/2017 10:01:04 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43674)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2017 10:01:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/19/2017 10:01:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 10:01:04 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 10:00:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2017 10:00:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2017 10:00:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 10:00:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 9:59:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 9:59:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:19Z. Reason: GVLK.
Information	9/19/2017 9:54:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a1ad16e-9cf2-11e7-b5fc-204747d02364
Report Status: 0"
Information	9/19/2017 9:53:33 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/19/2017 9:52:30 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/19/2017 9:52:30 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/19/2017 9:52:29 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/19/2017 9:52:28 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/19/2017 9:52:13 AM	ESENT	302	Logging/Recovery	Windows (6468) Windows: The database engine has successfully completed recovery steps.
Information	9/19/2017 9:52:11 AM	ESENT	301	Logging/Recovery	Windows (6468) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/19/2017 9:52:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2017 9:52:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2017 9:52:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 9:52:02 AM	ESENT	301	Logging/Recovery	Windows (6468) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0545C.log.
Information	9/19/2017 9:52:02 AM	ESENT	300	Logging/Recovery	Windows (6468) Windows: The database engine is initiating recovery steps.
Information	9/19/2017 9:52:02 AM	ESENT	102	General	Windows (6468) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/19/2017 9:52:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 9:51:57 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8657.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/19/2017 9:51:31 AM	Service1	0	None	Service started successfully.
Error	9/19/2017 9:51:18 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/19/2017 9:51:18 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/19/2017 9:51:16 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/19/2017 9:51:16 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/19/2017 9:51:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/19/2017 9:51:15 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/19/2017 9:51:15 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/19/2017 9:51:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/19/2017 9:51:15 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/19/2017 9:51:11 AM	PostgreSQL	0	None	"2017-09-19 09:51:11 IST LOG:  redirecting log output to logging collector process
2017-09-19 09:51:11 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/19/2017 9:51:11 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/19/2017 9:51:10 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/19/2017 9:51:10 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:07 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/19/2017 9:51:06 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/19/2017 9:51:06 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/19/2017 9:51:06 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3552 at 9/18/2017 7:04:57 PM (local) 9/18/2017 1:34:57 PM (UTC). This is an informational message only; no user action is required.
Information	9/19/2017 9:51:05 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/19/2017 9:51:04 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/19/2017 9:51:04 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/19/2017 9:51:04 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/19/2017 9:51:04 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/19/2017 9:51:04 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3552.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/19/2017 9:51:03 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/19/2017 9:50:55 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/19/2017 9:50:51 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/19/2017 9:50:42 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/19/2017 9:50:42 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/19/2017 9:50:39 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/19/2017 3:12:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/19/2017 3:12:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:27Z. Reason: GVLK.
Error	9/19/2017 3:07:39 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/19/2017 3:07:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/19/2017 3:07:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/19/2017 3:07:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/19/2017 3:07:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/19/2017 12:22:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 847d86b9-9ca2-11e7-b130-0205857feb80
Report Status: 0"
Information	9/19/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/18/2017 11:56:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 11:56:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/18/2017 11:55:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 10:10:31 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 10:10:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:30Z. Reason: GVLK.
Information	9/18/2017 10:05:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 10:05:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 10:05:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 10:05:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 9:31:52 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/18/2017 8:37:36 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/18/2017 8:26:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 8:21:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 8:21:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 8:21:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 8:00:07 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 7:55:08 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	9/18/2017 7:55:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 7:54:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2017 7:54:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44520)(?)])(1 )(2 )]

"
Information	9/18/2017 7:54:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44520)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 7:51:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 7:51:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 7:51:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 7:30:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b94b3a83-9c79-11e7-b130-204747d02364
Report Status: 0"
Information	9/18/2017 7:26:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 7:22:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9a7de2bd-9c78-11e7-b130-204747d02364
Report Status: 0"
Information	9/18/2017 7:21:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 7:21:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 7:21:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 7:14:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 7:14:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:05Z. Reason: GVLK.
Information	9/18/2017 7:08:18 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/18/2017 7:06:57 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 7:06:55 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 7:06:54 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 7:06:52 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/18/2017 7:06:47 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 7:06:47 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 7:06:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 7:06:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 7:06:20 PM	ESENT	302	Logging/Recovery	Windows (7384) Windows: The database engine has successfully completed recovery steps.
Information	9/18/2017 7:06:20 PM	ESENT	301	Logging/Recovery	Windows (7384) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/18/2017 7:06:18 PM	ESENT	301	Logging/Recovery	Windows (7384) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0545A.log.
Information	9/18/2017 7:06:18 PM	ESENT	300	Logging/Recovery	Windows (7384) Windows: The database engine is initiating recovery steps.
Information	9/18/2017 7:06:17 PM	ESENT	102	General	Windows (7384) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/18/2017 7:06:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8657.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/18/2017 7:05:37 PM	Service1	0	None	Service started successfully.
Error	9/18/2017 7:05:34 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/18/2017 7:05:28 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/18/2017 7:05:14 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/18/2017 7:05:11 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/18/2017 7:05:10 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/18/2017 7:05:09 PM	PostgreSQL	0	None	"2017-09-18 19:05:09 IST LOG:  redirecting log output to logging collector process
2017-09-18 19:05:09 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/18/2017 7:05:08 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/18/2017 7:05:07 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/18/2017 7:05:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/18/2017 7:05:06 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/18/2017 7:05:06 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/18/2017 7:05:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/18/2017 7:05:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/18/2017 7:05:00 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/18/2017 7:04:59 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/18/2017 7:04:58 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/18/2017 7:04:58 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/18/2017 7:04:58 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3616 at 9/18/2017 9:09:05 AM (local) 9/18/2017 3:39:05 AM (UTC). This is an informational message only; no user action is required.
Information	9/18/2017 7:04:57 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/18/2017 7:04:54 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/18/2017 7:04:54 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/18/2017 7:04:54 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/18/2017 7:04:54 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/18/2017 7:04:54 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3552.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/18/2017 7:04:53 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/18/2017 7:04:43 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/18/2017 7:04:36 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 7:04:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/18/2017 7:04:26 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/18/2017 7:04:15 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/18/2017 6:35:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2017 6:29:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/18/2017 5:14:40 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2017 5:02:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/18/2017 2:57:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/18/2017 2:33:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 2:28:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 2:28:21 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 0

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 15

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 15

Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44847)(?)])(1 )(2 )]

"
Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44847)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 2:28:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 2:22:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b0476b91-9c4e-11e7-baba-204747d02364
Report Status: 0"
Information	9/18/2017 2:20:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 2:15:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 2:15:25 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 15

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 32

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 46

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	9/18/2017 2:15:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2017 2:15:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44860)(?)])(1 )(2 )]

"
Information	9/18/2017 2:15:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44860)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 2:15:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 2:15:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 2:15:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 11:30:57 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 12824, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/18/2017 11:30:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/18/2017 11:30:04 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/18/2017 11:30:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/18/2017 10:31:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/18/2017 10:31:19 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/18/2017 10:29:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 10:24:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 10:24:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 10:24:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 10:11:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 10:06:04 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/18/2017 10:06:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/18/2017 10:06:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/18/2017 10:06:01 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 2449

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 281

Information	9/18/2017 10:05:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 10:05:52 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/18/2017 10:05:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/18/2017 10:05:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2017 10:05:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45109)(?)])(1 )(2 )]

"
Information	9/18/2017 10:05:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45109)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 10:05:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 10:05:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 10:05:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	9/18/2017 10:05:28 AM	Microsoft Office 16	2001	None	Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Information	9/18/2017 9:59:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 9:54:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8657.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/18/2017 9:54:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 9:54:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 9:54:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 9:29:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 9:25:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 9:25:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:06Z. Reason: GVLK.
Information	9/18/2017 9:22:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c4865087-9c24-11e7-baba-204747d02364
Report Status: 0"
Information	9/18/2017 9:20:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 9:20:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 9:20:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 9:20:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 9:19:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/18/2017 9:19:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45155)(?)])(1 )(2 )]

"
Information	9/18/2017 9:19:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45155)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 9:19:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/18/2017 9:19:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 9:19:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 9:17:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 9:17:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:11Z. Reason: GVLK.
Information	9/18/2017 9:11:24 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/18/2017 9:10:33 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 9:10:33 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 9:10:33 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 9:10:32 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/18/2017 9:10:02 AM	ESENT	302	Logging/Recovery	Windows (8532) Windows: The database engine has successfully completed recovery steps.
Information	9/18/2017 9:09:55 AM	ESENT	301	Logging/Recovery	Windows (8532) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/18/2017 9:09:55 AM	ESENT	300	Logging/Recovery	Windows (8532) Windows: The database engine is initiating recovery steps.
Information	9/18/2017 9:09:54 AM	ESENT	102	General	Windows (8532) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/18/2017 9:09:48 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8656.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/18/2017 9:09:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 9:09:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 9:09:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 9:09:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 9:09:19 AM	Service1	0	None	Service started successfully.
Error	9/18/2017 9:09:11 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/18/2017 9:09:11 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:11 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/18/2017 9:09:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/18/2017 9:09:11 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/18/2017 9:09:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/18/2017 9:09:10 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/18/2017 9:09:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/18/2017 9:09:09 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:09 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/18/2017 9:09:09 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/18/2017 9:09:08 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/18/2017 9:09:08 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/18/2017 9:09:08 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/18/2017 9:09:08 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/18/2017 9:09:05 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3464 at 9/18/2017 5:19:51 AM (local) 9/17/2017 11:49:51 PM (UTC). This is an informational message only; no user action is required.
Information	9/18/2017 9:09:04 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/18/2017 9:09:02 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/18/2017 9:09:02 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/18/2017 9:09:02 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/18/2017 9:09:02 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/18/2017 9:09:02 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/18/2017 9:09:01 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/18/2017 9:09:00 AM	PostgreSQL	0	None	"2017-09-18 09:09:00 IST LOG:  redirecting log output to logging collector process
2017-09-18 09:09:00 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/18/2017 9:09:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/18/2017 9:09:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/18/2017 9:09:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/18/2017 9:08:58 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/18/2017 9:08:58 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/18/2017 9:08:56 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3616.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/18/2017 9:08:46 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/18/2017 9:08:25 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/18/2017 9:08:06 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 9:07:50 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/18/2017 9:07:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/18/2017 9:07:50 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/18/2017 5:19:57 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/18/2017 5:19:51 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	9/18/2017 5:19:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/18/2017 5:19:34 AM	ESENT	302	Logging/Recovery	Windows (5632) Windows: The database engine has successfully completed recovery steps.
Information	9/18/2017 5:19:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 5:19:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 5:19:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 5:19:31 AM	ESENT	301	Logging/Recovery	Windows (5632) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/18/2017 5:19:31 AM	ESENT	300	Logging/Recovery	Windows (5632) Windows: The database engine is initiating recovery steps.
Information	9/18/2017 5:19:30 AM	ESENT	102	General	Windows (5632) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/18/2017 5:19:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Warning	9/18/2017 5:19:20 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 932 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
"
Information	9/18/2017 5:19:19 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/18/2017 5:19:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/18/2017 5:19:19 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/18/2017 5:19:19 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/18/2017 5:19:16 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8656.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/18/2017 5:18:21 AM	Service1	0	None	Service started successfully.
Information	9/18/2017 5:18:19 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/18/2017 5:18:15 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:15 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/18/2017 5:18:15 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/18/2017 5:18:15 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/18/2017 5:18:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Error	9/18/2017 5:18:14 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/18/2017 5:18:14 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/18/2017 5:18:14 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/18/2017 5:18:14 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:14 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/18/2017 5:18:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/18/2017 5:18:12 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:12 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/18/2017 5:18:11 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/18/2017 5:18:11 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/18/2017 5:18:11 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/18/2017 5:18:10 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/18/2017 5:18:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/18/2017 5:18:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/18/2017 5:18:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/18/2017 5:18:07 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:07 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:07 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3672 at 9/16/2017 11:25:20 AM (local) 9/16/2017 5:55:20 AM (UTC). This is an informational message only; no user action is required.
Information	9/18/2017 5:18:05 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/18/2017 5:18:03 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/18/2017 5:18:03 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/18/2017 5:18:00 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/18/2017 5:18:00 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/18/2017 5:18:00 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/18/2017 5:18:00 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/18/2017 5:18:00 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/18/2017 5:17:55 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/18/2017 5:17:54 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/18/2017 5:17:52 AM	PostgreSQL	0	None	"2017-09-18 05:17:52 IST LOG:  redirecting log output to logging collector process
2017-09-18 05:17:52 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/18/2017 5:17:51 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3464.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/18/2017 5:17:47 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/18/2017 5:17:02 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/18/2017 5:17:00 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/18/2017 5:16:38 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/18/2017 5:16:38 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/18/2017 5:16:38 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/18/2017 4:56:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/18/2017 4:56:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:00Z. Reason: GVLK.
Error	9/18/2017 4:51:15 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/18/2017 4:51:00 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/18/2017 4:51:00 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/18/2017 4:51:00 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/18/2017 4:50:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/18/2017 2:32:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8d09a331-9beb-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/18/2017 2:31:16 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/18/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/17/2017 10:53:27 PM	RasClient	20225	None	CoId={A17A01C2-28B2-4418-81F5-4B13EFB911CC}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.255.220
TunnelIpv6Address = None
Dial-in User = .
Information	9/17/2017 10:53:24 PM	RasClient	20224	None	CoId={A17A01C2-28B2-4418-81F5-4B13EFB911CC}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/17/2017 10:53:24 PM	RasClient	20223	None	CoId={A17A01C2-28B2-4418-81F5-4B13EFB911CC}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:53:24 PM	RasClient	20222	None	CoId={A17A01C2-28B2-4418-81F5-4B13EFB911CC}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:53:24 PM	RasClient	20221	None	CoId={A17A01C2-28B2-4418-81F5-4B13EFB911CC}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/17/2017 10:51:26 PM	RasClient	20226	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	9/17/2017 9:32:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9fd795ee-9bc1-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 4:32:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b282cf62-9b97-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 2:51:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2017 2:51:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:17Z. Reason: GVLK.
Information	9/17/2017 2:46:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2017 2:46:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2017 2:46:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2017 2:46:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2017 12:18:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8656.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/17/2017 11:32:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c584ac5c-9b6d-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 11:08:13 AM	RasClient	20225	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.247.46
TunnelIpv6Address = None
Dial-in User = .
Information	9/17/2017 11:08:10 AM	RasClient	20224	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/17/2017 11:08:10 AM	RasClient	20223	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 11:08:10 AM	RasClient	20222	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 11:08:10 AM	RasClient	20221	None	CoId={B234335E-8817-4B52-AE1C-AE3763FC6D28}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Error	9/17/2017 10:53:19 AM	Application Error	1000	(100)	"Faulting application name: f5fpclientW.exe, version: 7132.2017.404.2206, time stamp: 0x58e41a77
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x20746e65
Faulting process id: 0x1c68
Faulting application start time: 0x01d32eb10bb818ed
Faulting application path: C:\Program Files (x86)\F5 VPN\f5fpclientW.exe
Faulting module path: unknown
Report Id: 50362439-9b68-11e7-b9d1-204747d02364"
Error	9/17/2017 10:53:16 AM	RasClient	20227	None	CoId={84996F54-5DD3-4DF3-93D9-0DD9972B4090}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 628.
Information	9/17/2017 10:52:39 AM	RasClient	20224	None	CoId={84996F54-5DD3-4DF3-93D9-0DD9972B4090}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/17/2017 10:52:39 AM	RasClient	20223	None	CoId={84996F54-5DD3-4DF3-93D9-0DD9972B4090}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:52:39 AM	RasClient	20222	None	CoId={84996F54-5DD3-4DF3-93D9-0DD9972B4090}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:52:39 AM	RasClient	20221	None	CoId={84996F54-5DD3-4DF3-93D9-0DD9972B4090}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/17/2017 10:52:34 AM	RasClient	20226	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 829.
Information	9/17/2017 10:23:19 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/17/2017 10:19:57 AM	RasClient	20225	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.253.6
TunnelIpv6Address = None
Dial-in User = .
Information	9/17/2017 10:19:54 AM	RasClient	20224	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/17/2017 10:19:54 AM	RasClient	20223	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:19:54 AM	RasClient	20222	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/17/2017 10:19:54 AM	RasClient	20221	None	CoId={6737CD73-CA2E-40A9-B824-6D16F522D830}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/17/2017 6:31:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ce52cf4d-9b43-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 6:02:03 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/17/2017 5:57:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/17/2017 5:57:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2017 5:57:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/17/2017 5:43:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/17/2017 5:38:07 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485946
"
Error	9/17/2017 5:38:07 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {4D5226C6-9BAA-4FBF-AC63-434272A28006}
Information	9/17/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/17/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46818)(?)])(1 )(2 )]

"
Information	9/17/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46818)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/17/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/17/2017 4:03:28 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2017 4:03:28 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:28Z. Reason: GVLK.
Information	9/17/2017 3:58:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2017 3:58:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2017 3:58:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2017 3:58:27 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2017 3:58:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c8ff4cf-9b2e-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 3:58:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c8ff4ce-9b2e-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 3:58:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c8ff4cd-9b2e-11e7-b9d1-204747d02364
Report Status: 0"
Error	9/17/2017 3:55:07 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/17/2017 3:48:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/17/2017 3:48:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:28Z. Reason: GVLK.
Error	9/17/2017 3:43:56 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/17/2017 3:43:28 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/17/2017 3:43:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/17/2017 3:43:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/17/2017 3:43:28 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/17/2017 1:31:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dde9246d-9b19-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/17/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/16/2017 11:30:56 PM	RasClient	20226	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	9/16/2017 8:30:23 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3909ed8-9aef-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/16/2017 6:35:01 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 6:35:01 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:01Z. Reason: GVLK.
Information	9/16/2017 6:30:01 PM	Windows Activation Technologies	18	None	"SLUI notification schedule modified. 
 Schedule type: 1"
Information	9/16/2017 6:30:01 PM	Windows Activation Technologies	15	None	"Genuine validation schedule created/changed. 
 Interval: 129600 minutes"
Information	9/16/2017 6:30:01 PM	Windows Activation Technologies	13	None	"Genuine validation result: 
 hrOffline = 0x00000000, hrOnline = 0x80072EE7"
Error	9/16/2017 6:30:01 PM	Microsoft-Windows-Security-SPP	8208	None	Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error	9/16/2017 6:30:01 PM	Microsoft-Windows-Security-SPP	8200	None	"License acquisition failure details. 
hr=0x80072EE7"
Information	9/16/2017 6:30:01 PM	Windows Activation Technologies	2	None	"Health check passed. 
"
Information	9/16/2017 6:29:59 PM	Windows Activation Technologies	1	None	"Health check initiated. 
"
Information	9/16/2017 6:29:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/16/2017 6:29:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2017 6:29:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 6:29:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 6:29:58 PM	Windows Activation Technologies	10	None	"Genuine validation initiated. 
"
Information	9/16/2017 3:30:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d6c3dcdb-9ac5-11e7-b9d1-204747d02364
Report Status: 0"
Information	9/16/2017 12:47:24 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8655.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/16/2017 12:46:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 12:41:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 12:41:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 12:41:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 12:34:17 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/16/2017 12:16:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 12:11:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 12:11:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 12:11:01 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 11:46:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 11:41:02 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 11:41:02 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 11:41:01 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 11:34:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 11:34:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:20Z. Reason: GVLK.
Information	9/16/2017 11:32:32 AM	RasClient	20225	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.255.87
TunnelIpv6Address = None
Dial-in User = .
Information	9/16/2017 11:32:29 AM	RasClient	20224	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/16/2017 11:32:29 AM	RasClient	20223	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/16/2017 11:32:29 AM	RasClient	20222	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/16/2017 11:32:29 AM	RasClient	20221	None	CoId={D79B82B8-E29B-4F82-8325-73CD647DB137}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/16/2017 11:28:35 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/16/2017 11:27:27 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8654.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/16/2017 11:27:19 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 11:27:18 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 11:27:17 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 11:27:17 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/16/2017 11:27:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/16/2017 11:27:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2017 11:27:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 11:27:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 11:26:39 AM	ESENT	302	Logging/Recovery	Windows (2924) Windows: The database engine has successfully completed recovery steps.
Information	9/16/2017 11:26:34 AM	ESENT	301	Logging/Recovery	Windows (2924) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/16/2017 11:26:34 AM	ESENT	300	Logging/Recovery	Windows (2924) Windows: The database engine is initiating recovery steps.
Information	9/16/2017 11:26:34 AM	ESENT	102	General	Windows (2924) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/16/2017 11:25:50 AM	Service1	0	None	Service started successfully.
Information	9/16/2017 11:25:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/16/2017 11:25:43 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/16/2017 11:25:43 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/16/2017 11:25:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/16/2017 11:25:43 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	9/16/2017 11:25:40 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/16/2017 11:25:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/16/2017 11:25:38 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/16/2017 11:25:38 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/16/2017 11:25:37 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/16/2017 11:25:33 AM	PostgreSQL	0	None	"2017-09-16 11:25:33 IST LOG:  redirecting log output to logging collector process
2017-09-16 11:25:33 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/16/2017 11:25:32 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/16/2017 11:25:31 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/16/2017 11:25:28 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/16/2017 11:25:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/16/2017 11:25:27 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/16/2017 11:25:26 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/16/2017 11:25:25 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/16/2017 11:25:24 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3648 at 9/16/2017 10:25:14 AM (local) 9/16/2017 4:55:14 AM (UTC). This is an informational message only; no user action is required.
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/16/2017 11:25:20 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/16/2017 11:25:19 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/16/2017 11:25:19 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/16/2017 11:25:19 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/16/2017 11:25:19 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3672.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/16/2017 11:25:18 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/16/2017 11:25:12 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/16/2017 11:25:08 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 11:24:50 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/16/2017 11:24:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/16/2017 11:24:50 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/16/2017 11:16:01 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 11:11:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 11:11:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 11:11:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 11:05:42 AM	RasClient	20225	None	CoId={829F6C44-2189-4E0A-A432-4F6884BC0D86}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.244.207
TunnelIpv6Address = None
Dial-in User = .
Information	9/16/2017 11:05:36 AM	RasClient	20224	None	CoId={829F6C44-2189-4E0A-A432-4F6884BC0D86}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/16/2017 11:05:36 AM	RasClient	20223	None	CoId={829F6C44-2189-4E0A-A432-4F6884BC0D86}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/16/2017 11:05:36 AM	RasClient	20222	None	CoId={829F6C44-2189-4E0A-A432-4F6884BC0D86}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/16/2017 11:05:36 AM	RasClient	20221	None	CoId={829F6C44-2189-4E0A-A432-4F6884BC0D86}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/16/2017 10:46:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 10:41:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 10:41:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 10:41:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 10:40:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/16/2017 10:35:22 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	9/16/2017 10:35:22 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {195478F6-6636-41F0-BA98-2F198915D7A7}
Error	9/16/2017 10:35:22 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {195478F6-6636-41F0-BA98-2F198915D7A7}
Information	9/16/2017 10:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/16/2017 10:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47960)(?)])(1 )(2 )]

"
Information	9/16/2017 10:35:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 47960)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2017 10:35:18 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/16/2017 10:35:18 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 10:35:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 10:35:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/16/2017 10:35:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:04Z. Reason: GVLK.
Information	9/16/2017 10:29:18 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/16/2017 10:28:08 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 10:28:07 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 10:28:06 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 10:28:05 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/16/2017 10:27:25 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/16/2017 10:27:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/16/2017 10:27:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/16/2017 10:27:21 AM	ESENT	302	Logging/Recovery	Windows (7200) Windows: The database engine has successfully completed recovery steps.
Information	9/16/2017 10:27:16 AM	ESENT	301	Logging/Recovery	Windows (7200) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/16/2017 10:27:16 AM	ESENT	300	Logging/Recovery	Windows (7200) Windows: The database engine is initiating recovery steps.
Information	9/16/2017 10:27:16 AM	ESENT	102	General	Windows (7200) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/16/2017 10:27:16 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/16/2017 10:27:14 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8654.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/16/2017 10:25:41 AM	Service1	0	None	Service started successfully.
Information	9/16/2017 10:25:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/16/2017 10:25:36 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/16/2017 10:25:36 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/16/2017 10:25:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/16/2017 10:25:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	9/16/2017 10:25:34 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/16/2017 10:25:27 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/16/2017 10:25:27 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/16/2017 10:25:26 AM	PostgreSQL	0	None	"2017-09-16 10:25:26 IST LOG:  redirecting log output to logging collector process
2017-09-16 10:25:26 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/16/2017 10:25:26 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/16/2017 10:25:24 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/16/2017 10:25:23 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/16/2017 10:25:19 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:19 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/16/2017 10:25:19 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/16/2017 10:25:19 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/16/2017 10:25:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/16/2017 10:25:18 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/16/2017 10:25:18 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/16/2017 10:25:18 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/16/2017 10:25:18 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:17 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/16/2017 10:25:16 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/16/2017 10:25:16 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/16/2017 10:25:16 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3620 at 9/15/2017 11:47:53 PM (local) 9/15/2017 6:17:53 PM (UTC). This is an informational message only; no user action is required.
Information	9/16/2017 10:25:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/16/2017 10:25:12 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/16/2017 10:25:12 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/16/2017 10:25:12 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/16/2017 10:25:12 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/16/2017 10:25:12 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3648.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/16/2017 10:25:11 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/16/2017 10:24:39 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/16/2017 10:24:30 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/16/2017 10:24:12 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/16/2017 10:24:11 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/16/2017 10:24:11 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/15/2017 11:48:48 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/15/2017 11:47:56 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	9/15/2017 11:47:53 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	9/15/2017 11:47:44 PM	McLogEvent	257	None	The scan of C:\Windows\System32\wuaueng.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8654.0000.
Warning	9/15/2017 11:47:32 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 916 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 916 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 916 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 916 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 916 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1412 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/15/2017 11:47:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/15/2017 11:47:30 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/15/2017 11:47:30 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/15/2017 11:47:20 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/15/2017 9:48:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 9:48:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:07Z. Reason: GVLK.
Information	9/15/2017 9:43:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/15/2017 9:43:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 9:43:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 9:43:03 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 8:24:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd5b4cee-9a25-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 6:42:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/15/2017 3:55:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 3:50:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 3:50:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49085)(?)])(1 )(2 )]

"
Information	9/15/2017 3:50:24 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49085)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 3:50:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 3:50:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 3:50:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 3:24:37 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1cfbd30-99fb-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 2:47:56 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 2:42:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 2:42:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49152)(?)])(1 )(2 )]

"
Information	9/15/2017 2:42:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49152)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 2:42:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 2:42:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 2:42:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 2:42:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/15/2017 2:32:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/15/2017 2:32:25 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/15/2017 2:23:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 2:18:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 2:18:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49176)(?)])(1 )(2 )]

"
Information	9/15/2017 2:18:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49176)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 2:18:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 2:18:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 2:18:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 12:59:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 12:54:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 12:54:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49260)(?)])(1 )(2 )]

"
Information	9/15/2017 12:54:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49260)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 12:54:39 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 12:54:39 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 12:54:39 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 11:42:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/15/2017 11:42:10 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 11:41:49 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 47, Deleted: 0, Modified: 16, Compared: 12707, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/15/2017 11:40:53 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/15/2017 11:40:53 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/15/2017 11:37:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 11:37:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 11:37:09 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 11:14:16 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8654.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/15/2017 11:12:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 11:07:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 11:07:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 11:07:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 10:58:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 10:58:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:14Z. Reason: GVLK.
Information	9/15/2017 10:53:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/15/2017 10:53:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 10:53:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 10:53:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 10:52:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dc4c7920-99d5-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 10:52:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dc4c791f-99d5-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 10:52:27 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dc4c791e-99d5-11e7-88a4-204747d02364
Report Status: 0"
Error	9/15/2017 10:48:58 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/15/2017 10:47:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 10:42:25 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 250

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 515

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 93

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 562

Information	9/15/2017 10:42:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/15/2017 10:41:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 10:41:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49393)(?)])(1 )(2 )]

"
Information	9/15/2017 10:41:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49393)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	9/15/2017 10:41:34 AM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	9/15/2017 10:41:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 10:41:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49393)(?)])(1 )(2 )]

"
Information	9/15/2017 10:41:32 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49393)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 10:34:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/15/2017 10:34:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49401)(?)])(1 )(2 )]

"
Information	9/15/2017 10:34:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49401)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 10:34:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/15/2017 10:34:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 10:34:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 10:34:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:02Z. Reason: GVLK.
Information	9/15/2017 10:34:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 10:29:02 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/15/2017 10:29:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 10:29:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 10:29:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 10:28:24 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/15/2017 10:28:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:11Z. Reason: GVLK.
Information	9/15/2017 10:25:40 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/15/2017 10:25:29 AM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/15/2017 10:25:26 AM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Error	9/15/2017 10:23:07 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/15/2017 10:23:04 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\MICROSOFT VS CODE\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8653.0000.
Information	9/15/2017 10:22:22 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/15/2017 10:22:18 AM	McLogEvent	257	None	The scan of D:\installs\SetUpFile_2017_07_06_Th_19_52_55_4\DISK1\ISSetupPrerequisites\{39B44035-64F8-485C-902E-7A79A185BE70}\postgresql-9.5.3-1-windows-x64.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8653.0000.
Information	9/15/2017 10:21:51 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/15/2017 10:21:51 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/15/2017 10:21:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/15/2017 10:21:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/15/2017 10:21:31 AM	ESENT	302	Logging/Recovery	Windows (5088) Windows: The database engine has successfully completed recovery steps.
Information	9/15/2017 10:21:30 AM	ESENT	301	Logging/Recovery	Windows (5088) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/15/2017 10:21:28 AM	ESENT	301	Logging/Recovery	Windows (5088) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03DE6.log.
Information	9/15/2017 10:21:28 AM	ESENT	300	Logging/Recovery	Windows (5088) Windows: The database engine is initiating recovery steps.
Information	9/15/2017 10:21:27 AM	ESENT	102	General	Windows (5088) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Warning	9/15/2017 10:21:25 AM	Microsoft-Windows-Winlogon	6006	None	The winlogon notification subscriber <TrustedInstaller> took 124 second(s) to handle the notification event (CreateSession).
Information	9/15/2017 10:21:24 AM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8653.0000.
Information	9/15/2017 10:21:22 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/15/2017 10:21:11 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/15/2017 10:21:08 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/15/2017 10:21:05 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Warning	9/15/2017 10:20:21 AM	Microsoft-Windows-Winlogon	6005	None	The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Information	9/15/2017 10:19:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/15/2017 10:19:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/15/2017 10:19:19 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	9/15/2017 10:19:18 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	9/15/2017 10:19:18 AM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	9/15/2017 10:19:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/15/2017 10:19:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/15/2017 10:19:00 AM	Service1	0	None	Service started successfully.
Information	9/15/2017 10:19:00 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8653.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/15/2017 10:18:59 AM	PostgreSQL	0	None	Server started and accepting connections

Error	9/15/2017 10:18:50 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/15/2017 10:18:50 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/15/2017 10:18:50 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:49 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/15/2017 10:18:49 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/15/2017 10:18:49 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/15/2017 10:18:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/15/2017 10:18:48 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/15/2017 10:18:47 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:47 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/15/2017 10:18:46 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/15/2017 10:18:45 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/15/2017 10:18:45 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/15/2017 10:18:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/15/2017 10:18:45 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:44 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/15/2017 10:18:43 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/15/2017 10:18:42 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/15/2017 10:18:42 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/15/2017 10:18:42 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/15/2017 10:18:39 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:39 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3564 at 9/7/2017 10:52:22 AM (local) 9/7/2017 5:22:22 AM (UTC). This is an informational message only; no user action is required.
Information	9/15/2017 10:18:38 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/15/2017 10:18:31 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/15/2017 10:18:31 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/15/2017 10:18:31 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/15/2017 10:18:31 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/15/2017 10:18:31 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/15/2017 10:18:23 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/15/2017 10:18:22 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/15/2017 10:18:21 AM	PostgreSQL	0	None	"2017-09-15 10:18:21 IST LOG:  redirecting log output to logging collector process
2017-09-15 10:18:21 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/15/2017 10:18:17 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3620.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/15/2017 10:18:01 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	9/15/2017 10:16:11 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/15/2017 10:16:00 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: Wlansvc
P2: wlansvc.dll
P3: 6.1.7600.16385
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c4093170-99d0-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 10:15:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: odClientService
P2: odClientService.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c409316f-99d0-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 10:15:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: dot3svc
P2: dot3svc.dll
P3: 6.1.7601.17514
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b9afd5de-99d0-11e7-88a4-204747d02364
Report Status: 0"
Information	9/15/2017 10:14:06 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/15/2017 10:14:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/15/2017 10:14:06 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/14/2017 9:22:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/14/2017 7:34:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a01469da-9955-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 5:22:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/14/2017 3:45:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 3:40:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 3:40:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]

"
Information	9/14/2017 3:40:08 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 3:40:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 3:40:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]

"
Information	9/14/2017 3:40:03 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 3:39:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 3:39:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]

"
Information	9/14/2017 3:39:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50535)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 3:39:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 3:39:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50536)(?)])(1 )(2 )]

"
Information	9/14/2017 3:39:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50536)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 3:39:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/14/2017 3:39:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 3:39:13 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 3:38:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 3:34:36 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:36.278929600Z.
Information	9/14/2017 3:34:36 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:36.278929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:29.883929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:29.883929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:29.670929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:29.670929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:29.381929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:29.381929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:29.226929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:29.226929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:29.086929600Z.
Information	9/14/2017 3:34:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:29.086929600Z.
Information	9/14/2017 3:34:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:28.932929600Z.
Information	9/14/2017 3:34:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:28.932929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:27.890929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:27.890929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:27.728929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:27.728929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:27.561929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:27.561929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:27.415929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:27.415929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:27.228929600Z.
Information	9/14/2017 3:34:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:27.228929600Z.
Information	9/14/2017 3:34:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:26.220929600Z.
Information	9/14/2017 3:34:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:26.220929600Z.
Information	9/14/2017 3:34:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:26.093929600Z.
Information	9/14/2017 3:34:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:26.093929600Z.
Information	9/14/2017 3:34:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:25.965929600Z.
Information	9/14/2017 3:34:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:25.965929600Z.
Information	9/14/2017 3:34:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:25.842929600Z.
Information	9/14/2017 3:34:25 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:25.842929600Z.
Information	9/14/2017 3:34:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:15.842929600Z.
Information	9/14/2017 3:34:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:15.842929600Z.
Information	9/14/2017 3:34:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:13.042929600Z.
Information	9/14/2017 3:34:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:13.042929600Z.
Information	9/14/2017 3:34:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:04:12.201929600Z.
Information	9/14/2017 3:34:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:04:12.201929600Z.
Information	9/14/2017 3:33:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:51.465929600Z.
Information	9/14/2017 3:33:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:51.465929600Z.
Information	9/14/2017 3:33:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:51.072929600Z.
Information	9/14/2017 3:33:51 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:51.072929600Z.
Information	9/14/2017 3:33:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:50.756929600Z.
Information	9/14/2017 3:33:50 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:50.756929600Z.
Information	9/14/2017 3:33:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:48.902929600Z.
Information	9/14/2017 3:33:48 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:48.902929600Z.
Information	9/14/2017 3:33:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:27.513929600Z.
Information	9/14/2017 3:33:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:27.513929600Z.
Information	9/14/2017 3:33:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:27.048929600Z.
Information	9/14/2017 3:33:27 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:27.048929600Z.
Information	9/14/2017 3:33:26 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:26.481929600Z.
Information	9/14/2017 3:33:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:26.481929600Z.
Information	9/14/2017 3:33:22 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎14T10:03:22.085929600Z.
Information	9/14/2017 3:33:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎14T10:03:22.085929600Z.
Information	9/14/2017 3:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 3:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50542)(?)])(1 )(2 )]

"
Information	9/14/2017 3:33:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50542)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 3:33:14 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/14/2017 3:33:14 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 3:33:14 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 2:33:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 923e435f-992b-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 2:27:18 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 2:27:18 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:59:18Z. Reason: GVLK.
Information	9/14/2017 2:22:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 2:22:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 2:22:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 2:22:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 2:14:53 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/14/2017 2:09:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎14T08:39:18.763938100Z.
Information	9/14/2017 2:09:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 16588.
Information	9/14/2017 2:09:33 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/14/2017 2:09:33 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6 -- Configuration completed successfully.
Information	9/14/2017 2:09:33 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4040957. Installation success or error status: 0.
Information	9/14/2017 2:09:33 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6 - Update 'KB4040957' installed successfully.
Information	9/14/2017 2:09:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎14T08:39:18.763938100Z.
Information	9/14/2017 2:09:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 16588.
Information	9/14/2017 2:02:57 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/14/2017 1:58:49 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎09‎-‎14T08:25:52.122462400Z.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 10000.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1029	None	Product: Microsoft .NET Framework 4.6. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	9/14/2017 1:58:49 PM	MsiInstaller	11728	None	Product: Microsoft .NET Framework 4.6 -- Configuration completed successfully.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft .NET Framework 4.6. Product Version: 4.6.00081. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB4040973. Installation success or error status: 0.
Information	9/14/2017 1:58:49 PM	MsiInstaller	1022	None	Product: Microsoft .NET Framework 4.6 - Update 'KB4040973' installed successfully.
Information	9/14/2017 1:58:46 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 1:58:46 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:45Z. Reason: GVLK.
Information	9/14/2017 1:57:46 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:46 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:46 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:46 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET CLR Networking 4.0.0.0 (.NET CLR Networking 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:45 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:45 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:45 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:45 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:45 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:44 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:37 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00001.log
Information	9/14/2017 1:57:35 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/14/2017 1:57:31 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/14/2017 1:57:30 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:25 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	9/14/2017 1:57:24 PM	ASP.NET 4.0.30319.0	1019	Setup	Finish registering ASP.NET (version 4.0.30319.0). Detailed registration logs can be found in C:\Windows\TEMP\ASPNETSetup_00000.log
Information	9/14/2017 1:57:21 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the ASP.NET (ASP.NET) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/14/2017 1:57:19 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the ASP.NET (ASP.NET) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/14/2017 1:57:19 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the ASP.NET_4.0.30319 (ASP.NET_4.0.30319) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:57:07 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	9/14/2017 1:57:07 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the aspnet_state (ASP.NET State Service) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	9/14/2017 1:57:00 PM	ASP.NET 4.0.30319.0	1017	Setup	Start registering ASP.NET (version 4.0.30319.0) (internal flag: 0x00000404)
Information	9/14/2017 1:56:54 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:56:54 PM	Microsoft-Windows-LoadPerf	1002	None	Performance counters for the .NET Memory Cache 4.0 (.NET Memory Cache 4.0) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Information	9/14/2017 1:56:41 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:41 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WMINet_Utils.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:40 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\SysWOW64\msvcr120_clr0400.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\SysWOW64\msvcr120_clr0400.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\SysWOW64\msvcr120_clr0400.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\SysWOW64\msvcr120_clr0400.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\SysWOW64\msvcr120_clr0400.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\system32\msvcr120_clr0400.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\system32\msvcr120_clr0400.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\system32\msvcr120_clr0400.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\system32\msvcr120_clr0400.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:39 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\system32\msvcr120_clr0400.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 14968.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: SearchFilterHost , Id 14968.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: VisualJArchitect , Id 6920.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: chrome , Id 14916.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: RAVBg64 , Id 5208.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: explorer , Id 4688.
Information	9/14/2017 1:56:38 PM	MsiInstaller	1025	None	Product: Microsoft .NET Framework 4.6. The file C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll is being used by the following process: Name: NetworkAdapterManager , Id 3644.
Information	9/14/2017 1:55:52 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎09‎-‎14T08:25:52.122462400Z.
Information	9/14/2017 1:55:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\Installer\67bf70.msi. Client Process Id: 10000.
Information	9/14/2017 1:53:44 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 1:53:44 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 1:53:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 1:53:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 1:22:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/14/2017 12:06:14 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/14/2017 12:05:45 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/14/2017 12:05:24 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/14/2017 11:34:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 11:34:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-21T05:58:20Z. Reason: GVLK.
Information	9/14/2017 11:29:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 11:29:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 11:29:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/09/14 05:59"
Information	9/14/2017 11:29:18 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/09/14 05:59, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/14/2017 11:24:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 11:24:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 11:24:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 11:24:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 10:20:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 10:20:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:15Z. Reason: GVLK.
Information	9/14/2017 10:15:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 10:15:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 10:15:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 10:15:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 10:03:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 10:03:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:55Z. Reason: GVLK.
Information	9/14/2017 9:58:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 9:58:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 9:58:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 9:58:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 341f757f-9905-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 9:58:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 9:58:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 341f757e-9905-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 9:58:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 341f757d-9905-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 9:54:07 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8653.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	9/14/2017 9:46:57 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/14/2017 9:39:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 9:39:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:11Z. Reason: GVLK.
Information	9/14/2017 9:34:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 9:34:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 9:34:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 9:34:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 9:32:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 82aa4762-9901-11e7-b905-204747d02364
Report Status: 0"
Information	9/14/2017 9:30:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/14/2017 9:30:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:16Z. Reason: GVLK.
Information	9/14/2017 9:27:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/14/2017 9:25:50 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/14/2017 9:25:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/14/2017 9:25:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 9:25:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 9:25:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 9:23:53 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/14/2017 9:22:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/14/2017 9:22:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50913)(?)])(1 )(2 )]

"
Information	9/14/2017 9:22:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 50913)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/14/2017 9:22:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/14/2017 9:22:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/14/2017 9:22:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/14/2017 9:22:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	9/13/2017 7:10:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 7:10:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:58Z. Reason: GVLK.
Information	9/13/2017 7:05:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 7:05:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 7:05:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 7:05:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 6:40:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 6:35:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/13/2017 6:35:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51800)(?)])(1 )(2 )]

"
Information	9/13/2017 6:35:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51800)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51803)(?)])(1 )(2 )]

"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51803)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 6:32:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 6:14:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 6:14:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 6:14:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 6:13:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 4:37:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c65685d4-9873-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 4:21:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 4:16:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/13/2017 4:16:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51939)(?)])(1 )(2 )]

"
Information	9/13/2017 4:16:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51939)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 4:16:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/13/2017 4:16:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 4:16:08 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 3:38:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86207562-986b-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 3:38:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86207561-986b-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 3:38:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86207560-986b-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 3:30:37 PM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Information	9/13/2017 2:34:39 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 2:34:39 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:36Z. Reason: GVLK.
Information	9/13/2017 2:30:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/13/2017 2:30:16 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/13/2017 2:29:36 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 2:29:36 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 2:29:36 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 2:29:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 2:14:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 2:14:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 2:13:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 2:13:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/13/2017 2:13:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 1:16:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 1:16:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:02Z. Reason: GVLK.
Information	9/13/2017 1:11:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 1:11:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 1:11:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 1:11:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 12:58:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8652.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/13/2017 11:37:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: db57a725-9849-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 11:08:06 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/13/2017 10:58:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/13/2017 10:53:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/13/2017 10:14:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 10:14:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 10:13:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 8:23:29 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/13/2017 8:02:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/13/2017 8:02:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/13/2017 6:48:57 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 6:48:57 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:56Z. Reason: GVLK.
Information	9/13/2017 6:43:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 6:43:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 6:43:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 6:43:52 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 6:36:42 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd24c595-981f-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 6:14:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 6:14:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 6:13:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 5:41:40 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/13/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52578)(?)])(1 )(2 )]

"
Information	9/13/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52578)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 5:36:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/13/2017 5:36:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 5:36:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 4:26:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/13/2017 4:26:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/13/2017 4:10:48 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 4:10:48 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:48Z. Reason: GVLK.
Information	9/13/2017 4:05:48 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 4:05:48 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 4:05:48 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 4:05:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 4:05:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa073d1c-980a-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 4:05:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa073d1b-980a-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 4:05:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa073d1a-980a-11e7-b905-204747d02364
Report Status: 0"
Error	9/13/2017 4:02:05 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/13/2017 3:54:54 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/13/2017 3:54:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:54Z. Reason: GVLK.
Error	9/13/2017 3:50:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/13/2017 3:49:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/13/2017 3:49:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/13/2017 3:49:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/13/2017 3:49:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/13/2017 2:14:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 2:13:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 2:13:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/13/2017 1:36:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e152c741-97f5-11e7-b905-204747d02364
Report Status: 0"
Information	9/13/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/12/2017 10:14:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 10:13:24 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 8:36:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f74dec31-97cb-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 8:03:19 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 7:58:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2017 7:58:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53157)(?)])(1 )(2 )]

"
Information	9/12/2017 7:58:16 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53157)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 7:58:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2017 7:58:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 7:58:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 6:13:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 6:13:45 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/12/2017 6:13:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 3:36:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d239184-97a2-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 2:43:08 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/12/2017 2:21:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 2:16:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2017 2:16:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53499)(?)])(1 )(2 )]

"
Information	9/12/2017 2:16:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53499)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 2:16:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2017 2:16:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 2:16:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 2:13:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 12:46:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 12:46:20 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:18Z. Reason: GVLK.
Information	9/12/2017 12:41:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2017 12:41:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 12:41:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 12:41:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 12:39:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8651.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/12/2017 11:31:15 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/12/2017 11:16:24 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/12/2017 11:02:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/12/2017 10:36:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2189c21c-9778-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 10:13:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 10:12:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 10:12:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 6:13:00 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 6:12:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 5:41:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 5:36:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/12/2017 5:36:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54018)(?)])(1 )(2 )]

"
Information	9/12/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54018)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 5:36:37 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2017 5:36:37 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 5:36:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 5:35:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 22c1d436-974e-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 5:14:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 5:09:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/12/2017 5:09:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 5:09:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 4:35:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 4:35:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:21Z. Reason: GVLK.
Information	9/12/2017 4:30:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2017 4:30:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252420)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 4:30:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 4:30:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 4:28:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1c19f2f-9744-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 4:28:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1c19f2e-9744-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 4:28:16 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b1c19f2d-9744-11e7-b905-204747d02364
Report Status: 0"
Error	9/12/2017 4:13:56 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/12/2017 3:31:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/12/2017 3:31:18 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:17Z. Reason: GVLK.
Error	9/12/2017 3:28:13 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/12/2017 3:27:30 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\SPARX SYSTEMS\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8650.0000.
Information	9/12/2017 3:27:04 AM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft VS Code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8650.0000.
Information	9/12/2017 3:26:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/12/2017 3:26:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/12/2017 3:26:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/12/2017 3:26:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/12/2017 2:12:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 2:12:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/12/2017 12:35:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 362cb6e1-9724-11e7-b905-204747d02364
Report Status: 0"
Information	9/12/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/11/2017 11:31:31 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/11/2017 11:31:31 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/11/2017 11:30:56 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 17, Compared: 12354, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/11/2017 11:30:27 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/11/2017 10:38:58 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/11/2017 10:12:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 10:12:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 8:46:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 8:46:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:23Z. Reason: GVLK.
Information	9/11/2017 8:41:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2017 8:41:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 8:41:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 8:41:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 7:41:05 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 7:36:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 7:36:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54619)(?)])(1 )(2 )]

"
Information	9/11/2017 7:36:04 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54619)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:35:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 7:35:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54619)(?)])(1 )(2 )]

"
Information	9/11/2017 7:35:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54619)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:35:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/11/2017 7:35:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 7:35:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 7:35:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c36d59d-96fa-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 7:34:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 7:29:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 7:29:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54626)(?)])(1 )(2 )]

"
Information	9/11/2017 7:29:19 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54626)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 7:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54626)(?)])(1 )(2 )]

"
Information	9/11/2017 7:29:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54626)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:26:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 7:26:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54629)(?)])(1 )(2 )]

"
Information	9/11/2017 7:26:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54629)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:26:22 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/11/2017 7:26:22 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 7:26:22 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 6:12:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 6:12:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 2:35:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 613ee79d-96d0-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 2:12:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 2:11:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 12:49:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8650.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/11/2017 12:19:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎09‎-‎11T06:49:23.067680800Z.
Information	9/11/2017 12:19:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎09‎-‎11T06:49:23.067680800Z.
Information	9/11/2017 12:17:10 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/11/2017 12:13:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/11/2017 11:31:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/11/2017 10:34:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/11/2017 10:30:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 10:30:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:13Z. Reason: GVLK.
Information	9/11/2017 10:25:13 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2017 10:25:13 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 10:25:13 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 10:25:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 10:12:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 10:11:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 9:33:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024000e
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 34c64038-96a6-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 7:30:34 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 7:30:34 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:34Z. Reason: GVLK.
Information	9/11/2017 7:25:34 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2017 7:25:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253680)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 7:25:34 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 7:25:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 7:22:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2017 7:22:33 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2017 6:12:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 6:11:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 5:36:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/11/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55458)(?)])(1 )(2 )]

"
Information	9/11/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55458)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/11/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 5:36:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 5:35:35 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/11/2017 5:35:26 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/11/2017 5:26:19 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/11/2017 4:33:45 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4bb630c0-967c-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 3:50:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 3:50:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:55Z. Reason: GVLK.
Information	9/11/2017 3:45:55 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2017 3:45:55 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 3:45:55 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 3:45:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 3:45:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 935e1d3d-9675-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 3:45:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 935e1d3c-9675-11e7-b905-204747d02364
Report Status: 0"
Information	9/11/2017 3:45:39 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 935e1d3b-9675-11e7-b905-204747d02364
Report Status: 0"
Error	9/11/2017 3:40:53 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/11/2017 3:31:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/11/2017 3:31:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:45Z. Reason: GVLK.
Error	9/11/2017 3:27:23 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/11/2017 3:26:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/11/2017 3:26:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/11/2017 3:26:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/11/2017 3:26:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/11/2017 2:11:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 2:11:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/11/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/10/2017 11:33:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 615d431b-9652-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 10:11:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 10:11:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 10:11:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 6:33:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7729bcde-9628-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 6:11:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 6:11:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 5:19:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 5:19:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:40Z. Reason: GVLK.
Information	9/10/2017 5:14:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 5:14:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 5:14:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 5:14:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 2:30:17 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/10/2017 2:30:15 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/10/2017 2:30:14 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/10/2017 2:11:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 2:11:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 2:11:06 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/10/2017 2:10:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 1:44:37 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 1:44:37 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:37Z. Reason: GVLK.
Information	9/10/2017 1:39:37 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 1:39:37 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 1:39:37 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 1:39:36 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 1:33:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8cb46c5e-95fe-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 12:40:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/10/2017 12:35:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/10/2017 12:35:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/10/2017 12:24:27 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 12:24:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:27Z. Reason: GVLK.
Information	9/10/2017 12:20:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8649.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/10/2017 12:19:27 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 12:19:27 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 12:19:27 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 12:19:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 11:45:39 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/10/2017 11:45:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/10/2017 10:11:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 10:10:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 10:10:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 10:01:59 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/10/2017 8:33:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9ffcfa7b-95d4-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 6:11:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 6:10:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 6:10:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56898)(?)])(1 )(2 )]

"
Information	9/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56898)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 4:01:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 4:01:27 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:27Z. Reason: GVLK.
Information	9/10/2017 3:56:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 3:56:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 3:56:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 3:56:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7c3b265-95ad-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 3:56:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 3:56:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7c3b264-95ad-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 3:56:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e7c3b263-95ad-11e7-b905-204747d02364
Report Status: 0"
Error	9/10/2017 3:51:49 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/10/2017 3:40:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 3:40:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:39Z. Reason: GVLK.
Error	9/10/2017 3:36:17 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/10/2017 3:35:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 3:35:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 3:35:39 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 3:35:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 3:33:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5459fbb-95aa-11e7-b905-204747d02364
Report Status: 0"
Information	9/10/2017 3:16:56 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 3:11:56 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/10/2017 3:11:56 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 3:11:55 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 2:11:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 2:10:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 2:10:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/10/2017 1:01:25 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/10/2017 1:01:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/10/2017 12:22:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/10/2017 12:22:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:57Z. Reason: GVLK.
Information	9/10/2017 12:17:57 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/10/2017 12:17:57 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/10/2017 12:17:57 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/10/2017 12:17:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/10/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/9/2017 11:49:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/9/2017 11:48:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/9/2017 10:33:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cab30a46-9580-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 10:11:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 10:10:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 10:10:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/9/2017 10:10:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 6:11:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 6:09:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 5:33:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dff7b016-9556-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 5:00:41 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/9/2017 3:35:00 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/9/2017 3:34:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/9/2017 3:10:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/9/2017 3:10:42 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/9/2017 2:11:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 2:09:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 12:33:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f551c1f7-952c-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 12:26:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8648.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/9/2017 11:01:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/9/2017 10:23:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2017 10:23:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:40Z. Reason: GVLK.
Information	9/9/2017 10:18:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2017 10:18:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2017 10:18:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2017 10:18:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/9/2017 10:10:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 10:09:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 7:33:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0b0ff492-9503-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 6:10:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 6:09:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58338)(?)])(1 )(2 )]

"
Information	9/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58338)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/9/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/9/2017 5:15:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2017 5:15:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:41Z. Reason: GVLK.
Information	9/9/2017 5:10:41 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2017 5:10:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2017 5:10:41 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2017 5:10:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/9/2017 5:10:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c4e7066-94ef-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 5:10:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c4e7065-94ef-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 5:10:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0c4e7064-94ef-11e7-b905-204747d02364
Report Status: 0"
Error	9/9/2017 5:06:37 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/9/2017 5:02:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/9/2017 5:02:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:55Z. Reason: GVLK.
Error	9/9/2017 4:53:52 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/9/2017 4:53:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/9/2017 4:53:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/9/2017 4:53:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/9/2017 4:53:10 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/9/2017 2:33:14 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 20ae7b14-94d9-11e7-b905-204747d02364
Report Status: 0"
Information	9/9/2017 2:10:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 2:08:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/9/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/8/2017 11:31:47 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/8/2017 11:31:47 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/8/2017 11:31:09 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 1, Compared: 12246, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/8/2017 11:30:19 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/8/2017 11:26:41 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/8/2017 10:10:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 10:08:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 9:33:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35929356-94af-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 8:02:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 8:02:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:07Z. Reason: GVLK.
Information	9/8/2017 7:57:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2017 7:57:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2017 7:57:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 7:57:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 6:10:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 6:08:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 4:33:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b57e9b4-9485-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 3:56:10 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/8/2017 3:55:54 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/8/2017 2:10:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 2:08:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 12:41:04 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8647.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/8/2017 11:33:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244022
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ef7e168-945b-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 11:30:14 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 11:30:14 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:14Z. Reason: GVLK.
Information	9/8/2017 11:29:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/8/2017 11:29:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/8/2017 11:25:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2017 11:25:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2017 11:25:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 11:25:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 11:20:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/8/2017 11:19:50 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/8/2017 10:55:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/8/2017 10:10:06 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 10:08:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 6:57:24 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/8/2017 6:57:14 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/8/2017 6:31:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 30679b31-9431-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 6:14:53 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/8/2017 6:09:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 6:08:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/8/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59778)(?)])(1 )(2 )]

"
Information	9/8/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59778)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/8/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 4:44:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 4:39:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/8/2017 4:39:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 4:39:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 4:24:04 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	9/8/2017 4:23:59 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	9/8/2017 3:33:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 3:33:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:45Z. Reason: GVLK.
Information	9/8/2017 3:28:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2017 3:28:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2017 3:28:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 3:28:44 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 3:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9bed3af2-9417-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 3:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9bed3af1-9417-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 3:27:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9bed3af0-9417-11e7-b905-204747d02364
Report Status: 0"
Error	9/8/2017 3:23:51 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/8/2017 3:11:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/8/2017 3:11:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:50Z. Reason: GVLK.
Error	9/8/2017 3:07:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/8/2017 3:06:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/8/2017 3:06:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/8/2017 3:06:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/8/2017 3:06:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/8/2017 2:09:36 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 2:08:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/8/2017 1:30:59 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4439b240-9407-11e7-b905-204747d02364
Report Status: 0"
Information	9/8/2017 12:03:04 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/7/2017 10:22:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 10:22:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:15Z. Reason: GVLK.
Information	9/7/2017 10:17:19 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/7/2017 10:17:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 10:17:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 10:17:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 10:17:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 10:16:32 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/7/2017 10:09:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 10:08:13 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 8:30:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 52bfdc9a-93dd-11e7-b905-204747d02364
Report Status: 0"
Information	9/7/2017 6:09:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 6:08:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 3:30:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 67708260-93b3-11e7-b905-204747d02364
Report Status: 0"
Information	9/7/2017 2:44:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/7/2017 2:44:19 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/7/2017 2:12:54 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 2:09:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 2:09:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/7/2017 2:08:00 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 359

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 655

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 188

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 390

Information	9/7/2017 2:07:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/7/2017 2:07:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/7/2017 2:07:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60708)(?)])(1 )(2 )]

"
Information	9/7/2017 2:07:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60708)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 2:07:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2017 2:07:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 2:07:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 2:06:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.874. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	9/7/2017 2:06:20 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	9/7/2017 2:01:29 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/7/2017 1:07:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 1:07:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:54:10Z. Reason: GVLK.
Information	9/7/2017 1:02:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 1:02:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 1:02:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 1:02:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 12:36:02 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/7/2017 12:13:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 12:08:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2017 12:08:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 12:08:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 12:07:02 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8646.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/7/2017 11:43:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 11:38:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2017 11:38:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 11:38:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 11:29:19 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 11:29:19 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-14T05:53:19Z. Reason: GVLK.
Information	9/7/2017 11:24:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 11:24:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 11:24:18 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/09/07 05:54"
Information	9/7/2017 11:24:17 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/09/07 05:54, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	9/7/2017 11:19:14 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 11:19:14 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 11:19:14 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 11:19:14 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 11:13:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 11:08:17 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2017 11:08:17 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 11:08:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 11:01:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 11:01:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:14Z. Reason: GVLK.
Information	9/7/2017 10:55:26 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/7/2017 10:54:02 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:54:01 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:54:01 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8645.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/7/2017 10:54:01 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:54:00 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/7/2017 10:53:29 AM	ESENT	302	Logging/Recovery	Windows (7352) Windows: The database engine has successfully completed recovery steps.
Information	9/7/2017 10:53:29 AM	ESENT	301	Logging/Recovery	Windows (7352) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/7/2017 10:53:27 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 10:53:27 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 10:53:27 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 10:53:25 AM	ESENT	301	Logging/Recovery	Windows (7352) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03D6E.log.
Information	9/7/2017 10:53:25 AM	ESENT	300	Logging/Recovery	Windows (7352) Windows: The database engine is initiating recovery steps.
Information	9/7/2017 10:53:25 AM	ESENT	102	General	Windows (7352) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/7/2017 10:53:24 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 10:53:23 AM	Service1	0	None	Service started successfully.
Error	9/7/2017 10:53:15 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/7/2017 10:53:13 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/7/2017 10:52:42 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/7/2017 10:52:34 AM	PostgreSQL	0	None	"2017-09-07 10:52:34 IST LOG:  redirecting log output to logging collector process
2017-09-07 10:52:34 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/7/2017 10:52:33 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/7/2017 10:52:33 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/7/2017 10:52:32 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/7/2017 10:52:30 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/7/2017 10:52:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/7/2017 10:52:29 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/7/2017 10:52:29 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/7/2017 10:52:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/7/2017 10:52:29 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/7/2017 10:52:26 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/7/2017 10:52:25 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/7/2017 10:52:24 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/7/2017 10:52:23 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:23 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:23 AM	MSSQL$SQLEXPRESS	3406	Server	2 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/7/2017 10:52:22 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3964 at 9/7/2017 10:19:31 AM (local) 9/7/2017 4:49:31 AM (UTC). This is an informational message only; no user action is required.
Information	9/7/2017 10:52:21 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/7/2017 10:52:21 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/7/2017 10:52:21 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/7/2017 10:52:21 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/7/2017 10:52:21 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3564.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/7/2017 10:52:20 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/7/2017 10:52:16 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/7/2017 10:52:12 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:52:06 AM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/7/2017 10:52:06 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/7/2017 10:52:06 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/7/2017 10:52:06 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/7/2017 10:39:31 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 10:35:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 10:35:54 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:54Z. Reason: GVLK.
Information	9/7/2017 10:32:53 AM	McLogEvent	257	None	The scan of C:\Users\212558710\DOWNLOADS\org.sonarlint.eclipse.site-3.2.0.201706271328.zip has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8645.0000.
Information	9/7/2017 10:30:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 10:30:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 10:30:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 10:30:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 10:30:37 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7c20ca79-9389-11e7-bf30-0205857feb80
Report Status: 0"
Information	9/7/2017 10:29:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/7/2017 10:29:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:41Z. Reason: GVLK.
Information	9/7/2017 10:29:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/7/2017 10:29:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60925)(?)])(1 )(2 )]

"
Information	9/7/2017 10:29:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60925)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 10:29:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/7/2017 10:29:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 10:29:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	9/7/2017 10:26:06 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/7/2017 10:22:46 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/7/2017 10:21:19 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:21:17 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:21:16 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:21:15 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/7/2017 10:21:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/7/2017 10:21:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/7/2017 10:21:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/7/2017 10:21:01 AM	ESENT	302	Logging/Recovery	Windows (1940) Windows: The database engine has successfully completed recovery steps.
Information	9/7/2017 10:20:57 AM	ESENT	301	Logging/Recovery	Windows (1940) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/7/2017 10:20:57 AM	ESENT	300	Logging/Recovery	Windows (1940) Windows: The database engine is initiating recovery steps.
Information	9/7/2017 10:20:57 AM	ESENT	102	General	Windows (1940) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/7/2017 10:20:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/7/2017 10:20:43 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8645.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/7/2017 10:20:05 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/7/2017 10:20:02 AM	Service1	0	None	Service started successfully.
Error	9/7/2017 10:19:50 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/7/2017 10:19:50 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/7/2017 10:19:39 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:39 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/7/2017 10:19:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/7/2017 10:19:38 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/7/2017 10:19:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/7/2017 10:19:37 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:37 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/7/2017 10:19:37 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/7/2017 10:19:36 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:36 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/7/2017 10:19:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/7/2017 10:19:35 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:34 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/7/2017 10:19:33 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/7/2017 10:19:33 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/7/2017 10:19:33 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/7/2017 10:19:33 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/7/2017 10:19:31 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3696 at 9/4/2017 10:26:14 AM (local) 9/4/2017 4:56:14 AM (UTC). This is an informational message only; no user action is required.
Information	9/7/2017 10:19:29 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/7/2017 10:19:29 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/7/2017 10:19:29 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/7/2017 10:19:29 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/7/2017 10:19:29 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/7/2017 10:19:23 AM	PostgreSQL	0	None	"2017-09-07 10:19:23 IST LOG:  redirecting log output to logging collector process
2017-09-07 10:19:23 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/7/2017 10:19:19 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/7/2017 10:19:16 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/7/2017 10:19:16 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/7/2017 10:19:16 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/7/2017 10:19:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/7/2017 10:19:14 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/7/2017 10:19:13 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/7/2017 10:19:13 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/7/2017 10:19:13 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/7/2017 10:19:13 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/7/2017 10:19:13 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3964.
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/7/2017 10:19:12 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/7/2017 10:18:44 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/7/2017 10:18:40 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/7/2017 10:18:25 AM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/7/2017 10:18:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/7/2017 10:18:22 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/7/2017 10:18:22 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/6/2017 10:42:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 10:41:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 10:41:29 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/6/2017 10:41:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 10:34:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74029cfa-9325-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 8:25:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 8:25:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:41Z. Reason: GVLK.
Information	9/6/2017 8:20:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2017 8:20:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 8:20:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 8:20:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 8:00:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 8:00:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:48Z. Reason: GVLK.
Information	9/6/2017 7:55:48 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2017 7:55:48 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 7:55:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 7:55:47 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 7:36:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 7:31:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2017 7:31:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61824)(?)])(1 )(2 )]

"
Information	9/6/2017 7:31:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61824)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 7:31:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/6/2017 7:31:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 7:31:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 6:42:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 6:41:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 5:34:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 89bdf912-92fb-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 2:42:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 2:41:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 1:57:35 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/6/2017 12:34:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9d6e6825-92d1-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 12:30:48 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/6/2017 12:01:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8645.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/6/2017 11:16:20 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/6/2017 10:42:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 10:40:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 10:34:27 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/6/2017 7:32:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f4e3091-92a7-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 6:42:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 6:40:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/6/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62658)(?)])(1 )(2 )]

"
Information	9/6/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62658)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/6/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 5:05:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 5:05:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:38Z. Reason: GVLK.
Information	9/6/2017 5:00:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2017 5:00:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 5:00:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 5:00:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 5:00:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 315780b9-9292-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 5:00:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 315780b8-9292-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 5:00:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 315780b7-9292-11e7-a77d-204747d02364
Report Status: 0"
Error	9/6/2017 4:49:22 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/6/2017 4:35:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 4:35:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:11Z. Reason: GVLK.
Error	9/6/2017 4:30:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/6/2017 4:30:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2017 4:30:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 4:30:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 4:30:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 3:34:11 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/6/2017 3:34:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:10Z. Reason: GVLK.
Information	9/6/2017 3:29:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/6/2017 3:29:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/6/2017 3:29:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/6/2017 3:29:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/6/2017 3:15:00 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	9/6/2017 3:14:29 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	9/6/2017 2:41:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 2:40:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/6/2017 2:31:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 70f4d22c-927d-11e7-a77d-204747d02364
Report Status: 0"
Information	9/6/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/5/2017 11:31:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/5/2017 11:30:52 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 30, Compared: 12068, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/5/2017 11:30:01 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	9/5/2017 11:30:01 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	9/5/2017 10:41:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 10:40:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 9:48:44 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/5/2017 9:31:38 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f43bfdf-9253-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 6:41:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 6:40:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 4:31:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9503b17b-9229-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 2:41:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 2:40:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 12:21:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5222c10-9206-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 12:18:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8644.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/5/2017 12:08:02 PM	Desktop Window Manager	9013	None	The Desktop Window Manager was unable to start because composition was disabled by a running application
Information	9/5/2017 12:08:02 PM	Desktop Window Manager	9010	None	A request to disable the Desktop Window Manager was made by process (WebEx)
Warning	9/5/2017 12:07:35 PM	MsiInstaller	1015	None	Failed to connect to server. Error: 0x80070005
Warning	9/5/2017 12:07:34 PM	MsiInstaller	1001	None	Detection of product '{BC685733-C000-4BCC-90A8-395BB5877A54}', feature 'Device_Driver_Files' failed during request for component '{F8D90E48-3887-4919-942B-D87160FB64D6}'
Warning	9/5/2017 12:07:34 PM	MsiInstaller	1004	None	Detection of product '{BC685733-C000-4BCC-90A8-395BB5877A54}', feature 'Device_Driver_Files', component '{03713515-5282-0076-6E38-09A302E781B0}' failed.  The resource 'C:\Windows\inf\AMC\AMC_USB_Serial_Function.cat' does not exist.
Information	9/5/2017 12:06:22 PM	Desktop Window Manager	9013	None	The Desktop Window Manager was unable to start because composition was disabled by a running application
Information	9/5/2017 12:06:22 PM	Desktop Window Manager	9010	None	A request to disable the Desktop Window Manager was made by process (WebEx)
Information	9/5/2017 12:05:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 12:05:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:54Z. Reason: GVLK.
Information	9/5/2017 12:00:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2017 12:00:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 12:00:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 12:00:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 11:31:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a9bc7d87-91ff-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 10:41:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 10:40:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	9/5/2017 10:40:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 10:40:13 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	9/5/2017 10:40:00 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	9/5/2017 6:41:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 6:40:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 6:30:30 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c09bac8-91d5-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/5/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64098)(?)])(1 )(2 )]

"
Information	9/5/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64098)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/5/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 4:21:02 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/5/2017 4:19:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 4:14:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/5/2017 4:14:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 4:14:12 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 3:32:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 3:32:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:49Z. Reason: GVLK.
Information	9/5/2017 3:27:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2017 3:27:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 3:27:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 3:27:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 3:27:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0820373e-91bc-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 3:27:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0820373d-91bc-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 3:27:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0820373c-91bc-11e7-a77d-204747d02364
Report Status: 0"
Error	9/5/2017 3:24:16 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/5/2017 3:15:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 3:15:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:21Z. Reason: GVLK.
Error	9/5/2017 3:11:03 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/5/2017 3:10:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2017 3:10:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 3:10:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 3:10:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 2:41:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 2:40:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/5/2017 1:29:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8e4479af-91ab-11e7-a77d-204747d02364
Report Status: 0"
Information	9/5/2017 1:12:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 1:12:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:44Z. Reason: GVLK.
Information	9/5/2017 1:07:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2017 1:07:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 1:07:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 1:07:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 12:22:39 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/5/2017 12:22:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:38Z. Reason: GVLK.
Information	9/5/2017 12:17:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/5/2017 12:17:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252720)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/5/2017 12:17:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/5/2017 12:17:38 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/5/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/4/2017 10:40:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 10:39:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 8:29:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a44d9121-9181-11e7-a77d-204747d02364
Report Status: 0"
Information	9/4/2017 6:40:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 6:39:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 3:29:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ba37e6dc-9157-11e7-a77d-204747d02364
Report Status: 0"
Information	9/4/2017 2:40:44 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 2:39:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 1:00:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 1:00:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:41Z. Reason: GVLK.
Information	9/4/2017 12:55:40 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2017 12:55:40 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 12:55:40 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 12:55:38 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 12:19:51 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/4/2017 11:46:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 11:41:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2017 11:41:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 11:41:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 11:39:57 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8643.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/4/2017 11:39:18 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/4/2017 11:39:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	9/4/2017 11:18:21 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 11:18:21 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:21Z. Reason: GVLK.
Information	9/4/2017 11:16:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 11:13:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2017 11:13:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 11:13:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 11:13:19 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 11:11:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2017 11:11:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 11:11:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 11:09:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 76fc0a50-9133-11e7-a77d-204747d02364
Report Status: 0"
Information	9/4/2017 11:09:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 76fc0a4f-9133-11e7-a77d-204747d02364
Report Status: 0"
Information	9/4/2017 11:09:49 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 76fc0a4e-9133-11e7-a77d-204747d02364
Report Status: 0"
Error	9/4/2017 11:01:06 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	9/4/2017 10:46:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 10:42:22 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 10:42:22 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:22Z. Reason: GVLK.
Information	9/4/2017 10:42:13 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c26fbb8-912f-11e7-a77d-204747d02364
Report Status: 0"
Information	9/4/2017 10:40:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 10:40:33 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	9/4/2017 10:39:06 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 671

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 94

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 484

Information	9/4/2017 10:38:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/4/2017 10:38:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/4/2017 10:38:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65237)(?)])(1 )(2 )]

"
Information	9/4/2017 10:38:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65237)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 10:37:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/4/2017 10:37:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65238)(?)])(1 )(2 )]

"
Information	9/4/2017 10:37:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65238)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 10:37:00 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/4/2017 10:37:00 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 10:36:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	9/4/2017 10:36:36 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	9/4/2017 10:35:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2017 10:35:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 10:35:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 10:35:17 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/4/2017 10:35:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 10:34:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/4/2017 10:34:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:14Z. Reason: GVLK.
Information	9/4/2017 10:28:28 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/4/2017 10:26:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/4/2017 10:26:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/4/2017 10:26:53 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/4/2017 10:26:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/4/2017 10:26:52 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/4/2017 10:26:52 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/4/2017 10:26:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/4/2017 10:26:47 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/4/2017 10:26:42 AM	ESENT	302	Logging/Recovery	Windows (7552) Windows: The database engine has successfully completed recovery steps.
Information	9/4/2017 10:26:41 AM	ESENT	301	Logging/Recovery	Windows (7552) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/4/2017 10:26:41 AM	ESENT	300	Logging/Recovery	Windows (7552) Windows: The database engine is initiating recovery steps.
Information	9/4/2017 10:26:41 AM	ESENT	102	General	Windows (7552) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/4/2017 10:26:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/4/2017 10:26:30 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/4/2017 10:26:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/4/2017 10:26:30 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/4/2017 10:26:26 AM	Service1	0	None	Service started successfully.
Information	9/4/2017 10:26:22 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8642.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Error	9/4/2017 10:26:20 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/4/2017 10:26:20 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Warning	9/4/2017 10:26:19 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/4/2017 10:26:18 AM	PostgreSQL	0	None	Server started and accepting connections

Information	9/4/2017 10:26:17 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/4/2017 10:26:17 AM	PostgreSQL	0	None	"2017-09-04 10:26:17 IST LOG:  redirecting log output to logging collector process
2017-09-04 10:26:17 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/4/2017 10:26:16 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:16 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/4/2017 10:26:16 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/4/2017 10:26:16 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/4/2017 10:26:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/4/2017 10:26:15 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/4/2017 10:26:15 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/4/2017 10:26:14 AM	PostgreSQL	0	None	Waiting for server startup...

Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3592 at 9/3/2017 10:01:37 PM (local) 9/3/2017 4:31:37 PM (UTC). This is an informational message only; no user action is required.
Information	9/4/2017 10:26:14 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/4/2017 10:26:13 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/4/2017 10:26:13 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/4/2017 10:26:13 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/4/2017 10:26:13 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/4/2017 10:26:13 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3696.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/4/2017 10:26:12 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	9/4/2017 10:26:08 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/4/2017 10:26:06 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/4/2017 10:26:06 AM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/4/2017 10:26:06 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/4/2017 10:26:06 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/3/2017 10:01:43 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/3/2017 10:01:37 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	9/3/2017 10:01:35 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 772 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1212 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/3/2017 10:01:34 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/3/2017 10:01:34 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/3/2017 10:01:34 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/3/2017 10:01:31 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	9/3/2017 9:56:46 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 9:56:46 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 9:56:45 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 9:55:56 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 9:55:56 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:55Z. Reason: GVLK.
Information	9/3/2017 9:50:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2017 9:50:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 9:50:55 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 9:50:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 9:49:55 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 9:49:55 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:54Z. Reason: GVLK.
Information	9/3/2017 9:43:30 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/3/2017 9:42:16 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8642.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/3/2017 9:42:02 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 9:42:02 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 9:42:01 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 9:42:01 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/3/2017 9:41:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2017 9:41:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 9:41:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 9:41:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 9:41:28 PM	ESENT	302	Logging/Recovery	Windows (6436) Windows: The database engine has successfully completed recovery steps.
Information	9/3/2017 9:41:27 PM	ESENT	301	Logging/Recovery	Windows (6436) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/3/2017 9:41:27 PM	ESENT	300	Logging/Recovery	Windows (6436) Windows: The database engine is initiating recovery steps.
Information	9/3/2017 9:41:27 PM	ESENT	102	General	Windows (6436) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/3/2017 9:41:21 PM	Service1	0	None	Service started successfully.
Error	9/3/2017 9:41:16 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/3/2017 9:41:16 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/3/2017 9:41:14 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/3/2017 9:41:14 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/3/2017 9:41:14 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/3/2017 9:41:14 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/3/2017 9:41:14 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/3/2017 9:41:13 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	9/3/2017 9:41:13 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/3/2017 9:41:12 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/3/2017 9:41:09 PM	PostgreSQL	0	None	"2017-09-03 21:41:09 IST LOG:  redirecting log output to logging collector process
2017-09-03 21:41:09 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/3/2017 9:41:09 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/3/2017 9:41:09 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/3/2017 9:41:08 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/3/2017 9:41:06 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3764 at 9/3/2017 1:25:03 PM (local) 9/3/2017 7:55:03 AM (UTC). This is an informational message only; no user action is required.
Information	9/3/2017 9:41:04 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/3/2017 9:41:03 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/3/2017 9:41:03 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/3/2017 9:41:03 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/3/2017 9:41:03 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/3/2017 9:41:03 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3592.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/3/2017 9:41:02 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/3/2017 9:40:55 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/3/2017 9:40:54 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 9:40:49 PM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/3/2017 9:40:38 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/3/2017 9:40:38 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/3/2017 9:40:38 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/3/2017 7:50:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0267478a-90b3-11e7-bed3-204747d02364
Report Status: 0"
Information	9/3/2017 3:40:32 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 3:35:32 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 3:35:32 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 3:35:31 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 2:15:26 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 2:10:26 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 2:10:26 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 2:10:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 1:45:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 1:40:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 1:40:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 1:40:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 1:40:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 1:40:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:21Z. Reason: GVLK.
Information	9/3/2017 1:40:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 1:35:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2017 1:35:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 1:35:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 1:35:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 1:34:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2017 1:34:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66500)(?)])(1 )(2 )]

"
Information	9/3/2017 1:34:58 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66500)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 1:34:58 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 1:34:58 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 1:34:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 1:33:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/3/2017 1:33:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:38Z. Reason: GVLK.
Information	9/3/2017 1:30:06 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e5630c1a-907d-11e7-bed3-204747d02364
Report Status: 0"
Information	9/3/2017 1:27:53 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/3/2017 1:26:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8642.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/3/2017 1:26:29 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 1:26:29 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 1:26:28 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 1:26:28 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/3/2017 1:25:56 PM	ESENT	302	Logging/Recovery	Windows (1676) Windows: The database engine has successfully completed recovery steps.
Information	9/3/2017 1:25:55 PM	ESENT	301	Logging/Recovery	Windows (1676) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/3/2017 1:25:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/3/2017 1:25:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 1:25:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 1:25:48 PM	ESENT	301	Logging/Recovery	Windows (1676) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03D60.log.
Information	9/3/2017 1:25:48 PM	ESENT	300	Logging/Recovery	Windows (1676) Windows: The database engine is initiating recovery steps.
Information	9/3/2017 1:25:47 PM	ESENT	102	General	Windows (1676) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/3/2017 1:25:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 1:25:39 PM	Service1	0	None	Service started successfully.
Error	9/3/2017 1:25:32 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/3/2017 1:25:32 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/3/2017 1:25:22 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/3/2017 1:25:21 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/3/2017 1:25:18 PM	PostgreSQL	0	None	"2017-09-03 13:25:18 IST LOG:  redirecting log output to logging collector process
2017-09-03 13:25:18 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/3/2017 1:25:15 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/3/2017 1:25:13 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/3/2017 1:25:09 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/3/2017 1:25:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/3/2017 1:25:08 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/3/2017 1:25:08 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/3/2017 1:25:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/3/2017 1:25:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/3/2017 1:25:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/3/2017 1:25:07 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/3/2017 1:25:06 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/3/2017 1:25:05 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/3/2017 1:25:05 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3672 at 9/3/2017 12:33:42 AM (local) 9/2/2017 7:03:42 PM (UTC). This is an informational message only; no user action is required.
Information	9/3/2017 1:25:03 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/3/2017 1:25:02 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/3/2017 1:25:02 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/3/2017 1:25:02 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/3/2017 1:25:02 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/3/2017 1:25:02 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3764.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/3/2017 1:25:01 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/3/2017 1:24:55 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/3/2017 1:24:45 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/3/2017 1:24:37 PM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/3/2017 1:24:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/3/2017 1:24:37 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	9/3/2017 1:24:37 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/3/2017 12:33:50 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	9/3/2017 12:33:42 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	9/3/2017 12:33:41 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 18 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1392 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	9/3/2017 12:33:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	9/3/2017 12:33:40 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	9/3/2017 12:33:40 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	9/3/2017 12:14:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2017 12:14:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67300)(?)])(1 )(2 )]

"
Information	9/3/2017 12:14:54 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67300)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 12:07:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/3/2017 12:06:56 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 89, Deleted: 0, Modified: 6, Compared: 11995, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	9/3/2017 12:06:49 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	9/3/2017 12:04:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2017 12:04:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67310)(?)])(1 )(2 )]

"
Information	9/3/2017 12:04:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67310)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 12:04:27 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67310)(?)])(1 )(2 )]

"
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110510  Grace type=8.
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=4383ceba-91c8-4c73-a713-827d38ab4961"
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=71b3eab9-87c9-49b0-b656-29f898773e08"
Information	9/3/2017 12:04:26 AM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	9/3/2017 12:04:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	9/3/2017 12:04:17 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 187

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	9/3/2017 12:03:07 AM	RasClient	20225	None	CoId={5F6DD51D-20A2-4AF4-BCA7-917CA33AECBC}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.225.112
TunnelIpv6Address = None
Dial-in User = .
Information	9/3/2017 12:03:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/3/2017 12:03:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21232)(?)])(1 )(2 )]

"
Information	9/3/2017 12:03:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21232)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/3/2017 12:03:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/3/2017 12:03:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/3/2017 12:03:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/3/2017 12:03:01 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	9/3/2017 12:03:01 AM	RasClient	20224	None	CoId={5F6DD51D-20A2-4AF4-BCA7-917CA33AECBC}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	9/3/2017 12:03:01 AM	RasClient	20223	None	CoId={5F6DD51D-20A2-4AF4-BCA7-917CA33AECBC}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/3/2017 12:03:01 AM	RasClient	20222	None	CoId={5F6DD51D-20A2-4AF4-BCA7-917CA33AECBC}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	9/3/2017 12:03:01 AM	RasClient	20221	None	CoId={5F6DD51D-20A2-4AF4-BCA7-917CA33AECBC}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	9/3/2017 12:03:01 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	9/2/2017 11:20:33 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	9/2/2017 10:57:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8642.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/2/2017 9:36:33 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	9/2/2017 9:31:33 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/2/2017 9:31:33 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/2/2017 9:31:33 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/2/2017 8:24:55 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	9/2/2017 8:15:34 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	9/2/2017 8:15:34 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {BC333649-6FDD-4E95-A495-88F6100560AB}
Error	9/2/2017 8:15:34 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {BC333649-6FDD-4E95-A495-88F6100560AB}
Information	9/2/2017 8:15:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	9/2/2017 8:15:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21460)(?)])(1 )(2 )]

"
Information	9/2/2017 8:15:33 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/2/2017 8:15:29 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	9/2/2017 8:15:29 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/2/2017 8:15:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	9/2/2017 8:13:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	9/2/2017 8:13:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:53Z. Reason: GVLK.
Information	9/2/2017 8:08:07 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	9/2/2017 8:06:38 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/2/2017 8:06:37 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/2/2017 8:06:36 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/2/2017 8:06:34 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	9/2/2017 8:06:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	9/2/2017 8:06:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	9/2/2017 8:06:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	9/2/2017 8:06:11 PM	ESENT	302	Logging/Recovery	Windows (7368) Windows: The database engine has successfully completed recovery steps.
Information	9/2/2017 8:06:06 PM	ESENT	301	Logging/Recovery	Windows (7368) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	9/2/2017 8:06:06 PM	ESENT	300	Logging/Recovery	Windows (7368) Windows: The database engine is initiating recovery steps.
Information	9/2/2017 8:06:06 PM	ESENT	102	General	Windows (7368) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	9/2/2017 8:06:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	9/2/2017 8:06:01 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8639.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	9/2/2017 8:05:49 PM	Service1	0	None	Service started successfully.
Error	9/2/2017 8:05:19 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	9/2/2017 8:04:59 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	9/2/2017 8:04:57 PM	PostgreSQL	0	None	Server started and accepting connections

Information	9/2/2017 8:04:57 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	9/2/2017 8:04:53 PM	PostgreSQL	0	None	"2017-09-02 20:04:53 IST LOG:  redirecting log output to logging collector process
2017-09-02 20:04:53 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	9/2/2017 8:04:48 PM	PostgreSQL	0	None	Waiting for server startup...

Information	9/2/2017 8:04:46 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	9/2/2017 8:04:39 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	9/2/2017 8:04:39 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	9/2/2017 8:04:39 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	9/2/2017 8:04:39 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	9/2/2017 8:04:39 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	9/2/2017 8:04:35 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:34 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	9/2/2017 8:04:33 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	9/2/2017 8:04:33 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	9/2/2017 8:04:33 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	3406	Server	6 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	9/2/2017 8:04:31 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 2520 at 8/31/2017 10:58:15 PM (local) 8/31/2017 5:28:15 PM (UTC). This is an informational message only; no user action is required.
Information	9/2/2017 8:04:29 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	9/2/2017 8:04:28 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	9/2/2017 8:04:28 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	9/2/2017 8:04:28 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	9/2/2017 8:04:28 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3672.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	9/2/2017 8:04:27 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	9/2/2017 8:04:07 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	9/2/2017 8:04:00 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	9/2/2017 8:03:48 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	9/2/2017 8:03:48 PM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	9/2/2017 8:03:48 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	9/2/2017 8:03:48 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/31/2017 10:58:43 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	8/31/2017 10:58:16 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/31/2017 10:58:15 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	8/31/2017 10:58:02 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\ROOT
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 14748 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/31/2017 10:58:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/31/2017 10:58:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/31/2017 10:58:01 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/31/2017 10:29:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 10:29:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:32Z. Reason: GVLK.
Information	8/31/2017 10:24:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 10:24:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 10:24:31 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 10:24:30 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 10:22:27 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 10:22:23 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:23 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/31/2017 10:22:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/31/2017 10:22:23 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/31/2017 10:22:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:22:21 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 17404 at 8/31/2017 10:22:03 PM (local) 8/31/2017 4:52:03 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 2520.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 10:22:19 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/31/2017 10:22:12 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/31/2017 10:22:11 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/31/2017 10:22:05 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 10:22:03 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 10:22:03 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 10:22:03 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:02 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 10:22:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 10:22:00 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 10:21:59 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:21:58 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 6608 at 8/31/2017 10:16:02 PM (local) 8/31/2017 4:46:02 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 17404.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 10:21:57 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2-GDR) (KB4019093) - 12.0.5207.0 (X64) 
	Jul  3 2017 02:25:44 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/31/2017 10:21:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:51:28.393119500Z.
Information	8/31/2017 10:21:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 756.
Information	8/31/2017 10:21:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:21:53 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 10:21:53 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:21:53 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'GDR 5207 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:21:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:51:28.393119500Z.
Information	8/31/2017 10:21:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:50:39.224203100Z.
Information	8/31/2017 10:21:29 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Client Tools -- Install started.
Information	8/31/2017 10:21:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 756.
Information	8/31/2017 10:21:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 756.
Information	8/31/2017 10:21:27 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:21:27 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 10:21:27 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server 2014 sql_ssms (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:21:27 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'GDR 5207 for SQL Server 2014 sql_ssms (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:20:41 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Management Studio -- Install started.
Information	8/31/2017 10:20:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:50:39.224203100Z.
Information	8/31/2017 10:20:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:50:30.236304400Z.
Information	8/31/2017 10:20:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 756.
Information	8/31/2017 10:20:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 756.
Information	8/31/2017 10:20:37 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:20:37 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Services -- Configuration completed successfully.
Information	8/31/2017 10:20:37 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server Database Services 2008 Core Instance (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:20:37 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'GDR 5207 for SQL Server Database Services 2008 Core Instance (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:20:30 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Services -- Install started.
Information	8/31/2017 10:20:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:50:30.236304400Z.
Information	8/31/2017 10:20:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:50:12.110492000Z.
Information	8/31/2017 10:20:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 756.
Information	8/31/2017 10:20:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {F7012F84-80F5-4C25-852E-B1BA03276FE6}. Client Process Id: 756.
Information	8/31/2017 10:20:29 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:20:29 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 10:20:29 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server Database Services 2008 Common Core (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:20:29 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'GDR 5207 for SQL Server Database Services 2008 Common Core (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:20:12 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Common Files -- Install started.
Information	8/31/2017 10:20:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:50:12.110492000Z.
Information	8/31/2017 10:20:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:50:10.092290200Z.
Information	8/31/2017 10:20:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:50:01.897470800Z.
Information	8/31/2017 10:20:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {F7012F84-80F5-4C25-852E-B1BA03276FE6}. Client Process Id: 756.
Information	8/31/2017 10:20:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 756.
Information	8/31/2017 10:20:11 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Transact-SQL Compiler Service . Product Version: 12.2.5207.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 10:20:11 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Transact-SQL Compiler Service  -- Installation completed successfully.
Information	8/31/2017 10:20:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:50:10.092290200Z.
Information	8/31/2017 10:20:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:50:01.897470800Z.
Information	8/31/2017 10:20:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:49:58.661147200Z.
Information	8/31/2017 10:20:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:49:14.278709400Z.
Information	8/31/2017 10:20:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 756.
Information	8/31/2017 10:20:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 756.
Information	8/31/2017 10:20:00 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Express LocalDB . Product Version: 12.2.5207.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 10:20:00 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Express LocalDB  -- Installation completed successfully.
Information	8/31/2017 10:19:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:49:58.661147200Z.
Information	8/31/2017 10:19:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:49:14.278709400Z.
Information	8/31/2017 10:19:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:48:55.553837100Z.
Information	8/31/2017 10:19:13 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T16:46:54.780761000Z.
Information	8/31/2017 10:19:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 756.
Information	8/31/2017 10:19:13 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 756.
Information	8/31/2017 10:19:13 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Setup (English). Product Version: 12.2.5207.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 10:19:13 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Setup (English) -- Installation completed successfully.
Information	8/31/2017 10:18:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:48:55.553837100Z.
Information	8/31/2017 10:16:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T16:46:54.780761000Z.
Information	8/31/2017 10:16:53 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB4019093\GDR\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 756.
Information	8/31/2017 10:16:05 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 10:16:02 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 10:16:02 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 10:16:02 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:58 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 10:15:57 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 10:15:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:56 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 10:15:55 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 10:15:55 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:15:55 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 10804 at 8/31/2017 10:15:50 PM (local) 8/31/2017 4:45:50 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 10:15:54 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 6608.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 10:15:52 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2) (KB3171021) - 12.0.5000.0 (X64) 
	Jun 17 2016 19:14:09 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/31/2017 10:15:50 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 10:15:49 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 10:15:49 PM	MSSQL$SQLEXPRESS	9689	Server	Service Broker manager has shut down.
Information	8/31/2017 10:15:49 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 10:14:53 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:14:53 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 10:14:53 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server Database Services 2008 Common Core (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:14:53 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'GDR 5207 for SQL Server Database Services 2008 Common Core (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:14:48 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:14:48 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 10:14:48 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server 2014 sql_ssms (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:14:48 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'GDR 5207 for SQL Server 2014 sql_ssms (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:13:45 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 10:13:45 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 10:13:45 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: GDR 5207 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4019093). Installation success or error status: 0.
Information	8/31/2017 10:13:45 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'GDR 5207 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB4019093)' installed successfully.
Information	8/31/2017 10:13:14 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1642.
Information	8/31/2017 10:13:14 PM	MsiInstaller	11708	None	Product: SQL Server 2014 Database Engine Services -- Installation failed.
Information	8/31/2017 10:13:14 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.0.2000.8. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: {36E3064F-DF12-4C87-880A-FFED4731F917}. Installation success or error status: 1642.
Error	8/31/2017 10:13:14 PM	MsiInstaller	1024	None	Product: SQL Server 2014 Database Engine Services - Update '{36E3064F-DF12-4C87-880A-FFED4731F917}' could not be installed. Error code 1642. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
Information	8/31/2017 10:12:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 10:12:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:49:00Z. Reason: GVLK.
Information	8/31/2017 10:06:59 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 10:06:59 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 10:06:59 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 10:06:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 9:27:43 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f463842-8e65-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/31/2017 9:01:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 9:01:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:30Z. Reason: GVLK.
Information	8/31/2017 8:56:30 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 8:56:30 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 8:56:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 8:56:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 8:50:52 PM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8639.0000.
Information	8/31/2017 8:46:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:46:23 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:23 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 8:46:21 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/31/2017 8:46:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/31/2017 8:46:21 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/31/2017 8:46:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 8:46:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 8:46:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:17 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 16324 at 8/31/2017 8:46:06 PM (local) 8/31/2017 3:16:06 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 10804.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 8:46:16 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2) (KB3171021) - 12.0.5000.0 (X64) 
	Jun 17 2016 19:14:09 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/31/2017 8:46:10 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/31/2017 8:46:10 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the SQLAgent$SQLEXPRESS (SQL Server Agent (SQLEXPRESS)) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/31/2017 8:46:06 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 8:46:05 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 8:46:05 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:04 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 8:46:04 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 8:46:04 PM	MSSQL$SQLEXPRESS	919	Server	User 'sa' is changing database script level entry 17 to a value of 500.
Information	8/31/2017 8:46:04 PM	MSSQL$SQLEXPRESS	919	Server	User 'sa' is changing database script level entry 15 to a value of 500.
Information	8/31/2017 8:46:03 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:03 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:02 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:46:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:45:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 8:45:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:57Z. Reason: GVLK.
Information	8/31/2017 8:45:52 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:51 PM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 4606, server process ID (SPID) 11. This is an informational message only; no user action is required.
Information	8/31/2017 8:45:51 PM	MSSQL$SQLEXPRESS	17550	Server	DBCC TRACEON 4606, server process ID (SPID) 11. This is an informational message only; no user action is required.
Information	8/31/2017 8:45:33 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:33 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:27 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:27 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:26 PM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 4606, server process ID (SPID) 11. This is an informational message only; no user action is required.
Information	8/31/2017 8:45:26 PM	MSSQL$SQLEXPRESS	17550	Server	DBCC TRACEON 4606, server process ID (SPID) 11. This is an informational message only; no user action is required.
Information	8/31/2017 8:45:24 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:24 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:18 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'Agent XPs' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:45:18 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:44:49 PM	MSSQL$SQLEXPRESS	5084	Server	Setting database option RECOVERY to SIMPLE for database 'msdb'.
Information	8/31/2017 8:44:49 PM	MSSQL$SQLEXPRESS	5084	Server	Setting database option TRUSTWORTHY to ON for database 'msdb'.
Information	8/31/2017 8:44:45 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:44:44 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 1 to 0. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:44:42 PM	MSSQL$SQLEXPRESS	17551	Server	DBCC TRACEOFF 1717, server process ID (SPID) 11. This is an informational message only; no user action is required.
Information	8/31/2017 8:44:30 PM	MSSQL$SQLEXPRESS	15457	Server	Configuration option 'allow updates' changed from 0 to 1. Run the RECONFIGURE statement to install.
Information	8/31/2017 8:44:30 PM	MSSQL$SQLEXPRESS	5084	Server	Setting database option COMPATIBILITY_LEVEL to 120 for database 'msdb'.
Information	8/31/2017 8:44:29 PM	MSSQL$SQLEXPRESS	5084	Server	Setting database option COMPATIBILITY_LEVEL to 100 for database 'msdb'.
Information	8/31/2017 8:44:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:44:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:44:20 PM	MSSQL$SQLEXPRESS	8128	Server	Using 'xprepl.dll' version '2014.120.5000' to execute extended stored procedure 'xp_repl_encrypt'. This is an informational message only; no user action is required.
Information	8/31/2017 8:44:20 PM	MSSQL$SQLEXPRESS	33090	Server	Attempting to load library 'xprepl.dll' into memory. This is an informational message only. No user action is required.
Information	8/31/2017 8:44:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:44:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:44:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/31/2017 8:43:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/31/2017 8:43:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/31/2017 8:43:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:43:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/31/2017 8:43:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/31/2017 8:43:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/31/2017 8:43:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/31/2017 8:43:47 PM	MSSQL$SQLEXPRESS	8128	Server	Using 'xpstar.dll' version '2014.120.5000' to execute extended stored procedure 'xp_instance_regread'. This is an informational message only; no user action is required.
Information	8/31/2017 8:43:47 PM	MSSQL$SQLEXPRESS	33090	Server	Attempting to load library 'xpstar.dll' into memory. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:46 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 8:43:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 8:43:43 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 8:43:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 8:43:41 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.5000. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 8:43:40 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 8:43:39 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:43:39 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:43:38 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17118	Server	Database Instant File Initialization: disabled. For security and performance considerations see the topic 'Database Instant File Initialization' in SQL Server Books Online. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 16160 at 8/31/2017 8:34:59 PM (local) 8/31/2017 3:04:59 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 16324.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 8:43:37 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 (SP2) (KB3171021) - 12.0.5000.0 (X64) 
	Jun 17 2016 19:14:09 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/31/2017 8:43:33 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the MSSQL$SQLEXPRESS (SQL Server (SQLEXPRESS)) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/31/2017 8:43:32 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the MSSQL$SQLEXPRESS (SQL Server (SQLEXPRESS)) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/31/2017 8:43:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:13:22.137311300Z.
Information	8/31/2017 8:43:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {2BA1811B-44C0-4C50-8C5A-CE68AB25ED71}. Client Process Id: 4376.
Information	8/31/2017 8:43:27 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:43:27 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 8:43:27 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:43:27 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:43:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:13:22.137311300Z.
Information	8/31/2017 8:43:23 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Client Tools -- Install started.
Information	8/31/2017 8:43:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:13:10.360489100Z.
Information	8/31/2017 8:43:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {2BA1811B-44C0-4C50-8C5A-CE68AB25ED71}. Client Process Id: 4376.
Information	8/31/2017 8:43:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {839EF29A-3055-43DC-ADCE-8E84893798D5}. Client Process Id: 4376.
Information	8/31/2017 8:43:20 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:43:20 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 8:43:20 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:43:20 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:43:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:13:10.360489100Z.
Information	8/31/2017 8:43:09 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:12:34.513074200Z.
Information	8/31/2017 8:43:10 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Management Studio -- Install started.
Information	8/31/2017 8:43:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {839EF29A-3055-43DC-ADCE-8E84893798D5}. Client Process Id: 4376.
Information	8/31/2017 8:43:09 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 4376.
Information	8/31/2017 8:43:09 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:43:09 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 8:43:09 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:43:09 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:42:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:12:34.513074200Z.
Information	8/31/2017 8:42:34 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Client Tools -- Install started.
Information	8/31/2017 8:42:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:11:30.536188300Z.
Information	8/31/2017 8:42:32 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}. Client Process Id: 4376.
Information	8/31/2017 8:42:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 4376.
Information	8/31/2017 8:42:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:42:31 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 8:42:31 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:42:31 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:41:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:11:30.536188300Z.
Information	8/31/2017 8:41:30 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Management Studio -- Install started.
Information	8/31/2017 8:41:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:11:02.158704100Z.
Information	8/31/2017 8:41:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {75A54138-3B98-4705-92E4-F619825B121F}. Client Process Id: 4376.
Information	8/31/2017 8:41:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {5082A9F3-AEE5-4639-9BA7-C19661BA7331}. Client Process Id: 4376.
Information	8/31/2017 8:41:23 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:41:23 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Services -- Configuration completed successfully.
Information	8/31/2017 8:41:23 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:41:23 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:41:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:11:02.158704100Z.
Information	8/31/2017 8:41:02 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Services -- Install started.
Information	8/31/2017 8:40:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {5082A9F3-AEE5-4639-9BA7-C19661BA7331}. Client Process Id: 4376.
Information	8/31/2017 8:40:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 8:40:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 8:40:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 8:40:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:10:44.849898300Z.
Information	8/31/2017 8:40:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {D1B847A9-B06B-4264-9EF0-78E6E1571E65}. Client Process Id: 4376.
Information	8/31/2017 8:40:55 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:40:55 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	8/31/2017 8:40:55 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:40:55 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:40:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 8:40:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:10:44.849898300Z.
Information	8/31/2017 8:40:45 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Shared -- Install started.
Information	8/31/2017 8:40:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {D1B847A9-B06B-4264-9EF0-78E6E1571E65}. Client Process Id: 4376.
Information	8/31/2017 8:40:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:10:10.541194000Z.
Information	8/31/2017 8:40:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 4376.
Information	8/31/2017 8:40:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:40:43 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Services -- Configuration completed successfully.
Information	8/31/2017 8:40:43 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:40:43 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:40:10 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:10:10.541194000Z.
Information	8/31/2017 8:40:10 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Services -- Install started.
Information	8/31/2017 8:40:08 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:34.962870700Z.
Information	8/31/2017 8:40:08 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {17531BCD-C627-46A2-9F1E-7CC920E0E94A}. Client Process Id: 4376.
Information	8/31/2017 8:40:08 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {ACC530B8-B6B4-40D6-B59B-152468CF47D0}. Client Process Id: 4376.
Information	8/31/2017 8:40:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:40:08 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	8/31/2017 8:40:08 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:40:08 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:39:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:34.962870700Z.
Information	8/31/2017 8:39:35 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Database Engine Shared -- Install started.
Information	8/31/2017 8:39:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:31.331960300Z.
Information	8/31/2017 8:39:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:23.868200100Z.
Information	8/31/2017 8:39:34 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {ACC530B8-B6B4-40D6-B59B-152468CF47D0}. Client Process Id: 4376.
Information	8/31/2017 8:39:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SqlDom.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:33 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Transact-SQL ScriptDom . Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:39:33 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Transact-SQL ScriptDom  -- Installation completed successfully.
Information	8/31/2017 8:39:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:31.331960300Z.
Information	8/31/2017 8:39:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:23.868200100Z.
Information	8/31/2017 8:39:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:19.674458600Z.
Information	8/31/2017 8:39:23 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:16.037550000Z.
Information	8/31/2017 8:39:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SqlDom.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\x64\setup\RsFx.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:22 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 RsFx Driver. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:39:22 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 RsFx Driver -- Installation completed successfully.
Information	8/31/2017 8:39:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:19.674458600Z.
Information	8/31/2017 8:39:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:16.037550000Z.
Information	8/31/2017 8:39:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:09:11.886795600Z.
Information	8/31/2017 8:39:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\x64\setup\RsFx.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:15 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\sql_common_core_loc_msi\sql_common_core_loc.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:15 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:39:15 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 8:39:15 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:39:15 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:39:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:09:11.886795600Z.
Information	8/31/2017 8:39:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:44.224096900Z.
Information	8/31/2017 8:39:12 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Common Files -- Install started.
Information	8/31/2017 8:39:11 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\sql_common_core_loc_msi\sql_common_core_loc.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\x64\setup\sql_common_core_msi\sql_common_core.msi. Client Process Id: 4376.
Information	8/31/2017 8:39:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:39:11 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 8:39:11 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:39:11 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:38:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:44.224096900Z.
Information	8/31/2017 8:38:44 PM	MsiInstaller	11724	None	Product: SQL Server 2014 Common Files -- Install started.
Information	8/31/2017 8:38:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:38.191907100Z.
Information	8/31/2017 8:38:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:31.359957300Z.
Information	8/31/2017 8:38:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\x64\setup\sql_common_core_msi\sql_common_core.msi. Client Process Id: 4376.
Information	8/31/2017 8:38:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SQLSysClrTypes.msi. Client Process Id: 4376.
Information	8/31/2017 8:38:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft System CLR Types for SQL Server 2014 (x64). Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:38:42 PM	MsiInstaller	11707	None	Product: Microsoft System CLR Types for SQL Server 2014 (x64) -- Installation completed successfully.
Information	8/31/2017 8:38:38 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:38.191907100Z.
Information	8/31/2017 8:38:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:31.359957300Z.
Information	8/31/2017 8:38:30 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:28.223898400Z.
Information	8/31/2017 8:38:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SQLSysClrTypes.msi. Client Process Id: 4376.
Information	8/31/2017 8:38:30 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6476DB81-F263-4C04-8574-AAD31136C304}. Client Process Id: 4376.
Information	8/31/2017 8:38:30 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Sql Server Customer Experience Improvement Program. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:38:30 PM	MsiInstaller	11728	None	Product: Sql Server Customer Experience Improvement Program -- Configuration completed successfully.
Information	8/31/2017 8:38:30 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Sql Server Customer Experience Improvement Program. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Sql Server Customer Experience Improvement Program (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:38:30 PM	MsiInstaller	1022	None	Product: Sql Server Customer Experience Improvement Program - Update 'Service Pack 2 for Sql Server Customer Experience Improvement Program (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:38:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:28.223898400Z.
Information	8/31/2017 8:38:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6476DB81-F263-4C04-8574-AAD31136C304}. Client Process Id: 4376.
Information	8/31/2017 8:38:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:24.914891400Z.
Information	8/31/2017 8:38:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {3204DE95-97D2-4261-A286-98A262E171D4}. Client Process Id: 4376.
Information	8/31/2017 8:38:27 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:38:27 PM	MsiInstaller	11728	None	Product: SQL Server Browser for SQL Server 2014 -- Configuration completed successfully.
Information	8/31/2017 8:38:27 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Microsoft SQL Server Browser (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:38:27 PM	MsiInstaller	1022	None	Product: SQL Server Browser for SQL Server 2014 - Update 'Service Pack 2 for Microsoft SQL Server Browser (KB3171021)' installed successfully.
Information	8/31/2017 8:38:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:24.914891400Z.
Information	8/31/2017 8:38:24 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:17.393148600Z.
Information	8/31/2017 8:38:24 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {3204DE95-97D2-4261-A286-98A262E171D4}. Client Process Id: 4376.
Information	8/31/2017 8:38:24 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {366CD715-2FF4-40B4-A8B4-A05E5D21A945}. Client Process Id: 4376.
Information	8/31/2017 8:38:24 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:38:24 PM	MsiInstaller	11728	None	Product: Microsoft VSS Writer for SQL Server 2014 -- Configuration completed successfully.
Information	8/31/2017 8:38:24 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Microsoft SQL Server VSS Writer (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:38:24 PM	MsiInstaller	1022	None	Product: Microsoft VSS Writer for SQL Server 2014 - Update 'Service Pack 2 for Microsoft SQL Server VSS Writer (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:38:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:17.393148600Z.
Information	8/31/2017 8:38:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {366CD715-2FF4-40B4-A8B4-A05E5D21A945}. Client Process Id: 4376.
Information	8/31/2017 8:38:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:08:09.872405500Z.
Information	8/31/2017 8:38:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:56.416443500Z.
Information	8/31/2017 8:38:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 4376.
Information	8/31/2017 8:38:16 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Transact-SQL Compiler Service . Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:38:16 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Transact-SQL Compiler Service  -- Installation completed successfully.
Information	8/31/2017 8:38:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:08:09.872405500Z.
Information	8/31/2017 8:37:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:56.416443500Z.
Information	8/31/2017 8:37:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:53.913194700Z.
Information	8/31/2017 8:37:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:30.316275900Z.
Information	8/31/2017 8:37:56 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\sqlls.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:55 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Express LocalDB . Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:37:55 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Express LocalDB  -- Installation completed successfully.
Information	8/31/2017 8:37:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:53.913194700Z.
Information	8/31/2017 8:37:30 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:30.316275900Z.
Information	8/31/2017 8:37:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:28.516815900Z.
Information	8/31/2017 8:37:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:26.392453400Z.
Information	8/31/2017 8:37:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:28.516815900Z.
Information	8/31/2017 8:37:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\SqlLocalDB.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\msodbcsql.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:29 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft ODBC Driver 11 for SQL Server. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:37:29 PM	MsiInstaller	11707	None	Product: Microsoft ODBC Driver 11 for SQL Server -- Installation completed successfully.
Information	8/31/2017 8:37:26 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:26.392453400Z.
Information	8/31/2017 8:37:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\msodbcsql.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:24.721954700Z.
Information	8/31/2017 8:37:25 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:07:17.192410000Z.
Information	8/31/2017 8:37:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:24.721954700Z.
Information	8/31/2017 8:37:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\sqlncli.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:25 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2012 Native Client . Product Version: 11.2.5643.3. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:37:25 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2012 Native Client  -- Installation completed successfully.
Information	8/31/2017 8:37:17 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:07:17.192410000Z.
Information	8/31/2017 8:37:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\x64\sqlncli.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:06:03.622053700Z.
Information	8/31/2017 8:37:16 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎31T15:05:22.700962000Z.
Information	8/31/2017 8:37:16 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 4376.
Information	8/31/2017 8:37:16 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Microsoft SQL Server 2014 Setup (English). Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:37:16 PM	MsiInstaller	11707	None	Product: Microsoft SQL Server 2014 Setup (English) -- Installation completed successfully.
Information	8/31/2017 8:36:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:06:03.622053700Z.
Information	8/31/2017 8:35:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎31T15:05:22.700962000Z.
Information	8/31/2017 8:35:20 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files\Microsoft SQL Server\120\Setup Bootstrap\Update Cache\KB3171021\ServicePack\1033_ENU_LP\x64\setup\sqlsupport_msi\SqlSupport.msi. Client Process Id: 4376.
Information	8/31/2017 8:35:01 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/31/2017 8:34:59 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 8:34:59 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:59 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 8:34:56 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/31/2017 8:34:56 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:34:55 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17658	Server	SQL Server started in single-user mode. This an informational message only. No user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17656	Server	Warning ******************
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	1486	Server	Database Mirroring Transport is disabled in the endpoint configuration.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3528 at 8/31/2017 8:34:49 PM (local) 8/31/2017 3:04:49 PM (UTC). This is an informational message only; no user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17107	Server	Perfmon counters for resource governor pools and groups failed to initialize and are disabled.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/31/2017 8:34:54 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS""
	 -m ""SqlSetup""
	 -T 4022
	 -T 4010
	 -T 1905
	 -T 3701
	 -T 8015"
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 16160.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/31/2017 8:34:53 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/31/2017 8:34:49 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 15 user registry handles leaked from \Registry\User\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133:
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\My
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\CA
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\trust
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\TrustedPeople
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Policies\Microsoft\SystemCertificates
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\Disallowed
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\Root
Process 984 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\SystemCertificates\SmartCardRoot
"
Information	8/31/2017 8:34:49 PM	MSSQL$SQLEXPRESS	19032	Server	SQL Trace was stopped due to server shutdown. Trace ID = '1'. This is an informational message only; no user action is required.
Information	8/31/2017 8:34:49 PM	MSSQL$SQLEXPRESS	17148	Server	SQL Server is terminating in response to a 'stop' request from Service Control Manager. This is an informational message only. No user action is required.
Information	8/31/2017 8:34:49 PM	MSSQL$SQLEXPRESS	6527	Server	.NET Framework runtime has been stopped.
Information	8/31/2017 8:34:49 PM	MSSQL$SQLEXPRESS	9689	Server	Service Broker manager has shut down.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Sql Server Customer Experience Improvement Program. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:13 PM	MsiInstaller	11728	None	Product: Sql Server Customer Experience Improvement Program -- Configuration completed successfully.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Sql Server Customer Experience Improvement Program. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Sql Server Customer Experience Improvement Program (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1022	None	Product: Sql Server Customer Experience Improvement Program - Update 'Service Pack 2 for Sql Server Customer Experience Improvement Program (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:13 PM	MsiInstaller	11728	None	Product: SQL Server Browser for SQL Server 2014 -- Configuration completed successfully.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server Browser for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Microsoft SQL Server Browser (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:13 PM	MsiInstaller	1022	None	Product: SQL Server Browser for SQL Server 2014 - Update 'Service Pack 2 for Microsoft SQL Server Browser (KB3171021)' installed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	11728	None	Product: Microsoft VSS Writer for SQL Server 2014 -- Configuration completed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Microsoft VSS Writer for SQL Server 2014. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for Microsoft SQL Server VSS Writer (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1022	None	Product: Microsoft VSS Writer for SQL Server 2014 - Update 'Service Pack 2 for Microsoft SQL Server VSS Writer (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Common Files -- Configuration completed successfully.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Common Files. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:12 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Common Files - Update 'Service Pack 2 for SQL Server Database Services 2008 Common Core (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:34:08 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:08 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 8:34:08 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:08 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:34:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:34:06 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Management Studio -- Configuration completed successfully.
Information	8/31/2017 8:34:06 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Management Studio. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:34:06 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Management Studio - Update 'Service Pack 2 for SQL Server 2014 sql_ssms (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:33:44 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 8:33:44 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:44 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:33:43 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Client Tools -- Configuration completed successfully.
Information	8/31/2017 8:33:43 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Client Tools. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:43 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Client Tools - Update 'Service Pack 2 for SQL Server Tools and Workstation Components 2008 (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:33:31 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/31/2017 8:33:31 PM	MsiInstaller	11728	None	Product: SQL Server 2014 Database Engine Shared -- Configuration completed successfully.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Shared. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:31 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Shared - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Shared (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:13 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:33:13 PM	MsiInstaller	11707	None	Product: SQL Server 2014 Database Engine Services -- Installation completed successfully.
Information	8/31/2017 8:33:13 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:13 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:33:12 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0.
Information	8/31/2017 8:33:12 PM	MsiInstaller	11707	None	Product: SQL Server 2014 Database Engine Services -- Installation completed successfully.
Information	8/31/2017 8:33:12 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: SQL Server 2014 Database Engine Services. Product Version: 12.2.5000.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Update Name: Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021). Installation success or error status: 0.
Information	8/31/2017 8:33:12 PM	MsiInstaller	1022	None	Product: SQL Server 2014 Database Engine Services - Update 'Service Pack 2 for SQL Server Database Services 2008 Core Instance (64-bit) (KB3171021)' installed successfully.
Information	8/31/2017 8:31:30 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 8:31:30 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:27Z. Reason: GVLK.
Information	8/31/2017 8:26:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 8:26:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 8:26:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 8:26:22 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 8:20:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 8:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 7:49:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 7:34:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 7:19:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 7:14:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2017 7:14:43 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/31/2017 7:14:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2017 7:04:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 6:48:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 6:33:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 6:18:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 6:03:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 5:48:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 5:33:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 5:17:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 5:02:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 4:47:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 4:32:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 4:26:57 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1b1fe9a1-8e3b-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/31/2017 4:17:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 4:02:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 3:46:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 3:31:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 3:16:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 3:14:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2017 3:14:40 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/31/2017 3:14:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/31/2017 3:01:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 2:46:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 2:31:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 2:15:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 2:07:07 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/31/2017 2:00:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 1:45:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 1:33:01 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/31/2017 1:32:59 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/31/2017 1:30:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 1:15:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 12:59:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 12:57:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8639.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	8/31/2017 12:44:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 12:29:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 12:14:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 11:59:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 11:48:33 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 11:48:33 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:32Z. Reason: GVLK.
Information	8/31/2017 11:44:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 11:43:32 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 11:43:32 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 11:43:32 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 11:43:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 11:42:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d15cc99-8e13-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/31/2017 11:42:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d15cc98-8e13-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/31/2017 11:42:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6d15cc97-8e13-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/31/2017 11:32:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 19, Compared: 11993, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/31/2017 11:30:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/31/2017 11:28:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/31/2017 11:27:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 550851c6-8e11-11e7-a52c-80000bd6758f
Report Status: 0"
Error	8/31/2017 11:27:47 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/31/2017 11:24:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/31/2017 11:24:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-09-07T05:48:25Z. Reason: GVLK.
Information	8/31/2017 11:19:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 11:19:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 11:19:24 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/08/31 05:49"
Information	8/31/2017 11:19:23 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/31 05:49, 0, 1, 249000, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/31/2017 11:19:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/31/2017 11:17:05 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/31/2017 11:15:34 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/31/2017 11:14:19 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/31/2017 11:14:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 11:14:19 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 11:14:18 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 11:14:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/31/2017 11:14:18 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/31/2017 11:14:17 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/31/2017 11:14:09 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/31/2017 11:14:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/31/2017 11:14:07 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24881)(?)])(1 )(2 )]

"
Information	8/31/2017 11:14:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24881)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/31/2017 11:14:06 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/31/2017 11:14:06 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/31/2017 11:14:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/31/2017 11:13:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 9:56:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 9:41:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 9:40:56 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2017 9:40:56 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:56Z. Reason: GVLK.
Information	8/30/2017 9:35:56 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2017 9:35:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250560)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2017 9:35:56 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2017 9:35:55 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2017 9:25:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 8:41:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 8:26:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 8:12:00 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/30/2017 8:11:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 8:05:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/30/2017 7:55:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 7:47:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 62a1fc6f-8d29-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/30/2017 7:40:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 7:25:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 7:11:21 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/30/2017 7:10:40 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/30/2017 7:10:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 6:55:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 6:40:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 6:34:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2017 6:34:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:59Z. Reason: GVLK.
Information	8/30/2017 6:28:59 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2017 6:28:59 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2017 6:28:59 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2017 6:28:57 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2017 6:24:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 6:18:55 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/30/2017 6:09:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 5:54:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 5:41:43 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/30/2017 5:39:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26659)(?)])(1 )(2 )]

"
Information	8/30/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 26659)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/30/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/30/2017 5:24:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 5:09:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 4:53:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 4:41:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2017 4:41:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:42Z. Reason: GVLK.
Information	8/30/2017 4:38:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 4:36:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2017 4:36:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2017 4:36:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2017 4:36:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2017 4:36:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3b34441-8d0e-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/30/2017 4:36:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3b34440-8d0e-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/30/2017 4:36:35 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b3b3443f-8d0e-11e7-a52c-80000bd6758f
Report Status: 0"
Error	8/30/2017 4:34:26 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/30/2017 4:33:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/30/2017 4:33:05 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:04Z. Reason: GVLK.
Error	8/30/2017 4:27:28 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/30/2017 4:27:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/30/2017 4:27:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/30/2017 4:27:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/30/2017 4:27:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/30/2017 4:23:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 4:08:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 4:05:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/30/2017 3:53:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 3:37:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 3:22:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 3:07:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 2:52:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 2:47:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7775332f-8cff-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/30/2017 2:37:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 2:22:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 2:06:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 1:51:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 1:36:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 1:21:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 1:06:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 12:51:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 12:35:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 12:20:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 12:05:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/30/2017 12:05:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/29/2017 11:50:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:35:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:28:36 PM	Desktop Window Manager	9014	None	The Desktop Window Manager did not start because necessary data required to verify starting was not available
Information	8/29/2017 11:20:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:04:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:49:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:34:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:19:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:04:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:49:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:47:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8c99b82e-8cd5-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 9:33:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:18:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:03:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:48:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:33:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:18:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:05:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 8:02:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:47:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:32:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:17:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:02:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:47:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:42:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 6:42:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:00Z. Reason: GVLK.
Information	8/29/2017 6:37:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 6:37:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 6:37:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 6:36:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 6:31:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:16:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:01:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:46:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:31:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:15:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:00:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:46:24 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7d85c624-8cab-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 4:45:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:30:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:15:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:12:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 4:12:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:01Z. Reason: GVLK.
Information	8/29/2017 4:07:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 4:07:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 4:07:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 4:06:58 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 4:05:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 4:00:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:44:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:39:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 3:39:58 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:58Z. Reason: GVLK.
Information	8/29/2017 3:34:58 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 3:34:58 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 3:34:58 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 3:34:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 3:29:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:14:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:59:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:54:44 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12936.
Information	8/29/2017 2:54:44 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	8/29/2017 2:54:44 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	8/29/2017 2:54:44 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (17.012.20098). Installation success or error status: 0.
Information	8/29/2017 2:54:44 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (17.012.20098)' installed successfully.
Information	8/29/2017 2:54:38 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/29/2017 2:54:19 PM	ESENT	102	General	Windows (12216) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/29/2017 2:54:13 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/29/2017 2:54:13 PM	ESENT	103	General	Windows (3104) Windows: The database engine stopped the instance (0).
Information	8/29/2017 2:54:09 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 12936.
Information	8/29/2017 2:54:04 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 7856.
Information	8/29/2017 2:54:04 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20098. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	8/29/2017 2:54:04 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	8/29/2017 2:53:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 7856.
Information	8/29/2017 2:44:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:29:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:13:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:58:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:43:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:28:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:27:21 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/29/2017 1:27:20 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/29/2017 1:13:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:58:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:56:08 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/29/2017 12:42:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:27:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:12:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:05:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 12:05:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 11:57:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:46:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9392cb8c-8c81-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 11:42:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:27:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:16:35 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/29/2017 11:11:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 11:05:02 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/29/2017 10:56:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:41:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:26:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 10:11:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:56:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:40:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:25:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 9:10:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:55:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:40:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:25:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:09:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 8:05:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 8:04:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 7:54:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:39:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:24:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 7:09:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:54:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:46:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a796b125-8c57-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 6:38:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:23:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 6:08:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:53:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:51:58 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/29/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 5:38:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/29/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28099)(?)])(1 )(2 )]

"
Information	8/29/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28099)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/29/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 5:23:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 5:07:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:52:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:37:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:36:44 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 4:36:44 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:44Z. Reason: GVLK.
Information	8/29/2017 4:31:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 4:31:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 4:31:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 4:31:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 4:31:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2c45334-8c44-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 4:31:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2c45333-8c44-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 4:31:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d2c45332-8c44-11e7-a52c-80000bd6758f
Report Status: 0"
Error	8/29/2017 4:28:27 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/29/2017 4:25:59 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 4:25:59 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:59Z. Reason: GVLK.
Information	8/29/2017 4:22:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	8/29/2017 4:19:18 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/29/2017 4:19:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 4:19:02 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 4:19:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 4:18:59 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 4:07:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 4:05:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 4:04:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 3:51:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:47:55 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 3:42:55 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/29/2017 3:42:55 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 3:42:54 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 3:36:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:21:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 3:06:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:51:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:36:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:20:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 2:05:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:50:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:46:11 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bb4ad99a-8c2d-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/29/2017 1:35:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:20:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:05:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/29/2017 1:05:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:08Z. Reason: GVLK.
Information	8/29/2017 1:05:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 1:00:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/29/2017 1:00:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252540)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/29/2017 1:00:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/29/2017 1:00:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/29/2017 12:49:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:34:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:19:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:04:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 12:04:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/29/2017 12:04:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/29/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/28/2017 11:49:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:34:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:18:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:03:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 10:48:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 10:33:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 10:18:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 10:02:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 9:47:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 9:32:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 9:17:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 9:02:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 8:47:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 8:46:05 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cf0f4b7a-8c03-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/28/2017 8:31:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 8:16:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 8:04:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2017 8:04:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/28/2017 8:04:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2017 8:01:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 7:46:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 7:31:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 7:16:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 7:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 6:45:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 6:30:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 6:27:17 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 6:23:51 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/28/2017 6:22:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 6:22:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28773)(?)])(1 )(2 )]

"
Information	8/28/2017 6:22:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 28773)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 6:22:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2017 6:22:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 6:22:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 6:15:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 6:00:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 5:45:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 5:29:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 5:14:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 4:59:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 4:44:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 4:29:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 4:14:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 4:04:05 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2017 4:04:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2017 4:03:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2017 3:58:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 3:46:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e3fe2bf4-8bd9-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/28/2017 3:43:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 3:28:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 3:13:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 2:58:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 2:50:17 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/28/2017 2:50:09 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/28/2017 2:43:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 2:28:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 2:12:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 1:57:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 1:42:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 1:27:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 1:17:54 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/28/2017 1:17:51 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/28/2017 1:12:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 12:56:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 12:41:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 12:26:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 12:18:53 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/28/2017 12:12:42 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 12:11:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 12:08:44 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 28, Deleted: 0, Modified: 0, Compared: 11859, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/28/2017 12:07:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 12:07:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29148)(?)])(1 )(2 )]

"
Information	8/28/2017 12:07:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29148)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 12:06:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 12:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29148)(?)])(1 )(2 )]

"
Information	8/28/2017 12:06:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29148)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 12:04:26 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 15

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 16

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 16

Information	8/28/2017 12:03:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2017 12:02:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 12:02:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29153)(?)])(1 )(2 )]

"
Information	8/28/2017 12:02:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29153)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 12:01:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/28/2017 12:00:58 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/28/2017 12:00:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 12:00:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29154)(?)])(1 )(2 )]

"
Information	8/28/2017 12:00:52 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29154)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 11:56:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2017 11:56:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 11:56:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 11:56:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:53:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 11:53:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:03Z. Reason: GVLK.
Information	8/28/2017 11:48:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2017 11:48:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 11:48:02 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 11:48:01 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 11:47:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 922858f9-8bb8-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/28/2017 11:47:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 922858f8-8bb8-11e7-a52c-80000bd6758f
Report Status: 0"
Information	8/28/2017 11:47:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: <<PROCESS>>: CompatTelRunner.ex
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 922858f7-8bb8-11e7-a52c-80000bd6758f
Report Status: 0"
Error	8/28/2017 11:44:17 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/28/2017 11:40:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	8/28/2017 11:39:26 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/28/2017 11:31:19 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 11:26:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2017 11:26:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 11:26:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 11:25:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:10:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/28/2017 11:10:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/28/2017 11:10:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/28/2017 11:10:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/28/2017 11:10:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/28/2017 11:10:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/28/2017 11:10:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/28/2017 11:10:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Error	8/28/2017 11:10:14 AM	SideBySide	63	None	"Activation context generation failed for ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"".Error in manifest or policy file ""c:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\CopyDatabaseWizard.exe"" on line 8. The value ""1.0"" of attribute ""version"" in element ""assemblyIdentity"" is invalid."
Information	8/28/2017 11:03:45 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 11:03:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:44Z. Reason: GVLK.
Information	8/28/2017 11:01:16 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 10:58:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2017 10:58:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 10:58:44 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 10:58:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/28/2017 10:56:43 AM	SideBySide	59	None	"Activation context generation failed for ""c:\users\212558710\documents\visual studio 2015\projects\webapi_sut\webapi_sut\bin\roslyn\vbcscompiler.exe"".Error in manifest or policy file ""c:\users\212558710\documents\visual studio 2015\projects\webapi_sut\webapi_sut\bin\roslyn\vbcscompiler.exe.Config"" on line 0. Invalid Xml syntax."
Information	8/28/2017 10:56:01 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/28/2017 10:56:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:00Z. Reason: GVLK.
Error	8/28/2017 10:55:47 AM	SideBySide	35	None	"Activation context generation failed for ""c:\program files (x86)\microsoft office\root\office16\lync.exe.Manifest"".Error in manifest or policy file ""c:\program files (x86)\microsoft office\root\office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/28/2017 10:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/28/2017 10:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29222)(?)])(1 )(2 )]

"
Information	8/28/2017 10:53:25 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29222)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 10:53:09 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/28/2017 10:53:09 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 10:53:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 10:44:06 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/28/2017 10:42:39 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/28/2017 10:42:38 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/28/2017 10:42:38 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/28/2017 10:42:37 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/28/2017 10:42:33 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8633.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/28/2017 10:42:25 AM	ESENT	302	Logging/Recovery	Windows (3104) Windows: The database engine has successfully completed recovery steps.
Information	8/28/2017 10:42:25 AM	ESENT	301	Logging/Recovery	Windows (3104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/28/2017 10:42:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/28/2017 10:42:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/28/2017 10:42:11 AM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	8/28/2017 10:42:09 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/28/2017 10:42:08 AM	ESENT	301	Logging/Recovery	Windows (3104) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03D3B.log.
Information	8/28/2017 10:42:08 AM	ESENT	300	Logging/Recovery	Windows (3104) Windows: The database engine is initiating recovery steps.
Information	8/28/2017 10:42:08 AM	ESENT	102	General	Windows (3104) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/28/2017 10:42:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/28/2017 10:42:04 AM	Service1	0	None	Service started successfully.
Error	8/28/2017 10:41:42 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/28/2017 10:41:40 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/28/2017 10:41:20 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/28/2017 10:41:10 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/28/2017 10:41:07 AM	PostgreSQL	0	None	"2017-08-28 10:41:07 IST LOG:  redirecting log output to logging collector process
2017-08-28 10:41:07 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/28/2017 10:41:07 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/28/2017 10:41:06 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/28/2017 10:41:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/28/2017 10:41:00 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/28/2017 10:41:00 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/28/2017 10:41:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/28/2017 10:41:00 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/28/2017 10:40:58 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/28/2017 10:40:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/28/2017 10:40:57 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/28/2017 10:40:56 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/28/2017 10:40:55 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/28/2017 10:40:55 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/28/2017 10:40:55 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/28/2017 10:40:53 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3640 at 8/26/2017 11:48:55 PM (local) 8/26/2017 6:18:55 PM (UTC). This is an informational message only; no user action is required.
Warning	8/28/2017 10:40:51 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/28/2017 10:40:51 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/28/2017 10:40:51 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/28/2017 10:40:51 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/28/2017 10:40:51 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/28/2017 10:40:51 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3528.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/28/2017 10:40:50 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/28/2017 10:40:41 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/28/2017 10:40:36 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/26/2017 11:49:02 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	8/28/2017 10:40:36 AM	Microsoft-Windows-Winlogon	6003	None	The winlogon notification subscriber <TrustedInstaller> was unavailable to handle a critical notification event.
Information	8/28/2017 10:40:36 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/28/2017 10:40:36 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/26/2017 11:48:55 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/26/2017 11:48:55 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	8/26/2017 11:48:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:48:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8633.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Warning	8/26/2017 11:48:32 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 200 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1712 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/26/2017 11:48:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/26/2017 11:48:31 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/26/2017 11:48:31 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/26/2017 11:48:27 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	8/26/2017 11:48:27 PM	RasClient	20226	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 631.
Information	8/26/2017 11:33:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:18:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:03:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 10:51:37 PM	RasClient	20225	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.225.112
TunnelIpv6Address = None
Dial-in User = .
Information	8/26/2017 10:51:31 PM	RasClient	20224	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	8/26/2017 10:51:31 PM	RasClient	20223	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	8/26/2017 10:51:31 PM	RasClient	20222	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	8/26/2017 10:51:31 PM	RasClient	20221	None	CoId={66AE3263-8A65-47B6-80ED-DD26D9E52512}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	8/26/2017 10:48:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 7:10:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 7:08:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 7:07:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c568f724-8a63-11e7-9987-80000bd6758f
Report Status: 0"
Information	8/26/2017 7:03:10 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 7:03:10 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 7:03:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 6:55:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 6:40:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 6:38:09 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 6:33:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 6:33:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 6:33:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 6:25:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 6:10:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 6:08:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 6:03:11 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 6:03:11 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 6:03:10 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 5:53:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 5:53:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:10Z. Reason: GVLK.
Information	8/26/2017 5:51:24 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2017 5:50:50 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\microsoft vs code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8633.0000.
Information	8/26/2017 5:50:03 PM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8633.0000.
Information	8/26/2017 5:49:58 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/26/2017 5:49:24 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/26/2017 5:49:08 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 5:49:05 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 5:49:04 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 5:48:51 PM	ESENT	302	Logging/Recovery	Windows (7744) Windows: The database engine has successfully completed recovery steps.
Information	8/26/2017 5:48:50 PM	ESENT	301	Logging/Recovery	Windows (7744) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/26/2017 5:48:45 PM	ESENT	301	Logging/Recovery	Windows (7744) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03D3A.log.
Information	8/26/2017 5:48:45 PM	ESENT	300	Logging/Recovery	Windows (7744) Windows: The database engine is initiating recovery steps.
Information	8/26/2017 5:48:43 PM	ESENT	102	General	Windows (7744) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/26/2017 5:47:52 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/26/2017 5:47:52 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/26/2017 5:47:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/26/2017 5:47:51 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/26/2017 5:47:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2017 5:47:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2017 5:47:12 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	8/26/2017 5:47:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	8/26/2017 5:47:06 PM	Microsoft-Windows-WMI	63	None	A provider, InvProv, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Warning	8/26/2017 5:47:06 PM	Microsoft-Windows-WMI	63	None	A provider, InvProv, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Error	8/26/2017 5:47:06 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/26/2017 5:47:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/26/2017 5:47:01 PM	PostgreSQL	0	None	Timed out waiting for server startup

Information	8/26/2017 5:46:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8633.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/26/2017 5:46:46 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/26/2017 5:46:45 PM	Service1	0	None	Service started successfully.
Information	8/26/2017 5:46:43 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/26/2017 5:46:40 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/26/2017 5:46:40 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/26/2017 5:46:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/26/2017 5:46:32 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/26/2017 5:46:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/26/2017 5:46:30 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:30 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database JPAdemo (database ID 11) in 1 second(s) (analysis 108 ms, redo 0 ms, undo 474 ms.) This is an informational message only. No user action is required.
Information	8/26/2017 5:46:30 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:30 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:29 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/26/2017 5:46:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/26/2017 5:46:27 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/26/2017 5:46:26 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/26/2017 5:46:25 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/26/2017 5:46:24 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/26/2017 5:46:23 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/26/2017 5:46:23 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Error	8/26/2017 5:46:21 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/26/2017 5:46:19 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/26/2017 5:46:17 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:17 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:17 PM	MSSQL$SQLEXPRESS	3406	Server	44 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/26/2017 5:46:17 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/26/2017 5:46:16 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/26/2017 5:46:16 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/26/2017 5:46:16 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/26/2017 5:46:16 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3960 at 8/26/2017 10:16:33 AM (local) 8/26/2017 4:46:33 AM (UTC). This is an informational message only; no user action is required.
Information	8/26/2017 5:46:08 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/26/2017 5:46:07 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/26/2017 5:46:07 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/26/2017 5:46:07 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/26/2017 5:46:07 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/26/2017 5:45:45 PM	PostgreSQL	0	None	"2017-08-26 17:45:45 IST LOG:  redirecting log output to logging collector process
2017-08-26 17:45:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/26/2017 5:45:42 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/26/2017 5:45:41 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/26/2017 5:45:40 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3640.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/26/2017 5:45:30 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/26/2017 5:44:58 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/26/2017 5:44:25 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 5:41:01 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/26/2017 5:41:01 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/26/2017 5:41:01 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/26/2017 3:33:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 3:18:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 3:09:01 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2017 3:08:16 PM	GE Software	0	(1)	++Installation complete
Information	8/26/2017 3:08:16 PM	GE Software	0	(1)	++Installation complete with an exit code of: 0
Information	8/26/2017 3:05:10 PM	GE Software	0	(1)	++This is a Windows 7 machine. KB2952664 will now install.
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++Application Install Check Passed - Proceeding with Installation
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++Passed the Permissions Check
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++Started the installation of Microsoft Upgrade Analytics 201707 V01 with the following commandline: /Q
Information	8/26/2017 3:05:03 PM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	8/26/2017 3:05:02 PM	GE Software	0	(1)	++ Session ID: 1. Session ID Return Code: 203.
Information	8/26/2017 3:03:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 2:48:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 2:32:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 2:20:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 2:20:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:21Z. Reason: GVLK.
Information	8/26/2017 2:17:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 2:15:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2017 2:15:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2017 2:15:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 2:15:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 2:07:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: dac1ef4f-8a39-11e7-9f18-80000bd6758f
Report Status: 0"
Information	8/26/2017 2:02:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 1:47:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 1:32:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 1:17:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 1:05:51 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 1:02:57 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/26/2017 1:01:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	8/26/2017 1:00:51 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C4EB8962-B963-498D-9ADC-35F2CA72F212}
Error	8/26/2017 1:00:51 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {C4EB8962-B963-498D-9ADC-35F2CA72F212}
Information	8/26/2017 12:59:57 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/26/2017 12:59:56 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/26/2017 12:59:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/26/2017 12:59:38 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 46, Deleted: 0, Modified: 21, Compared: 11919, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/26/2017 12:58:55 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/26/2017 12:58:52 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 203

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 93

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 124

Information	8/26/2017 12:58:50 PM	RasClient	20225	None	CoId={DB0C48C7-455C-490D-ADF4-DB0B9ADBCCC1}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.243.222
TunnelIpv6Address = None
Dial-in User = .
Information	8/26/2017 12:58:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/26/2017 12:58:45 PM	RasClient	20224	None	CoId={DB0C48C7-455C-490D-ADF4-DB0B9ADBCCC1}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	8/26/2017 12:58:45 PM	RasClient	20223	None	CoId={DB0C48C7-455C-490D-ADF4-DB0B9ADBCCC1}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	8/26/2017 12:58:45 PM	RasClient	20222	None	CoId={DB0C48C7-455C-490D-ADF4-DB0B9ADBCCC1}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	8/26/2017 12:58:45 PM	RasClient	20221	None	CoId={DB0C48C7-455C-490D-ADF4-DB0B9ADBCCC1}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	8/26/2017 12:58:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/26/2017 12:58:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31977)(?)])(1 )(2 )]

"
Information	8/26/2017 12:58:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 31977)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2017 12:58:17 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 12:58:17 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 12:58:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	8/26/2017 12:58:17 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 12:58:17 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/26/2017 12:56:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎26T07:26:47.993988700Z.
Information	8/26/2017 12:56:50 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\f5tmp\f5fpclients.msi. Client Process Id: 10192.
Information	8/26/2017 12:56:50 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: BIG-IP Edge Client. Product Version: 71.2017.0404.2206. Product Language: 1033. Manufacturer: F5 Networks, Inc.. Reconfiguration success or error status: 0.
Information	8/26/2017 12:56:50 PM	MsiInstaller	11728	None	Product: BIG-IP Edge Client -- Configuration completed successfully.
Information	8/26/2017 12:56:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎26T07:26:47.993988700Z.
Information	8/26/2017 12:56:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎26T07:26:43.695742800Z.
Information	8/26/2017 12:56:47 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\f5tmp\f5fpclients.msi. Client Process Id: 10192.
Information	8/26/2017 12:56:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\F5_MSI_TMP942242\f5fpclients.msi. Client Process Id: 10640.
Information	8/26/2017 12:56:46 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: BIG-IP Edge Client. Product Version: 71.2017.0404.2206. Product Language: 1033. Manufacturer: F5 Networks, Inc.. Reconfiguration success or error status: 0.
Information	8/26/2017 12:56:46 PM	MsiInstaller	11728	None	Product: BIG-IP Edge Client -- Configuration completed successfully.
Information	8/26/2017 12:56:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎26T07:26:43.695742800Z.
Information	8/26/2017 12:56:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\F5_MSI_TMP942242\f5fpclients.msi. Client Process Id: 10640.
Information	8/26/2017 12:56:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎08‎-‎26T07:26:37.781404600Z.
Information	8/26/2017 12:56:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\f5tmp\f5fpclients.msi. Client Process Id: 5380.
Information	8/26/2017 12:56:41 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: BIG-IP Edge Client. Product Version: 71.2017.0404.2206. Product Language: 1033. Manufacturer: F5 Networks, Inc.. Reconfiguration success or error status: 0.
Information	8/26/2017 12:56:41 PM	MsiInstaller	11728	None	Product: BIG-IP Edge Client -- Configuration completed successfully.
Information	8/26/2017 12:56:37 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎08‎-‎26T07:26:37.781404600Z.
Information	8/26/2017 12:56:37 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\f5tmp\f5fpclients.msi. Client Process Id: 5380.
Information	8/26/2017 12:46:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 12:31:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 12:16:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 12:01:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:52:33 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/26/2017 11:45:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:37:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 11:32:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 11:32:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 11:32:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 11:30:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:15:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 11:07:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 11:02:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 11:02:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 11:02:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 11:00:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 10:44:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 10:37:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 10:32:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 10:32:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 10:32:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 10:24:52 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 10:24:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:51Z. Reason: GVLK.
Information	8/26/2017 10:19:05 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/26/2017 10:18:28 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 10:18:27 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 10:18:26 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 10:18:24 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/26/2017 10:17:44 AM	ESENT	302	Logging/Recovery	Windows (2468) Windows: The database engine has successfully completed recovery steps.
Information	8/26/2017 10:17:42 AM	ESENT	301	Logging/Recovery	Windows (2468) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/26/2017 10:17:39 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/26/2017 10:17:39 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2017 10:17:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 10:17:37 AM	ESENT	301	Logging/Recovery	Windows (2468) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03D30.log.
Information	8/26/2017 10:17:37 AM	ESENT	300	Logging/Recovery	Windows (2468) Windows: The database engine is initiating recovery steps.
Information	8/26/2017 10:17:36 AM	ESENT	102	General	Windows (2468) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/26/2017 10:17:31 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 10:17:11 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8633.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/26/2017 10:17:02 AM	Service1	0	None	Service started successfully.
Information	8/26/2017 10:16:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/26/2017 10:16:50 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/26/2017 10:16:50 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/26/2017 10:16:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/26/2017 10:16:50 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Error	8/26/2017 10:16:45 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/26/2017 10:16:45 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/26/2017 10:16:42 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/26/2017 10:16:40 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/26/2017 10:16:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/26/2017 10:16:39 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:38 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/26/2017 10:16:37 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/26/2017 10:16:36 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/26/2017 10:16:36 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/26/2017 10:16:36 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/26/2017 10:16:34 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:34 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:34 AM	MSSQL$SQLEXPRESS	3406	Server	63 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:34 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3448 at 8/26/2017 9:30:10 AM (local) 8/26/2017 4:00:10 AM (UTC). This is an informational message only; no user action is required.
Information	8/26/2017 10:16:33 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/26/2017 10:16:32 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/26/2017 10:16:32 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/26/2017 10:16:32 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/26/2017 10:16:32 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/26/2017 10:16:31 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/26/2017 10:16:30 AM	PostgreSQL	0	None	"2017-08-26 10:16:30 IST LOG:  redirecting log output to logging collector process
2017-08-26 10:16:30 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/26/2017 10:16:28 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3960.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/26/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/26/2017 10:16:15 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/26/2017 10:15:47 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/26/2017 10:15:27 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/26/2017 10:15:27 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/26/2017 10:15:27 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/26/2017 9:30:16 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/26/2017 9:30:10 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	8/26/2017 9:30:05 AM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\Microsoft\Windows\UsrClass.dat has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8633.0000.
Information	8/26/2017 9:30:05 AM	McLogEvent	257	None	The scan of C:\Users\212558710\NTUSER.DAT has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8633.0000.
Warning	8/26/2017 9:29:57 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 33 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 992 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 992 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 992 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 992 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 992 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1172 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/26/2017 9:29:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/26/2017 9:29:55 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/26/2017 9:29:55 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/26/2017 9:27:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 9:07:46 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec9f8895-8a0f-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/26/2017 9:02:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/26/2017 8:59:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/26/2017 8:57:53 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/26/2017 8:57:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32217)(?)])(1 )(2 )]

"
Information	8/26/2017 8:57:52 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32217)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/26/2017 8:57:52 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/26/2017 8:57:52 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/26/2017 8:57:51 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/26/2017 8:57:38 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 249 ms, redo 68 ms, undo 377 ms.) This is an informational message only. No user action is required.
Information	8/26/2017 8:57:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/26/2017 12:21:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 11:52:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/25/2017 11:51:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 11:51:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/25/2017 11:21:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 10:51:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 10:21:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 10:06:44 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2017 10:06:44 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:43Z. Reason: GVLK.
Information	8/25/2017 10:01:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2017 10:01:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2017 10:01:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2017 10:01:43 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/25/2017 9:51:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 9:21:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 9:09:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8633.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/25/2017 8:51:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 8:21:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/25/2017 8:03:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5295eed1-89a2-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/25/2017 7:59:48 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/25/2017 7:59:48 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:46Z. Reason: GVLK.
Information	8/25/2017 7:57:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/25/2017 7:52:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/25/2017 7:52:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33003)(?)])(1 )(2 )]

"
Information	8/25/2017 7:52:40 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33003)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2017 7:52:40 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/25/2017 7:52:40 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2017 7:52:36 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/25/2017 7:52:26 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/25/2017 7:52:26 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257160)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/25/2017 7:52:25 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/25/2017 7:52:22 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/25/2017 7:52:17 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/25/2017 7:52:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954429

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/25/2017 7:52:06 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/25/2017 7:52:06 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/25/2017 7:51:47 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 102 ms, redo 138 ms, undo 303 ms.) This is an informational message only. No user action is required.
Information	8/25/2017 7:51:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:52:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:22:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/24/2017 10:22:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:29:35 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5045402d-88bb-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/24/2017 4:20:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:05:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:01:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2017 4:01:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:42Z. Reason: GVLK.
Information	8/24/2017 3:56:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2017 3:56:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 3:56:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2017 3:56:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/24/2017 3:56:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2017 3:56:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:32:15Z. Reason: GVLK.
Information	8/24/2017 3:51:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2017 3:51:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 3:51:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2017 3:51:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/24/2017 3:50:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:35:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:20:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:04:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:49:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:34:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:19:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:16:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 2:15:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 2:04:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:49:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:33:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:18:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:03:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:48:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:33:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:23:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8632.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/24/2017 12:18:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:02:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 11:47:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 11:32:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 11:28:28 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3f3b77aa-8891-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/24/2017 11:17:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 11:02:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:46:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:31:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:16:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 10:15:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 10:15:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 10:01:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 9:46:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 9:35:58 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 4, Compared: 11843, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/24/2017 9:35:14 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/24/2017 9:31:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 9:15:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 9:07:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/24/2017 9:07:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-31T03:31:47Z. Reason: GVLK.
Information	8/24/2017 9:02:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 9:02:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 9:02:46 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/08/24 03:32"
Information	8/24/2017 9:02:45 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/24 03:32, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/24/2017 9:00:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 8:57:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/24/2017 8:57:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 8:57:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2017 8:57:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/24/2017 8:56:53 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/24/2017 8:56:34 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/24/2017 8:45:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 8:30:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 8:15:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 7:59:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 7:51:44 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/24/2017 7:44:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 7:29:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 7:14:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 6:59:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 6:44:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 6:28:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 6:27:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2f1d0999-8867-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/24/2017 6:15:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 6:15:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 6:13:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 5:58:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 5:43:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 5:41:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/24/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/24/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35299)(?)])(1 )(2 )]

"
Information	8/24/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 35299)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/24/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/24/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/24/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/24/2017 5:28:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 5:13:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:57:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:42:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:27:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 4:12:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:57:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:42:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:26:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 3:11:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:56:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:41:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:26:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 2:15:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 2:15:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/24/2017 2:10:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:55:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:40:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:27:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 44dabba3-883d-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/24/2017 1:25:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 1:10:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:55:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:40:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:24:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/24/2017 12:09:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:54:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:39:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:24:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:09:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:53:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:38:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:23:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:15:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 10:15:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 10:08:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 9:53:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 9:38:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 9:34:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2017 9:34:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:42Z. Reason: GVLK.
Information	8/23/2017 9:29:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2017 9:29:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2017 9:29:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2017 9:29:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2017 9:22:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 9:07:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 8:52:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 8:37:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 8:27:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5988b11e-8813-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/23/2017 8:22:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 8:06:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 7:51:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 7:36:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 7:27:54 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/23/2017 7:21:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 7:06:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 6:51:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 6:35:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 6:20:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 6:15:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 6:15:25 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/23/2017 6:15:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 6:14:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 6:05:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 6:04:12 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/23/2017 5:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 5:35:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 5:20:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 5:04:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 4:49:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 4:34:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 4:32:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2017 4:32:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:07Z. Reason: GVLK.
Information	8/23/2017 4:27:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2017 4:27:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2017 4:27:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2017 4:27:06 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2017 4:19:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 4:04:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 3:49:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 3:33:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 3:27:13 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6f71adea-87e9-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/23/2017 3:18:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 3:03:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 2:57:12 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/23/2017 2:48:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 2:33:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 2:18:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 2:14:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 2:14:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/23/2017 2:02:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 1:47:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 1:32:27 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 414 ms, redo 0 ms, undo 1203 ms.) This is an informational message only. No user action is required.
Information	8/23/2017 1:32:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 1:17:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 1:01:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 12:46:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 12:31:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 12:16:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 12:01:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:46:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:30:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:15:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 11:09:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/23/2017 11:09:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:47Z. Reason: GVLK.
Information	8/23/2017 11:04:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/23/2017 11:04:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2017 11:04:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2017 11:04:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/23/2017 11:00:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:46:05 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8631.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/23/2017 10:45:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:30:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/23/2017 10:26:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6079c329-87bf-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/23/2017 10:20:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/23/2017 10:15:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/23/2017 10:15:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36460)(?)])(1 )(2 )]

"
Information	8/23/2017 10:15:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36460)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/23/2017 10:15:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/23/2017 10:15:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/23/2017 10:15:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/23/2017 10:15:17 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/23/2017 10:15:12 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/23/2017 10:15:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/23/2017 10:15:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/23/2017 10:15:00 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/23/2017 10:14:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/23/2017 10:14:55 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/23/2017 10:14:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 10:19:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 10:04:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:48:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:46:23 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/22/2017 9:33:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:18:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:03:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:48:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:33:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:17:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:16:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 8:16:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:15Z. Reason: GVLK.
Information	8/22/2017 8:11:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2017 8:11:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 8:11:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 8:11:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 8:02:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:47:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:35:20 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/22/2017 7:32:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:17:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:02:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:02:00 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 46075217-873e-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/22/2017 6:59:57 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 6:59:56 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/22/2017 6:59:48 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 6:46:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:31:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:16:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:01:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:46:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:30:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:15:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:12:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 5:12:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:33Z. Reason: GVLK.
Information	8/22/2017 5:07:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2017 5:07:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 5:07:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 5:07:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 5:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:45:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:30:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:15:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:59:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:44:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:29:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:14:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:59:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 2:59:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:44:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:28:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:13:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:01:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5afb0927-8714-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/22/2017 1:58:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:43:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:35:10 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 1:30:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2017 1:30:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37705)(?)])(1 )(2 )]

"
Information	8/22/2017 1:30:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37705)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 1:30:07 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2017 1:30:07 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 1:30:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 1:28:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:13:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:57:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:42:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:38:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8630.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/22/2017 12:27:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:12:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 11:57:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 11:42:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 11:26:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 11:11:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 11:04:35 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 10:59:35 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 218

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	8/22/2017 10:59:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 10:59:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2017 10:59:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37856)(?)])(1 )(2 )]

"
Information	8/22/2017 10:59:15 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37856)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 10:59:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2017 10:59:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 10:59:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 10:58:32 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/22/2017 10:58:22 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/22/2017 10:56:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 10:41:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 10:26:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 10:10:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:55:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:53:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 9:52:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 9:40:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:25:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:10:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 9:01:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6fe53c46-86ea-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/22/2017 8:55:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:40:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:24:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:11:23 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 8:11:23 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:23Z. Reason: GVLK.
Information	8/22/2017 8:09:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 8:06:23 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2017 8:06:23 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 8:06:23 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 8:06:22 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 7:54:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:39:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:24:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 7:09:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:53:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:38:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:23:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 6:08:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:53:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:53:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 5:52:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 5:41:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 5:37:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/22/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38179)(?)])(1 )(2 )]

"
Information	8/22/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38179)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 5:31:55 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/22/2017 5:22:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 5:07:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:52:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:37:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:22:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:06:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 4:00:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 621d27aa-86c0-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/22/2017 3:51:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:44:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 3:39:45 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/22/2017 3:39:45 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 3:39:44 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 3:36:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:21:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 3:06:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:51:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:35:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:20:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 2:05:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:52:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 1:52:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/22/2017 1:50:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:43:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/22/2017 1:43:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:04Z. Reason: GVLK.
Information	8/22/2017 1:38:03 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/22/2017 1:38:03 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/22/2017 1:38:03 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/22/2017 1:38:03 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/22/2017 1:35:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:20:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 1:04:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:49:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:34:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:19:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:04:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/22/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/21/2017 11:49:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:33:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:18:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:03:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:59:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53c890cf-8696-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/21/2017 10:48:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:33:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:18:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:02:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:52:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 9:52:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 9:47:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:32:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:17:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:02:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:47:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:31:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:16:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:01:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:46:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:31:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:29:46 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/21/2017 7:16:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:00:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:45:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:30:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:15:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:00:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:58:45 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 460229df-866c-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/21/2017 5:53:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/21/2017 5:52:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 5:52:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 5:51:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 5:48:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38887)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 5:48:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 38887)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 5:48:29 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/21/2017 5:48:29 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/21/2017 5:48:28 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	8/21/2017 5:48:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/21/2017 5:48:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/21/2017 5:48:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/21/2017 5:45:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:29:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:14:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:59:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:44:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:29:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:14:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:59:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:48:14 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/21/2017 3:48:14 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:13Z. Reason: GVLK.
Information	8/21/2017 3:43:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:43:13 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/21/2017 3:43:13 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 3:43:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/21/2017 3:43:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/21/2017 3:28:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:13:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:58:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:43:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:27:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:12:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:57:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:52:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 1:51:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 1:42:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:27:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:12:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:57:39 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35bdd53f-8642-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/21/2017 12:56:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:41:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:33:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8629.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/21/2017 12:26:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:24:07 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/21/2017 12:11:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:56:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:41:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:25:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 11:10:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:55:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:40:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:25:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 10:24:19 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/21/2017 10:23:59 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/21/2017 10:10:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:54:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:52:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 9:51:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 9:39:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:30:49 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 12, Compared: 11697, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/21/2017 9:30:24 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/21/2017 9:24:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 9:09:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:54:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:38:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:23:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 8:08:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:57:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 49df0a3a-8618-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/21/2017 7:53:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:38:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:23:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 7:07:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:52:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:37:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:22:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 6:07:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:51:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:51:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 5:51:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/21/2017 5:36:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/21/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39619)(?)])(1 )(2 )]

"
Information	8/21/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39619)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/21/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/21/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/21/2017 5:21:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 5:06:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:51:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:36:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:21:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 4:05:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:50:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:35:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:20:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 3:05:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:57:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5f208db1-85ee-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/21/2017 2:50:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:37:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/21/2017 2:37:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:06Z. Reason: GVLK.
Information	8/21/2017 2:34:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:32:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/21/2017 2:32:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 2:32:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/21/2017 2:32:06 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/21/2017 2:26:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/21/2017 2:26:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:06Z. Reason: GVLK.
Information	8/21/2017 2:21:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/21/2017 2:21:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 253860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/21/2017 2:21:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/21/2017 2:21:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/21/2017 2:19:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 2:04:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:51:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 1:51:29 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/21/2017 1:49:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:34:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:18:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 1:03:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:48:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:33:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:18:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:03:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/21/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/20/2017 11:48:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:32:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:17:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:02:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:47:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:32:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:17:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:01:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:57:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 751a6ea7-85c4-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/20/2017 9:51:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 9:51:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 9:51:14 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 9:46:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:31:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:16:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:01:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:45:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:30:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:21:36 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/20/2017 8:15:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:00:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:45:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:30:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:26:48 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/20/2017 7:14:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:59:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:44:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:29:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:14:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:59:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:51:31 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 5:51:29 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/20/2017 5:51:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 5:51:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 5:43:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:28:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:13:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:58:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:57:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8aefac17-859a-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/20/2017 4:43:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:28:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:12:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:57:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:42:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:27:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:12:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:57:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:41:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:26:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:11:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:56:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:51:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/20/2017 1:50:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/20/2017 1:41:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	8/20/2017 1:34:46 PM	Group Policy Shortcuts	8194	(2)	The client-side extension could not apply computer policy settings for 'GE000000000_GE008000000_OG_Link_Deployment {B24CB7AA-27DA-49A7-85DC-BE252305030B}' because it failed with error code '0x80070035 The network path was not found.' See trace file for more details.
Error	8/20/2017 1:34:42 PM	Group Policy Registry	8194	(2)	The client-side extension could not apply computer policy settings for 'Logon_Disable_IPv6_ALL {FCA4FE78-369E-42C2-9BE4-4AB7AA05E07E}' because it failed with error code '0x80070035 The network path was not found.' See trace file for more details.
Information	8/20/2017 1:25:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:10:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:56:44 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8628.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/20/2017 12:55:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:40:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:25:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:10:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:57:23 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9fdf4664-8570-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/20/2017 11:55:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:42:00 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/20/2017 11:41:52 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/20/2017 11:39:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:24:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 11:09:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:54:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:39:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:28:00 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/20/2017 10:28:00 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:26:59Z. Reason: GVLK.
Information	8/20/2017 10:23:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 10:22:58 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/20/2017 10:22:58 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/20/2017 10:22:58 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/20/2017 10:22:56 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/20/2017 10:08:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:53:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:51:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 9:50:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 9:40:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/20/2017 9:40:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:10Z. Reason: GVLK.
Information	8/20/2017 9:38:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:35:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/20/2017 9:35:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 254880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/20/2017 9:35:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/20/2017 9:35:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/20/2017 9:31:16 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/20/2017 9:31:15 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/20/2017 9:31:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/20/2017 9:30:15 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/20/2017 9:30:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/20/2017 9:30:12 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/20/2017 9:23:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 9:08:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:52:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:37:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:22:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 8:07:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:52:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:37:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:21:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 7:06:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:57:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b5d9e9dc-8546-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/20/2017 6:51:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:36:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:21:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 6:06:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:51:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 5:50:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:50:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/20/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/20/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41059)(?)])(1 )(2 )]

"
Information	8/20/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41059)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/20/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/20/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/20/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/20/2017 5:35:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:20:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:05:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 5:04:34 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/20/2017 4:59:34 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/20/2017 4:59:34 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/20/2017 4:59:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/20/2017 4:50:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:35:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:19:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 4:04:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:49:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:34:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:19:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 3:04:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:58:29 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/20/2017 2:48:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:33:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:18:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 2:03:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:57:19 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cbb9d953-851c-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/20/2017 1:50:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 1:50:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/20/2017 1:48:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:33:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:17:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 1:02:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:47:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:32:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:17:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/20/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/20/2017 12:01:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:46:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:43:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/19/2017 11:43:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:17Z. Reason: GVLK.
Information	8/19/2017 11:38:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/19/2017 11:38:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/19/2017 11:38:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/19/2017 11:38:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/19/2017 11:31:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:16:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:01:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:46:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:30:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:15:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:00:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:50:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 9:50:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 9:45:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:30:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:15:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:59:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:57:17 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e1b2cb63-84f2-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/19/2017 8:44:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:29:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:14:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:11:34 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/19/2017 7:59:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:55:11 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/19/2017 7:55:01 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/19/2017 7:44:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:28:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:13:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:58:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:43:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:28:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:13:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:57:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:50:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 5:50:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/19/2017 5:50:22 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 5:42:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:40:33 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/19/2017 5:40:28 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/19/2017 5:27:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:12:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:57:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:42:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:26:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:11:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:57:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f78cec05-84c8-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/19/2017 3:56:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:41:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:26:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:11:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:55:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:40:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:25:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:10:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:50:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 1:40:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:24:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:11:00 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/19/2017 1:11:00 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:00Z. Reason: GVLK.
Information	8/19/2017 1:09:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:06:00 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/19/2017 1:06:00 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/19/2017 1:06:00 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/19/2017 1:06:00 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/19/2017 12:54:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:39:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:24:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:14:52 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8627.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/19/2017 12:09:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:53:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:38:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:23:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 11:08:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:57:12 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0d53d382-849f-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/19/2017 10:53:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:38:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:23:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 10:07:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:54:32 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/19/2017 9:54:32 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:32Z. Reason: GVLK.
Information	8/19/2017 9:52:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:49:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 9:45:44 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/19/2017 9:45:44 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/19/2017 9:45:43 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/19/2017 9:45:43 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/19/2017 9:37:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:22:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 9:14:38 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/19/2017 9:07:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:51:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:36:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:21:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 8:06:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:51:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:36:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:20:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 7:05:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:50:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:35:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:20:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 6:05:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:57:10 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2339666d-8475-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/19/2017 5:49:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:49:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42499)(?)])(1 )(2 )]

"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42499)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/19/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/19/2017 5:34:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:19:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 5:04:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:49:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:34:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:18:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 4:03:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:48:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:33:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:18:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 3:03:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:47:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:32:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:17:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 2:02:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:49:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/19/2017 1:47:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:32:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:16:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 1:01:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:57:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 38a50f9a-844b-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/19/2017 12:46:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:31:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:16:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/19/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/19/2017 12:01:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:45:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:30:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:15:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:00:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:45:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:30:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:14:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:59:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:49:20 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/18/2017 9:44:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:36:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 9:36:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:26:57Z. Reason: GVLK.
Information	8/18/2017 9:31:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/18/2017 9:31:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 9:31:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 9:31:57 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 9:29:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:14:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:59:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:43:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:28:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:13:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:09:25 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/18/2017 7:58:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:57:04 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4e0f1d27-8421-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/18/2017 7:43:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:28:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:12:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:57:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:42:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:33:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 6:28:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 6:28:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43167)(?)])(1 )(2 )]

"
Information	8/18/2017 6:28:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43167)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 6:28:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 6:28:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 6:28:37 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 6:27:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:12:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:08:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 6:03:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 6:03:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43192)(?)])(1 )(2 )]

"
Information	8/18/2017 6:03:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43192)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 6:03:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 6:03:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 6:03:28 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 5:57:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:49:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/18/2017 5:41:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:39:46 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 5:34:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 5:34:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43220)(?)])(1 )(2 )]

"
Information	8/18/2017 5:34:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43220)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 5:34:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 5:34:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43221)(?)])(1 )(2 )]

"
Information	8/18/2017 5:34:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43221)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 5:34:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 5:34:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 5:34:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 5:26:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:11:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:56:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:50:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 4:50:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:03Z. Reason: GVLK.
Information	8/18/2017 4:45:03 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/18/2017 4:45:03 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257340)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 4:45:03 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 4:45:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 4:41:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:26:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:10:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:06:52 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/18/2017 3:55:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:44:48 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/18/2017 3:44:38 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/18/2017 3:40:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:25:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:10:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:57:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 641288d3-83f7-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/18/2017 2:55:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:39:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:24:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:09:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:54:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:48:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/18/2017 1:39:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:24:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:08:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:53:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:38:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:23:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:08:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:53:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:37:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:28:57 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/18/2017 11:28:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/18/2017 11:22:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 11:07:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:52:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:37:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:21:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 10:06:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:55:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 54c20ab2-83cd-11e7-ba45-0205857feb80
Report Status: 0"
Information	8/18/2017 9:54:02 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 9:51:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:50:19 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 26, Deleted: 0, Modified: 34, Compared: 11660, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/18/2017 9:49:01 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 156

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 1997

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 452

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 125

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1482

Information	8/18/2017 9:48:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/18/2017 9:48:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 9:48:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43687)(?)])(1 )(2 )]

"
Information	8/18/2017 9:48:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43687)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 9:48:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 9:48:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 9:48:11 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/18/2017 9:48:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 9:36:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:21:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 9:06:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:50:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:35:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:20:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 8:05:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:50:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:35:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:20:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 7:04:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:49:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:34:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:19:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 6:03:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:48:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/18/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43939)(?)])(1 )(2 )]

"
Information	8/18/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43939)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 5:33:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:18:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 5:09:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 5:04:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/18/2017 5:04:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 5:04:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 5:03:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:55:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a282573-83a3-11e7-ba45-80000bd6758f
Report Status: 0"
Information	8/18/2017 4:47:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:32:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:27:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/18/2017 4:27:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:31Z. Reason: GVLK.
Information	8/18/2017 4:22:31 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/18/2017 4:22:31 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/18/2017 4:22:31 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/18/2017 4:22:30 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/18/2017 4:17:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 4:02:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:47:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:31:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:16:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 3:01:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:46:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:31:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:15:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 2:00:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:45:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:29:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 1:14:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:59:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:44:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:29:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:13:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/18/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/17/2017 11:58:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:55:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f1f629d-8379-11e7-ba45-80000bd6758f
Report Status: 0"
Information	8/17/2017 11:43:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:30:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 11:30:12 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:12Z. Reason: GVLK.
Information	8/17/2017 11:28:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:25:12 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 11:25:12 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258360)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 11:25:12 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 11:25:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 11:13:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:58:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:44:58 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/17/2017 10:42:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:27:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:17:50 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/17/2017 10:12:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:57:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:41:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:26:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:11:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 8:56:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 8:41:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 8:36:45 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 8:31:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 8:31:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 8:31:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 8:26:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 8:10:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 8:06:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 8:01:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 8:01:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 8:01:43 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 7:55:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 7:40:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 7:36:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 7:31:44 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 7:31:44 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 7:31:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 7:23:28 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 7:23:27 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:24Z. Reason: GVLK.
Information	8/17/2017 7:21:49 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	8/17/2017 7:21:48 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	8/17/2017 7:17:46 PM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8624.0000.
Information	8/17/2017 7:17:38 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/17/2017 7:17:25 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/17/2017 7:17:15 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 7:17:12 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 7:17:10 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 7:17:05 PM	ESENT	302	Logging/Recovery	Windows (8132) Windows: The database engine has successfully completed recovery steps.
Information	8/17/2017 7:16:58 PM	ESENT	301	Logging/Recovery	Windows (8132) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/17/2017 7:16:57 PM	ESENT	300	Logging/Recovery	Windows (8132) Windows: The database engine is initiating recovery steps.
Information	8/17/2017 7:16:57 PM	ESENT	102	General	Windows (8132) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/17/2017 7:16:27 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/17/2017 7:16:27 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/17/2017 7:16:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/17/2017 7:16:26 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/17/2017 7:15:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 7:15:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 7:15:23 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	8/17/2017 7:15:22 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (volmgrx)
License Id=dd988d42-3935-2ce5-d88a-3d7d9fd5e283"
Information	8/17/2017 7:15:22 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	8/17/2017 7:15:22 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Windows(TM) - Component PPD License (appid)
License Id=585f9e04-208c-a713-f44d-3e1b391b4324"
Information	8/17/2017 7:15:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 7:15:14 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 7:15:08 PM	Service1	0	None	Service started successfully.
Error	8/17/2017 7:14:56 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/17/2017 7:14:56 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/17/2017 7:14:53 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/17/2017 7:14:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8624.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/17/2017 7:14:53 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/17/2017 7:14:35 PM	PostgreSQL	0	None	"2017-08-17 19:14:34 IST LOG:  redirecting log output to logging collector process
2017-08-17 19:14:34 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/17/2017 7:14:33 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/17/2017 7:14:31 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/17/2017 7:14:30 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/17/2017 7:14:26 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/17/2017 7:14:25 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/17/2017 7:14:25 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/17/2017 7:14:25 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:24 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/17/2017 7:14:23 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/17/2017 7:14:22 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/17/2017 7:14:19 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:19 PM	MSSQL$SQLEXPRESS	3406	Server	89 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/17/2017 7:14:18 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3664 at 8/17/2017 8:52:18 AM (local) 8/17/2017 3:22:18 AM (UTC). This is an informational message only; no user action is required.
Information	8/17/2017 7:14:16 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3448.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/17/2017 7:14:15 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/17/2017 7:13:50 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/17/2017 7:13:42 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 7:12:25 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/17/2017 7:11:53 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/17/2017 7:11:43 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/17/2017 6:58:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 6:55:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9438b346-834f-11e7-9ac7-80000bd6758f
Report Status: 0"
Information	8/17/2017 6:42:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 6:27:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 6:12:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 6:07:05 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 6:06:26 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 5:57:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 5:42:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 5:26:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 5:11:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 4:56:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 4:41:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 4:26:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 4:11:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 3:55:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 3:40:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 3:25:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 3:10:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 2:55:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 2:40:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 2:26:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 2:24:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 2:21:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/17/2017 2:21:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44853)(?)])(1 )(2 )]

"
Information	8/17/2017 2:21:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 44853)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 2:21:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 2:21:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 2:21:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 2:09:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 2:06:51 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 2:06:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 1:55:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a7cb2074-8325-11e7-9ac7-80000bd6758f
Report Status: 0"
Information	8/17/2017 1:54:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 1:39:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 1:24:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 1:09:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 12:53:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 12:38:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 12:23:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 12:08:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:53:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:38:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:22:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 11:07:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:52:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:37:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:29:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/17/2017 10:29:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/17/2017 10:22:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:12:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 10:07:33 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/17/2017 10:07:20 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 212, Deleted: 0, Modified: 149, Compared: 11593, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/17/2017 10:07:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 10:06:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 10:06:28 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/17/2017 10:06:13 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 203

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 93

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 141

Information	8/17/2017 10:06:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/17/2017 10:05:51 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	8/17/2017 10:05:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/17/2017 10:05:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45110)(?)])(1 )(2 )]

"
Information	8/17/2017 10:05:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45110)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 10:05:40 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 10:05:40 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 10:05:39 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 10:05:38 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/17/2017 9:56:51 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8624.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/17/2017 9:54:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:54:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:42Z. Reason: GVLK.
Information	8/17/2017 9:51:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:49:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 9:49:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 9:49:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:49:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:48:23 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/17/2017 9:42:57 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/17/2017 9:42:51 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:38:35 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:38:35 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:35Z. Reason: GVLK.
Information	8/17/2017 9:37:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 9:37:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:37:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:36:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:33:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 9:33:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 9:33:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:33:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:33:31 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:33:31 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:29Z. Reason: GVLK.
Information	8/17/2017 9:28:29 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 9:28:29 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 9:28:28 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:28:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:21:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/17/2017 9:21:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/17/2017 9:21:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/17/2017 9:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/17/2017 9:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/17/2017 9:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/17/2017 9:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/17/2017 9:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/17/2017 9:12:50 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:08:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:08:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-24T03:27:09Z. Reason: GVLK.
Information	8/17/2017 9:07:50 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 9:07:50 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:07:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:07:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/17/2017 9:02:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/17/2017 9:02:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45172)(?)])(1 )(2 )]

"
Information	8/17/2017 9:02:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 45172)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 9:02:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/17/2017 9:02:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 9:02:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 9:00:08 AM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8623.0000.
Information	8/17/2017 8:57:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 8:57:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 8:57:52 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/08/17 03:27"
Information	8/17/2017 8:57:50 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/17 03:27, 0, 1, 247860, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/17/2017 8:56:06 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/17/2017 8:55:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b875642b-82fb-11e7-9ac7-80000bd6758f
Report Status: 0"
Information	8/17/2017 8:54:32 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/17/2017 8:53:38 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 8:53:36 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 8:53:35 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 8:53:34 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/17/2017 8:52:49 AM	ESENT	102	General	Windows (7748) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/17/2017 8:52:47 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/17/2017 8:52:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 247860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/17/2017 8:52:47 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/17/2017 8:52:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/17/2017 8:52:29 AM	Service1	0	None	Service started successfully.
Information	8/17/2017 8:52:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/17/2017 8:52:28 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/17/2017 8:52:28 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/17/2017 8:52:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/17/2017 8:52:28 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/17/2017 8:52:22 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/17/2017 8:52:20 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/17/2017 8:52:20 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/17/2017 8:52:20 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/17/2017 8:52:20 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/17/2017 8:52:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8623.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/17/2017 8:52:19 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/17/2017 8:52:18 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3740 at 8/16/2017 9:54:39 PM (local) 8/16/2017 4:24:39 PM (UTC). This is an informational message only; no user action is required.
Error	8/17/2017 8:52:18 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/17/2017 8:52:17 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/17/2017 8:52:13 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/17/2017 8:52:11 AM	PostgreSQL	0	None	"2017-08-17 08:52:11 IST LOG:  redirecting log output to logging collector process
2017-08-17 08:52:11 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/17/2017 8:52:11 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/17/2017 8:52:10 AM	PostgreSQL	0	None	Waiting for server startup...

Warning	8/17/2017 8:52:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/17/2017 8:52:08 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/17/2017 8:52:08 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/17/2017 8:52:08 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/17/2017 8:52:08 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/17/2017 8:52:08 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3664.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/17/2017 8:52:06 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/17/2017 8:52:00 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/17/2017 8:51:54 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/17/2017 8:51:54 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/16/2017 9:54:46 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	8/17/2017 8:51:54 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/16/2017 9:54:39 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	8/16/2017 9:54:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8623.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Warning	8/16/2017 9:54:13 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 14 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 984 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1432 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	8/16/2017 9:54:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	8/16/2017 9:54:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	8/16/2017 9:54:12 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	8/16/2017 9:54:09 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	8/16/2017 9:52:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248520)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 9:52:18 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 9:52:18 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 16:22, 0, 1, 248520, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 9:50:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 9:47:17 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 9:47:17 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 16:17, 0, 1, 248580, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 9:47:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/16/2017 9:47:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 9:47:15 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 9:47:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 9:47:15 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 9:47:15 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-23T16:16:15Z. Reason: GVLK.
Information	8/16/2017 9:42:15 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 9:42:15 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 16:12, 0, 1, 248580, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 9:41:47 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 9:41:47 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 16:11, 0, 1, 248580, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 9:41:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/16/2017 9:41:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 9:41:46 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 9:41:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 9:40:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 9:40:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-23T16:04:35Z. Reason: GVLK.
Information	8/16/2017 9:35:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 9:35:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 9:35:35 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 9:35:35 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 16:05, 0, 1, 248580, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 9:30:32 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/16/2017 9:30:32 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 9:30:32 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 9:30:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 9:20:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 8:10:38 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/16/2017 8:05:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 7:50:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 7:34:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 7:26:06 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 7:21:06 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/16/2017 7:21:06 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 7:21:06 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 7:19:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 7:04:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 6:56:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 6:51:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/16/2017 6:51:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 6:51:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 6:49:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 6:41:13 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8623.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/16/2017 6:34:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/16/2017 6:33:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 9688.
Information	8/16/2017 6:33:25 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20095. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	8/16/2017 6:33:25 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	8/16/2017 6:33:25 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20095. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (17.012.20095). Installation success or error status: 0.
Information	8/16/2017 6:33:25 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (17.012.20095)' installed successfully.
Information	8/16/2017 6:33:08 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/16/2017 6:33:08 PM	ESENT	103	General	Windows (8160) Windows: The database engine stopped the instance (0).
Information	8/16/2017 6:33:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 9688.
Information	8/16/2017 6:32:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8328.
Information	8/16/2017 6:32:58 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20095. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	8/16/2017 6:32:58 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	8/16/2017 6:32:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8328.
Information	8/16/2017 6:26:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 6:21:08 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/16/2017 6:21:08 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 6:21:07 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 6:17:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 6:17:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-23T12:41:43Z. Reason: GVLK.
Information	8/16/2017 6:14:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a56efda4-8280-11e7-928d-80000bd6758f
Report Status: 0"
Information	8/16/2017 6:12:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 6:12:43 PM	Microsoft-Windows-Security-SPP	8196	None	"License Activation Scheduler (sppuinotify.dll) was not able to automatically activate.  Error code:
0xC004F074"
Information	8/16/2017 6:12:43 PM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0xC0020017, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/16 12:42, 0, 1, 248760, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/16/2017 6:09:35 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/16/2017 6:08:10 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/16/2017 6:08:07 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/16/2017 6:08:06 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/16/2017 6:08:04 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/16/2017 6:07:43 PM	ESENT	302	Logging/Recovery	Windows (8160) Windows: The database engine has successfully completed recovery steps.
Information	8/16/2017 6:07:42 PM	ESENT	301	Logging/Recovery	Windows (8160) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/16/2017 6:07:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/16/2017 6:07:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 6:07:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 6:07:37 PM	ESENT	301	Logging/Recovery	Windows (8160) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03CFF.log.
Information	8/16/2017 6:07:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 6:07:37 PM	ESENT	300	Logging/Recovery	Windows (8160) Windows: The database engine is initiating recovery steps.
Information	8/16/2017 6:07:37 PM	ESENT	102	General	Windows (8160) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/16/2017 6:07:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8618.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/16/2017 6:06:44 PM	Service1	0	None	Service started successfully.
Error	8/16/2017 6:06:15 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/16/2017 6:06:15 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/16/2017 6:06:13 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/16/2017 6:05:59 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/16/2017 6:05:58 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/16/2017 6:05:58 PM	PostgreSQL	0	None	"2017-08-16 18:05:58 IST LOG:  redirecting log output to logging collector process
2017-08-16 18:05:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/16/2017 6:05:57 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/16/2017 6:05:55 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/16/2017 6:05:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/16/2017 6:05:50 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/16/2017 6:05:50 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/16/2017 6:05:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/16/2017 6:05:50 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/16/2017 6:05:46 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/16/2017 6:05:45 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/16/2017 6:05:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/16/2017 6:05:44 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/16/2017 6:05:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/16/2017 6:05:44 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/16/2017 6:05:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:43 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/16/2017 6:05:42 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	3406	Server	84 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/16/2017 6:05:40 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3676 at 8/11/2017 10:05:27 AM (local) 8/11/2017 4:35:27 AM (UTC). This is an informational message only; no user action is required.
Information	8/16/2017 6:05:39 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/16/2017 6:05:39 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/16/2017 6:05:39 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/16/2017 6:05:39 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/16/2017 6:05:39 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3740.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/16/2017 6:05:38 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/16/2017 6:05:17 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/16/2017 6:05:11 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/16/2017 6:04:53 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/16/2017 6:04:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/16/2017 6:04:53 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/16/2017 6:00:44 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/16/2017 5:57:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/16/2017 5:57:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 248760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 5:57:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 5:57:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Error	8/16/2017 5:55:29 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	8/16/2017 5:55:29 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DD06CB95-A385-4679-9E41-9534C61E333F}
Error	8/16/2017 5:55:29 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {DD06CB95-A385-4679-9E41-9534C61E333F}
Information	8/16/2017 5:55:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/16/2017 5:55:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46080)(?)])(1 )(2 )]

"
Information	8/16/2017 5:55:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 46080)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/16/2017 5:55:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/16/2017 5:55:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/16/2017 5:55:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/16/2017 5:55:07 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/16/2017 5:55:01 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 17 ms, redo 0 ms, undo 10 ms.) This is an informational message only. No user action is required.
Information	8/16/2017 5:54:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 8:26:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 8:11:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:56:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:50:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 7:40:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:25:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:10:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:55:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:43:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df63bd4a-7e96-11e7-bb43-80000bd6758f
Report Status: 0"
Information	8/11/2017 6:39:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:24:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:09:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 5:54:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 5:39:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 5:24:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 5:08:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:53:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:38:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:23:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:08:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:53:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:49:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 3:37:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:33:49 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/11/2017 3:22:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:07:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:52:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:37:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:33:13 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/11/2017 2:22:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:06:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:51:48 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/11/2017 1:51:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:51:43 PM	ESENT	102	General	Windows (12820) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/11/2017 1:51:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13172.
Information	8/11/2017 1:51:19 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20093. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	8/11/2017 1:51:19 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	8/11/2017 1:51:19 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20093. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (17.012.20093). Installation success or error status: 0.
Information	8/11/2017 1:51:19 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (17.012.20093)' installed successfully.
Information	8/11/2017 1:51:18 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/11/2017 1:50:52 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/11/2017 1:50:52 PM	ESENT	103	General	Windows (8244) Windows: The database engine stopped the instance (0).
Information	8/11/2017 1:50:45 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 13172.
Information	8/11/2017 1:50:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6780.
Information	8/11/2017 1:50:39 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.012.20093. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	8/11/2017 1:50:39 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	8/11/2017 1:50:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 6780.
Information	8/11/2017 1:43:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f539d6ca-7e6c-11e7-bb43-80000bd6758f
Report Status: 0"
Information	8/11/2017 1:36:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:21:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:06:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:51:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:35:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:20:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:05:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 11:54:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 11:50:49 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/11/2017 11:50:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 27, Deleted: 0, Modified: 2, Compared: 11486, Queries: 0, Results: 0, Version: 16.0.7766.6611.
Information	8/11/2017 11:50:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 11:49:43 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 109

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 125

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	8/11/2017 11:49:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 11:49:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/11/2017 11:49:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53646)(?)])(1 )(2 )]

"
Information	8/11/2017 11:49:22 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53646)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 11:49:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2017 11:49:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 11:49:21 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 11:49:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	8/11/2017 11:49:20 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/11/2017 11:35:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 11:31:10 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8618.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/11/2017 11:19:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 11:04:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 10:49:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 10:34:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 10:20:48 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 10:15:50 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 1152.
Information	8/11/2017 10:15:50 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.7766.2099. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/11/2017 10:15:50 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	8/11/2017 10:15:50 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/11/2017 10:15:47 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53739)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 10:15:47 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/11/2017 10:15:47 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/11/2017 10:15:47 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 10:15:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2017 10:15:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 10:15:46 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 10:15:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 10:15:07 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 1152.
Information	8/11/2017 10:15:07 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:15:07 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2099. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/11/2017 10:15:07 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	8/11/2017 10:15:04 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:15:03 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:15:03 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2099. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/11/2017 10:15:03 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	8/11/2017 10:15:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 10:15:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:18:01Z. Reason: GVLK.
Information	8/11/2017 10:14:54 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:14:53 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/11/2017 10:14:52 AM	ESENT	102	General	Windows (8244) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/11/2017 10:14:52 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:14:52 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2099. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/11/2017 10:14:52 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	8/11/2017 10:14:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:14:17 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/11/2017 10:14:17 AM	ESENT	103	General	Windows (7644) Windows: The database engine stopped the instance (0).
Information	8/11/2017 10:14:14 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:14:14 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2099. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	8/11/2017 10:14:14 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	8/11/2017 10:12:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 1152.
Information	8/11/2017 10:11:21 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/11/2017 10:11:20 AM	ESENT	102	General	Windows (7644) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/11/2017 10:11:18 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	8/11/2017 10:11:18 AM	ESENT	103	General	Windows (8916) Windows: The database engine stopped the instance (0).
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:16 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	8/11/2017 10:11:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:11:15 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	8/11/2017 10:10:40 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=89fdcb09-5030-4b80-bc8a-8e98c230e2d0"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=52cb0865-4092-4535-bebc-bbad8d5f6500"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=e7be914e-23b4-4cd4-b058-21a0cff6f94f"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7da5c758-9205-4543-b52c-cfac434627f1"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=20ce7206-dad6-4f4f-87f8-fcad4a145355"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=758c1bbf-8ebc-4ac7-b053-a326920e8b68"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=cf3ed145-dfd8-4e97-bf91-11e01f057d5e"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5b5ea619-1170-4d9e-8fc8-0960888b7431"
Information	8/11/2017 10:10:37 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6f429561-d63d-42e3-8b66-e2d61597c80e"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bbf7509f-b3a2-4713-a815-71e1d96d7490"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=aa746716-d1e2-44d9-8f47-c07f894832df"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0d1964ec-3df5-4502-a64a-f36512f035f9"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=613452e6-1730-4764-8ef6-b2115d970264"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ebfd22a7-76e0-46d1-9a2c-658aa3fe5a96"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=47745e77-0f59-438c-88cc-f1f4c2935f65"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=987e2dfd-9019-49b1-8f46-48e3b6af2b74"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=81ce275d-af14-4c87-9270-86028e12069f"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2571a19e-089a-4969-b5e8-ddffbf9fa049"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d31537c8-d813-4cfd-96ee-044661f5e16e"
Information	8/11/2017 10:10:36 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=871ba58b-a95c-4e66-8f30-b7af01d7767d"
Information	8/11/2017 10:10:35 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5d37def8-1e50-4fe6-97dc-373e1b68f743"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=80f4fb6c-b614-430b-8949-b76a82b9feb1"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6a75e296-2f1d-4a3c-acb8-b96a377f6e54"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5ea9fc4d-7f3f-404c-9ee7-269a78dd29cd"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=37339799-7bda-47f7-9b01-0160d6ec30ee"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7be03f78-fec3-481c-9b83-0cb67664675e"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=835b0016-93af-42ef-bb26-5fc1960509f8"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=9b3eca54-55d1-4c70-b00b-04d742afa893"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=545f91f2-7de4-40d3-b8a8-516609dba545"
Information	8/11/2017 10:10:34 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f8ef987c-d49b-4575-b3d2-ad3ba94441fb"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6ced6197-e10b-4252-9e5d-c71b30302235"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=ac8ed6d5-96bb-47ac-8f6c-13d269009f86"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f2ed2aa1-f04a-495f-af23-bac9060aaee1"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a14fd7bb-507b-4e24-9fd2-0a69eca78cb4"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=65f86812-c661-47b1-9c4f-31850f714943"
Information	8/11/2017 10:10:33 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=02857536-cf15-4c0d-b44a-a1b64c46d07d"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=60f9f3e8-c1be-4b13-aead-7005b2c806b6"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=0db9cf5f-dfa7-4d40-b430-1da4b8e2259a"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8e25612b-ee1d-4f26-8799-740f69243a17"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=87b19075-f273-4502-9167-158800827d43"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=85815fb6-f287-4ff9-9155-d13103ce14f1"
Information	8/11/2017 10:10:32 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2379f603-aa01-44d3-92c2-d8aa002523c1"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bbb7ec1c-d627-4371-a4a7-b311eda6dbcc"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=57d699dc-639e-495f-8c22-d4af696034ed"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=bc1b8bd5-96cf-4c77-9c52-08590fa81818"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=be089e7b-571b-4330-9a09-63cb6d7c8d59"
Information	8/11/2017 10:10:31 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ce62428d-1958-4a99-9d9d-83d4260f990e"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ab7bd8f5-8934-47d2-9ee9-7c09aeeaabf4"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=22be7fa2-ca89-4e32-b4c3-41ede6a99d71"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=13351a6e-df68-443d-8edd-d9f4cae1ff67"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=303d5c42-d5db-413c-a214-043c26110ff2"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32814545-fe45-4806-bfab-db23cb8ed04f"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fcd5ee65-6dc1-4ede-9830-c75ffa9e4733"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe73e4ab-0060-4888-9b1b-83cc923cd076"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bbbd973-6d0f-448f-aa0e-91c43fa94eb7"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f0a52c37-71c8-4b1c-b178-43b4ef6b145a"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ee2c65f4-85f2-4006-8e11-7dc63f23b498"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c9ce7541-001c-4779-b883-f5169b882b41"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d153ef14-af6e-474c-84d5-2303e980041a"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7d86124e-eb3b-46a0-b815-3b697f47fd7c"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=91370939-d8a9-49f2-a80e-836f8d3676bc"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2665797f-c833-48db-a0ea-9b88351cbc44"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	8/11/2017 10:10:30 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	8/11/2017 10:10:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	8/11/2017 10:10:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	8/11/2017 10:10:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	8/11/2017 10:10:29 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	8/11/2017 10:10:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2017 10:10:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 10:10:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 10:09:13 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/11/2017 10:08:12 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Microsoft Windows Search Protocol Host'.
Information	8/11/2017 10:08:12 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Error	8/11/2017 10:08:12 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Microsoft Windows Search Protocol Host' could not be shut down.
Information	8/11/2017 10:07:52 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/11/2017 10:07:50 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/11/2017 10:07:49 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/11/2017 10:07:48 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/11/2017 10:07:25 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎08‎-‎11T04:37:25.246140400Z.
Information	8/11/2017 10:07:22 AM	ESENT	302	Logging/Recovery	Windows (8916) Windows: The database engine has successfully completed recovery steps.
Information	8/11/2017 10:07:21 AM	ESENT	301	Logging/Recovery	Windows (8916) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/11/2017 10:07:16 AM	ESENT	301	Logging/Recovery	Windows (8916) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03CF6.log.
Information	8/11/2017 10:07:15 AM	ESENT	300	Logging/Recovery	Windows (8916) Windows: The database engine is initiating recovery steps.
Information	8/11/2017 10:07:14 AM	ESENT	102	General	Windows (8916) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/11/2017 10:07:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/11/2017 10:07:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 10:07:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 10:07:08 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 10:07:05 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8617.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/11/2017 10:06:18 AM	Service1	0	None	Service started successfully.
Error	8/11/2017 10:06:00 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/11/2017 10:05:57 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/11/2017 10:05:54 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/11/2017 10:05:45 AM	PostgreSQL	0	None	"2017-08-11 10:05:45 IST LOG:  redirecting log output to logging collector process
2017-08-11 10:05:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/11/2017 10:05:45 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/11/2017 10:05:44 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/11/2017 10:05:43 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/11/2017 10:05:42 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/11/2017 10:05:37 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/11/2017 10:05:37 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/11/2017 10:05:37 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/11/2017 10:05:37 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/11/2017 10:05:37 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/11/2017 10:05:33 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/11/2017 10:05:32 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/11/2017 10:05:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/11/2017 10:05:32 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:31 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/11/2017 10:05:30 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/11/2017 10:05:29 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/11/2017 10:05:29 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/11/2017 10:05:29 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	3406	Server	7 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/11/2017 10:05:27 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3628 at 8/3/2017 8:49:54 AM (local) 8/3/2017 3:19:54 AM (UTC). This is an informational message only; no user action is required.
Information	8/11/2017 10:05:25 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/11/2017 10:05:25 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/11/2017 10:05:25 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/11/2017 10:05:25 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/11/2017 10:05:25 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3676.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/11/2017 10:05:24 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/11/2017 10:05:09 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/11/2017 10:05:03 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/11/2017 10:04:45 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/11/2017 10:04:45 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/11/2017 10:04:45 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/11/2017 9:34:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 9:33:49 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/11/2017 9:33:49 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/11/2017 9:23:59 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 9:23:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 9:21:08 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 9:21:08 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:18:08Z. Reason: GVLK.
Information	8/11/2017 9:16:08 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/11/2017 9:16:08 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 9:16:08 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 9:16:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 9:04:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 8:43:25 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 09a46cb0-7e43-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/11/2017 8:34:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 8:04:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:34:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 7:04:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:57:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/11/2017 6:57:22 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/11/2017 6:37:20 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/11/2017 6:37:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/11/2017 6:34:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:08:11 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 6:04:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 6:03:19 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎08‎-‎11T00:33:19.665360100Z.
Information	8/11/2017 6:03:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2017 6:03:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 6:03:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 5:41:41 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 5:36:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/11/2017 5:36:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54019)(?)])(1 )(2 )]

"
Information	8/11/2017 5:36:38 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 54019)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 5:36:38 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/11/2017 5:36:38 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 5:36:37 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 5:34:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 5:23:56 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 5:23:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 5:04:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:34:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 4:04:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:43:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/11/2017 3:43:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:24Z. Reason: GVLK.
Information	8/11/2017 3:43:22 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1e9c22f4-7e19-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/11/2017 3:38:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 3:38:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/11/2017 3:38:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256860)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/11/2017 3:38:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/11/2017 3:38:20 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/11/2017 3:34:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 3:04:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:33:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 2:03:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:33:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 1:23:43 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 1:23:35 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 1:23:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/11/2017 1:03:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:33:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:03:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/11/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/10/2017 11:33:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 11:03:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 10:43:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 34878074-7def-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/10/2017 10:33:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 10:29:07 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/10/2017 10:03:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:42:41 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 9:42:41 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:41Z. Reason: GVLK.
Information	8/10/2017 9:37:41 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2017 9:37:41 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 9:37:41 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 9:37:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 9:33:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:23:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 9:23:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 9:23:33 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/10/2017 9:23:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 9:03:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:01:33 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 9:01:33 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:33Z. Reason: GVLK.
Information	8/10/2017 8:56:33 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2017 8:56:33 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 8:56:33 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 8:56:32 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 8:33:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 8:03:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:33:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:03:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:33:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:03:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:43:16 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 49447168-7dc5-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/10/2017 5:33:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:23:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 5:23:39 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/10/2017 5:22:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 5:03:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 4:33:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 4:03:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:33:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:03:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:33:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:03:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 1:33:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 1:22:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 1:15:53 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/10/2017 1:15:52 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/10/2017 1:15:15 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 16, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/10/2017 1:15:07 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 5, Compared: 11440, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/10/2017 1:14:20 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/10/2017 1:14:20 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/10/2017 1:03:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:57:00 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8617.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/10/2017 12:42:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 385a73ca-7d9b-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/10/2017 12:33:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:03:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 11:33:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 11:03:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 11:01:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824237067_823193239942979946915768960194281796.msi. Client Process Id: 20892.
Information	8/10/2017 11:01:11 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Refresh Manager. Product Version: 1.8.0. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 0.
Information	8/10/2017 11:01:11 AM	MsiInstaller	11707	None	Product: Adobe Refresh Manager -- Installation operation completed successfully.
Information	8/10/2017 11:01:11 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/10/2017 11:01:09 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	8/10/2017 11:00:45 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\Cache\Arm_001824237067_823193239942979946915768960194281796.msi. Client Process Id: 20892.
Information	8/10/2017 10:33:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 10:20:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 10:20:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:18:17Z. Reason: GVLK.
Information	8/10/2017 10:15:16 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2017 10:15:16 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 10:15:16 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 10:15:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 10:03:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:33:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:32:36 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/10/2017 9:32:09 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/10/2017 9:30:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/10/2017 9:27:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 9:22:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 9:22:18 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 63

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 46

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 78

Information	8/10/2017 9:21:59 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/10/2017 9:21:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55233)(?)])(1 )(2 )]

"
Information	8/10/2017 9:21:58 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55233)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 9:21:58 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/10/2017 9:21:58 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 9:21:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 9:18:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 9:03:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 8:47:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 8:32:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 8:17:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 8:02:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:47:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:41:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 29298a2f-7d71-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/10/2017 7:32:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:16:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 7:01:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:46:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:31:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:26:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 6:25:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 6:25:43 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/10/2017 6:16:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 6:01:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:57:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 5:57:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:42Z. Reason: GVLK.
Information	8/10/2017 5:52:42 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2017 5:52:42 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 5:52:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 5:52:41 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 5:45:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:41:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55459)(?)])(1 )(2 )]

"
Information	8/10/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 55459)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/10/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 5:30:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:15:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 5:02:09 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/10/2017 5:02:09 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:18:09Z. Reason: GVLK.
Information	8/10/2017 5:00:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 4:57:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 4:57:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/10/2017 4:57:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/10/2017 4:57:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/10/2017 4:57:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/10/2017 4:45:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 4:30:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 4:14:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:59:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:44:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:29:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 3:14:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:59:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:43:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:41:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3e5bc244-7d47-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/10/2017 2:28:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:26:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 2:25:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 2:25:44 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/10/2017 2:13:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 2:12:45 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/10/2017 2:12:14 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/10/2017 1:58:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 1:43:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 1:28:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 1:12:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:57:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:42:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:27:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:12:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/10/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/9/2017 11:57:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:41:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:26:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:11:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:56:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:41:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:26:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 10:26:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:25:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 10:25:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 10:10:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:55:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:40:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 53c11cca-7d1d-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/9/2017 9:40:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:37:32 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 9:37:32 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:32Z. Reason: GVLK.
Information	8/9/2017 9:32:31 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2017 9:32:31 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 9:32:30 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 9:32:28 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 9:25:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:10:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:54:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:39:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:24:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:09:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:54:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:39:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:23:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:08:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:53:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:38:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:26:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 6:25:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 6:23:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:18:13 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/9/2017 6:17:59 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/9/2017 6:08:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:52:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:37:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:29:26 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/9/2017 5:29:14 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/9/2017 5:22:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:07:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:52:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:40:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6a385819-7cf3-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/9/2017 4:37:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:21:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:06:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:51:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:36:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:21:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:06:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:50:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:35:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:26:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 2:25:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 2:25:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 2:20:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:05:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:52:16 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/9/2017 1:50:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:34:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:04:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:49:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:34:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:19:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:09:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8616.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/9/2017 12:03:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:53:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 11:53:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-16T06:17:20Z. Reason: GVLK.
Information	8/9/2017 11:48:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:48:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 11:48:19 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 11:48:19 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/08/09 06:18"
Information	8/9/2017 11:48:18 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/09 06:18, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/9/2017 11:43:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2017 11:43:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 11:43:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 11:43:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 11:40:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7f0f5c6a-7cc9-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/9/2017 11:33:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:18:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 11:03:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:48:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:32:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:30:41 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/9/2017 10:30:37 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/9/2017 10:26:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 10:25:31 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 10:17:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 10:02:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:47:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:45:55 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/9/2017 9:32:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:30:16 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 9:30:16 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:15Z. Reason: GVLK.
Information	8/9/2017 9:25:15 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2017 9:25:15 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 9:25:15 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 9:25:15 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 9:16:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 9:01:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:46:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:31:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:16:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 8:01:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:45:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:30:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:15:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 7:00:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:45:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:40:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8319aae5-7c9f-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/9/2017 6:30:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 6:26:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 6:25:18 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 6:14:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:59:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:44:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:41:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56899)(?)])(1 )(2 )]

"
Information	8/9/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 56899)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 5:36:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/9/2017 5:36:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 5:29:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 5:14:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:58:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:47:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 4:47:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:55Z. Reason: GVLK.
Information	8/9/2017 4:43:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:42:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2017 4:42:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249600)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 4:42:54 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 4:42:54 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 4:28:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 4:13:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/9/2017 4:13:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/9/2017 4:13:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:58:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:43:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:38:30 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/9/2017 3:37:57 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/9/2017 3:29:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/9/2017 3:29:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:50Z. Reason: GVLK.
Information	8/9/2017 3:27:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 3:24:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 3:24:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/9/2017 3:24:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/9/2017 3:24:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/9/2017 3:24:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/9/2017 3:12:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:57:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:42:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:27:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 2:26:14 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 2:25:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/9/2017 2:12:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:56:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:41:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:40:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97f466a5-7c75-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/9/2017 1:26:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 1:11:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:56:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:41:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:26:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:10:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/9/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/8/2017 11:55:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:40:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:25:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:10:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:54:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:39:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:26:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 10:25:09 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 10:24:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:09:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:54:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:42:08 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/8/2017 9:39:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:23:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:08:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:53:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:40:14 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ad92293b-7c4b-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/8/2017 8:38:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:23:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:08:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:52:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:37:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:27:06 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/8/2017 7:27:06 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:06Z. Reason: GVLK.
Information	8/8/2017 7:22:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:22:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/8/2017 7:22:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2017 7:22:05 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2017 7:22:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/8/2017 7:07:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:52:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:37:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:25:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 6:25:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 6:21:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:06:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:51:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:36:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:21:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:06:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:50:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:35:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:20:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:05:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:50:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:40:10 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c23a1091-7c21-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/8/2017 3:34:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:04:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:49:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:34:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:25:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 2:25:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 2:19:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:03:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:48:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:33:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:18:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:03:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:51:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8615.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/8/2017 12:48:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:33:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:17:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:02:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:47:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:32:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:17:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 11:01:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:46:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:40:07 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d805f33e-7bf7-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/8/2017 10:31:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:25:11 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 10:24:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 10:24:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 10:16:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 10:01:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:53:09 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/8/2017 9:52:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/8/2017 9:46:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:32:58 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/8/2017 9:30:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:15:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 9:03:37 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/8/2017 9:03:28 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/8/2017 9:00:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:45:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:30:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 8:15:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:59:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:44:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:29:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 7:14:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:59:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:44:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:28:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:25:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 6:24:48 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 6:24:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 6:23:01 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎08‎-‎08T00:53:01.921074200Z.
Information	8/8/2017 6:22:59 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/8/2017 6:17:59 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/8/2017 6:17:59 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2017 6:17:59 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/8/2017 6:13:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 6:07:40 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/8/2017 6:07:40 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:40Z. Reason: GVLK.
Information	8/8/2017 6:02:40 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/8/2017 6:02:40 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250920)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2017 6:02:40 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2017 6:02:39 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/8/2017 5:58:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:43:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:41:38 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/8/2017 5:40:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: edae55e2-7bcd-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/8/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/8/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58339)(?)])(1 )(2 )]

"
Information	8/8/2017 5:36:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58339)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/8/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/8/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/8/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/8/2017 5:28:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 5:13:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:57:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:42:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:27:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 4:12:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:57:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:55:08 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/8/2017 3:42:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:26:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 3:11:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:56:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:41:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:26:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 2:24:57 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 2:24:39 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/8/2017 2:11:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:55:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:40:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:25:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 1:10:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:55:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:40:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:40:03 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03984164-7ba4-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/8/2017 12:24:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/8/2017 12:09:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:54:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:39:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:24:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:09:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:53:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:38:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:24:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2017 10:24:54 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/7/2017 10:24:28 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2017 10:23:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:08:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:53:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:38:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:22:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:07:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 8:52:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 8:37:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 8:22:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 8:07:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 7:51:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 7:40:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 196ed825-7b7a-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/7/2017 7:36:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 7:21:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 7:06:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 6:51:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 6:35:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 6:24:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2017 6:20:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 6:05:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 5:50:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 5:35:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 5:20:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 5:04:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 4:49:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 4:34:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 4:19:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 4:04:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 3:49:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 3:33:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 3:18:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 3:03:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 2:48:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 2:39:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2ebdc1b4-7b50-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/7/2017 2:33:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 2:24:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2017 2:24:01 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/7/2017 2:24:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/7/2017 2:18:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 2:02:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 1:47:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 1:32:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 1:25:03 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/7/2017 1:25:03 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/7/2017 1:24:31 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 16, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/7/2017 1:24:22 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 2, Compared: 11327, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/7/2017 1:23:44 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	8/7/2017 1:23:44 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/7/2017 1:17:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 1:02:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 12:47:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 12:31:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 12:16:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 12:01:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 12:00:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8614.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/7/2017 11:46:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:31:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:16:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 11:09:10 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/7/2017 11:09:10 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:10Z. Reason: GVLK.
Information	8/7/2017 11:04:10 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/7/2017 11:04:10 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2017 11:04:10 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2017 11:04:07 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/7/2017 11:00:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:45:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:30:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:28:46 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/7/2017 10:26:38 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/7/2017 10:23:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/7/2017 10:23:51 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/7/2017 10:23:48 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/7/2017 10:23:48 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 78

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 203

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 140

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 296

Error	8/7/2017 10:23:46 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {1F27166C-D465-466F-9E62-89969B4D971F}
Error	8/7/2017 10:23:46 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {1F27166C-D465-466F-9E62-89969B4D971F}
Information	8/7/2017 10:23:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/7/2017 10:23:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2017 10:23:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59492)(?)])(1 )(2 )]

"
Information	8/7/2017 10:23:28 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59492)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2017 10:23:27 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2017 10:23:27 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2017 10:23:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2017 10:15:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 10:00:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:59:20 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/7/2017 9:44:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/7/2017 9:35:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	8/7/2017 9:30:14 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	8/7/2017 9:30:14 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {2FC9E3CF-78C8-46D3-854B-B46422175605}
Error	8/7/2017 9:30:14 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {2FC9E3CF-78C8-46D3-854B-B46422175605}
Information	8/7/2017 9:30:14 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/7/2017 9:30:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59545)(?)])(1 )(2 )]

"
Information	8/7/2017 9:30:13 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59545)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/7/2017 9:30:13 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/7/2017 9:30:13 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/7/2017 9:30:10 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/7/2017 9:29:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/5/2017 12:29:54 AM	Microsoft-Windows-Winlogon	4004	None	The Windows logon process has failed to terminate the currently logged on user's processes.
Information	8/5/2017 12:17:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/5/2017 12:01:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:46:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:31:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:16:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:01:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:46:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:30:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:15:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:00:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:45:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:30:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:25:33 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 58b19478-792d-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/4/2017 9:15:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	8/4/2017 9:15:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 5:10:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:55:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:45:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2017 4:40:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:24:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:09:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:54:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:39:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:24:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:09:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:53:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:52:42 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 772669cb-78f6-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/4/2017 2:38:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:23:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:08:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:53:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:38:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:22:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:07:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:52:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:45:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2017 12:37:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:22:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:07:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:02:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8611.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/4/2017 11:51:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:36:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:21:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:18:54 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/4/2017 11:18:20 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/4/2017 11:06:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 11:05:05 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2017 11:05:04 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:04Z. Reason: GVLK.
Information	8/4/2017 11:00:04 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2017 11:00:04 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256380)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2017 11:00:04 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2017 11:00:04 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/4/2017 10:51:48 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/4/2017 10:51:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:36:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:20:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 10:05:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:52:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8ad1cfa4-78cc-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/4/2017 9:50:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:35:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:20:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 9:05:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 8:49:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 8:45:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2017 8:34:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 8:19:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 8:04:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 7:49:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 7:33:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 7:18:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 7:03:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 6:48:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 6:33:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 6:18:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 6:02:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 5:47:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 5:41:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/4/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/4/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64099)(?)])(1 )(2 )]

"
Information	8/4/2017 5:36:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64099)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2017 5:36:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/4/2017 5:36:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2017 5:36:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/4/2017 5:36:15 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/4/2017 5:32:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 5:31:15 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/4/2017 5:31:15 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2017 5:31:14 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/4/2017 5:17:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 5:02:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:52:34 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a0e01a5b-78a2-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/4/2017 4:47:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:45:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2017 4:31:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:16:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 4:01:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:46:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:31:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:16:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 3:00:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:45:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:36:52 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/4/2017 2:30:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:15:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 2:00:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:45:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:29:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:14:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 1:07:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/4/2017 1:07:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:43Z. Reason: GVLK.
Information	8/4/2017 1:02:43 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/4/2017 1:02:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256980)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/4/2017 1:02:42 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/4/2017 1:02:42 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/4/2017 12:59:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:44:45 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/4/2017 12:44:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:29:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:14:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/4/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/3/2017 11:58:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:52:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b6e0c1e5-7878-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/3/2017 11:46:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 11:46:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:20Z. Reason: GVLK.
Information	8/3/2017 11:43:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:41:20 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2017 11:41:20 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 11:41:20 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 11:41:19 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 11:28:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:13:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:58:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:42:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:27:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:12:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:57:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:42:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:27:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:24:46 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/3/2017 9:24:12 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/3/2017 9:11:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 8:56:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 8:44:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2017 8:41:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 8:26:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 8:11:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 7:56:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 7:40:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 7:25:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 7:10:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 6:55:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 6:52:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cd006f7c-784e-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/3/2017 6:40:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 6:25:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 6:09:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 5:54:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 5:39:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 5:24:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 5:09:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 4:53:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 4:49:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 4:45:18 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 7, Compared: 11306, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/3/2017 4:44:18 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 219

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 218

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 234

Information	8/3/2017 4:44:15 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2017 4:43:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/3/2017 4:43:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64871)(?)])(1 )(2 )]

"
Information	8/3/2017 4:43:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 64871)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 4:43:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 4:43:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 4:43:50 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 4:43:49 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/3/2017 4:38:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 4:23:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 4:15:03 PM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8610.0000.
Information	8/3/2017 4:14:07 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\MICROSOFT VS CODE\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8610.0000.
Information	8/3/2017 4:14:07 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8610.0000.
Information	8/3/2017 4:08:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 3:53:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 3:38:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 3:22:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 3:07:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 2:52:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 2:37:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 2:22:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 2:07:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 1:52:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e230ec3e-7824-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/3/2017 1:51:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 1:39:49 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/3/2017 1:36:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 1:21:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 1:06:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 1:01:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2017 1:01:00 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/3/2017 1:00:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2017 12:51:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 12:36:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 12:20:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 12:05:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:50:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:35:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:20:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 11:04:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:56:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 10:51:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/3/2017 10:51:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65224)(?)])(1 )(2 )]

"
Information	8/3/2017 10:51:16 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65224)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 10:51:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 10:51:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 10:51:15 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 10:49:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:34:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:30:34 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/3/2017 10:30:32 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	8/3/2017 10:30:21 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/3/2017 10:30:21 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	8/3/2017 10:19:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 10:11:08 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 10:10:36 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8610.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/3/2017 10:06:07 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 10:06:07 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 10:06:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 10:04:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:49:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:41:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 9:36:07 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 9:36:07 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 9:36:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 9:33:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:18:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/3/2017 9:11:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 9:06:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 9:06:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:50Z. Reason: GVLK.
Information	8/3/2017 9:06:07 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 9:06:07 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 9:06:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 9:06:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 9:03:12 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 30, Deleted: 0, Modified: 1, Compared: 11283, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/3/2017 9:01:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2017 9:01:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 9:01:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 9:01:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 9:01:10 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 202

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 4400

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 405

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 94

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 296

Information	8/3/2017 9:00:42 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/3/2017 9:00:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/3/2017 9:00:31 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]

"
Information	8/3/2017 9:00:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 9:00:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/3/2017 9:00:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]

"
Information	8/3/2017 9:00:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 65335)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 9:00:10 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/3/2017 9:00:10 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 9:00:07 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 9:00:03 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/3/2017 8:58:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/3/2017 8:58:46 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:40Z. Reason: GVLK.
Information	8/3/2017 8:53:25 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/3/2017 8:52:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f72ae59b-77fa-11e7-861d-80000bd6758f
Report Status: 0"
Information	8/3/2017 8:52:07 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/3/2017 8:52:06 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/3/2017 8:52:05 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/3/2017 8:52:03 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/3/2017 8:51:57 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/3/2017 8:51:30 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/3/2017 8:51:30 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/3/2017 8:51:30 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/3/2017 8:51:26 AM	ESENT	302	Logging/Recovery	Windows (7132) Windows: The database engine has successfully completed recovery steps.
Information	8/3/2017 8:51:26 AM	ESENT	301	Logging/Recovery	Windows (7132) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/3/2017 8:51:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/3/2017 8:51:22 AM	ESENT	301	Logging/Recovery	Windows (7132) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03CAF.log.
Information	8/3/2017 8:51:22 AM	ESENT	300	Logging/Recovery	Windows (7132) Windows: The database engine is initiating recovery steps.
Information	8/3/2017 8:51:21 AM	ESENT	102	General	Windows (7132) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/3/2017 8:51:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8609.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/3/2017 8:50:39 AM	Service1	0	None	Service started successfully.
Error	8/3/2017 8:50:19 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/3/2017 8:50:19 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/3/2017 8:50:17 AM	PostgreSQL	0	None	Server started and accepting connections

Information	8/3/2017 8:50:11 AM	PostgreSQL	0	None	"2017-08-03 08:50:11 IST LOG:  redirecting log output to logging collector process
2017-08-03 08:50:11 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/3/2017 8:50:10 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/3/2017 8:50:09 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/3/2017 8:50:08 AM	PostgreSQL	0	None	Waiting for server startup...

Information	8/3/2017 8:50:06 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/3/2017 8:50:06 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/3/2017 8:50:06 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/3/2017 8:50:06 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/3/2017 8:50:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/3/2017 8:50:05 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/3/2017 8:50:01 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/3/2017 8:49:59 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/3/2017 8:49:59 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/3/2017 8:49:59 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/3/2017 8:49:57 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/3/2017 8:49:56 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/3/2017 8:49:56 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/3/2017 8:49:56 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	3406	Server	26 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/3/2017 8:49:54 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3556 at 8/2/2017 7:11:51 PM (local) 8/2/2017 1:41:51 PM (UTC). This is an informational message only; no user action is required.
Information	8/3/2017 8:49:52 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/3/2017 8:49:52 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/3/2017 8:49:52 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/3/2017 8:49:52 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/3/2017 8:49:52 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3628.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/3/2017 8:49:51 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/3/2017 8:49:40 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/3/2017 8:49:33 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/3/2017 8:49:21 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/3/2017 8:49:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/3/2017 8:49:21 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/2/2017 10:27:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 10:12:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:57:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:46:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e0cbd165-779d-11e7-a2a2-80000bd6758f
Report Status: 0"
Information	8/2/2017 9:42:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:28:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 9:28:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:40Z. Reason: GVLK.
Information	8/2/2017 9:27:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:23:39 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 9:23:39 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258660)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 9:23:39 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 9:23:37 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 9:11:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:56:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:41:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:32:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 8:27:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 8:27:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 8:27:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 8:26:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:11:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:07:39 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/2/2017 8:02:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 7:57:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 7:57:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 7:57:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 7:56:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:40:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:33:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 7:28:00 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 7:28:00 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 7:28:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 7:27:17 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 7:27:17 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:17Z. Reason: GVLK.
Information	8/2/2017 7:22:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 7:22:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 7:22:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 7:22:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 7:21:13 PM	McLogEvent	257	None	The scan of C:\myworks\cms\old_code\CMS-Serverside-Components\ServerSideBDD\src\test\resources\testdata\uploaddocument\TestFileLimit.pdf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8609.0000.
Information	8/2/2017 7:20:40 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 7:20:40 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:38Z. Reason: GVLK.
Information	8/2/2017 7:18:13 PM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8609.0000.
Information	8/2/2017 7:14:50 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/2/2017 7:13:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8609.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/2/2017 7:13:38 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 7:13:37 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 7:13:36 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 7:13:36 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/2/2017 7:12:56 PM	ESENT	302	Logging/Recovery	Windows (6312) Windows: The database engine has successfully completed recovery steps.
Information	8/2/2017 7:12:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 7:12:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258780)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 7:12:52 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 7:12:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 7:12:49 PM	ESENT	301	Logging/Recovery	Windows (6312) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/2/2017 7:12:48 PM	ESENT	300	Logging/Recovery	Windows (6312) Windows: The database engine is initiating recovery steps.
Information	8/2/2017 7:12:48 PM	ESENT	102	General	Windows (6312) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/2/2017 7:12:32 PM	Service1	0	None	Service started successfully.
Error	8/2/2017 7:12:13 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/2/2017 7:12:13 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/2/2017 7:12:10 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/2/2017 7:12:04 PM	PostgreSQL	0	None	"2017-08-02 19:12:04 IST LOG:  redirecting log output to logging collector process
2017-08-02 19:12:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/2/2017 7:12:04 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/2/2017 7:12:03 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/2/2017 7:12:02 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/2/2017 7:12:01 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/2/2017 7:12:00 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/2/2017 7:12:00 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/2/2017 7:12:00 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/2/2017 7:12:00 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/2/2017 7:12:00 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/2/2017 7:11:56 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/2/2017 7:11:55 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/2/2017 7:11:55 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/2/2017 7:11:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/2/2017 7:11:55 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/2/2017 7:11:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/2/2017 7:11:53 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	3406	Server	36 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/2/2017 7:11:51 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3552 at 8/2/2017 2:19:50 PM (local) 8/2/2017 8:49:50 AM (UTC). This is an informational message only; no user action is required.
Information	8/2/2017 7:11:49 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/2/2017 7:11:49 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/2/2017 7:11:49 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/2/2017 7:11:49 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/2/2017 7:11:49 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3556.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/2/2017 7:11:48 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/2/2017 7:11:41 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/2/2017 7:11:35 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 7:11:25 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/2/2017 7:11:25 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/2/2017 7:11:25 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/2/2017 6:52:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:37:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 6:36:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:21:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:06:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:51:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:36:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:21:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:05:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:50:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:46:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f6eb2066-7773-11e7-8d09-80000bd6758f
Report Status: 0"
Information	8/2/2017 4:43:06 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/2/2017 4:35:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:20:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:05:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:34:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:19:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:04:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 2:49:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 2:38:26 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 19, Deleted: 0, Modified: 6, Compared: 11304, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/2/2017 2:37:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/2/2017 2:37:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66437)(?)])(1 )(2 )]

"
Information	8/2/2017 2:37:44 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66437)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 2:37:44 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	8/2/2017 2:37:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 66437)(?)])(1 )(2 )]

"
Information	8/2/2017 2:37:42 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/2/2017 2:37:42 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=109637  Grace type=8.
Information	8/2/2017 2:37:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=9f34efdb-b4b2-4e5b-8c97-32d49f81c66b"
Information	8/2/2017 2:37:41 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=47a941c2-ccbc-4ae0-bf1a-bf50c53ffb6e"
Information	8/2/2017 2:37:41 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	8/2/2017 2:37:40 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 343

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 188

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 94

Information	8/2/2017 2:37:32 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 2:37:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/2/2017 2:37:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20357)(?)])(1 )(2 )]

"
Information	8/2/2017 2:37:11 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 20357)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 2:37:08 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	8/2/2017 2:36:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	8/2/2017 2:36:16 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	8/2/2017 2:35:47 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 2:35:47 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 2:35:46 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 2:28:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 2:28:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:59Z. Reason: GVLK.
Information	8/2/2017 2:23:37 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/2/2017 2:22:13 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/2/2017 2:21:31 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 2:21:30 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 2:21:28 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 2:21:26 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/2/2017 2:20:48 PM	ESENT	302	Logging/Recovery	Windows (8144) Windows: The database engine has successfully completed recovery steps.
Information	8/2/2017 2:20:47 PM	ESENT	301	Logging/Recovery	Windows (8144) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/2/2017 2:20:47 PM	ESENT	300	Logging/Recovery	Windows (8144) Windows: The database engine is initiating recovery steps.
Information	8/2/2017 2:20:47 PM	ESENT	102	General	Windows (8144) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/2/2017 2:20:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8609.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/2/2017 2:20:43 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 2:20:43 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 2:20:43 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 2:20:40 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 2:20:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/2/2017 2:20:20 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/2/2017 2:20:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/2/2017 2:20:20 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/2/2017 2:20:11 PM	Service1	0	None	Service started successfully.
Error	8/2/2017 2:20:03 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/2/2017 2:20:03 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/2/2017 2:19:59 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/2/2017 2:19:55 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/2/2017 2:19:55 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/2/2017 2:19:55 PM	PostgreSQL	0	None	"2017-08-02 14:19:55 IST LOG:  redirecting log output to logging collector process
2017-08-02 14:19:55 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/2/2017 2:19:53 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/2/2017 2:19:53 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/2/2017 2:19:52 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/2/2017 2:19:52 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	3406	Server	4 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/2/2017 2:19:50 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3716 at 8/2/2017 1:49:50 PM (local) 8/2/2017 8:19:50 AM (UTC). This is an informational message only; no user action is required.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3552.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/2/2017 2:19:49 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/2/2017 2:19:48 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/2/2017 2:19:43 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/2/2017 2:19:43 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 2:19:36 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/2/2017 2:19:36 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/2/2017 2:19:36 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/2/2017 2:10:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 2:05:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 2:05:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 2:05:20 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 1:59:23 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 1:59:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:13:22Z. Reason: GVLK.
Information	8/2/2017 1:53:37 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/2/2017 1:52:17 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 1:52:14 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 1:52:13 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 1:52:08 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/2/2017 1:51:46 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 1:51:46 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 1:51:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 1:51:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 1:51:38 PM	ESENT	302	Logging/Recovery	Windows (7448) Windows: The database engine has successfully completed recovery steps.
Information	8/2/2017 1:51:35 PM	ESENT	301	Logging/Recovery	Windows (7448) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/2/2017 1:51:34 PM	ESENT	300	Logging/Recovery	Windows (7448) Windows: The database engine is initiating recovery steps.
Information	8/2/2017 1:51:34 PM	ESENT	102	General	Windows (7448) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/2/2017 1:51:33 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8609.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/2/2017 1:51:08 PM	Service1	0	None	Service started successfully.
Error	8/2/2017 1:50:56 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/2/2017 1:50:56 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/2/2017 1:50:45 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/2/2017 1:50:45 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/2/2017 1:50:28 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/2/2017 1:50:10 PM	PostgreSQL	0	None	"2017-08-02 13:50:10 IST LOG:  redirecting log output to logging collector process
2017-08-02 13:50:10 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/2/2017 1:50:08 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/2/2017 1:50:07 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/2/2017 1:50:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/2/2017 1:50:02 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/2/2017 1:50:02 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/2/2017 1:50:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/2/2017 1:50:02 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	8/2/2017 1:49:56 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/2/2017 1:49:55 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:54 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/2/2017 1:49:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/2/2017 1:49:52 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	8/2/2017 1:49:52 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/2/2017 1:49:52 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/2/2017 1:49:52 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/2/2017 1:49:52 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/2/2017 1:49:51 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:51 PM	MSSQL$SQLEXPRESS	3406	Server	162 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/2/2017 1:49:50 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4064 at 8/1/2017 4:55:11 PM (local) 8/1/2017 11:25:11 AM (UTC). This is an informational message only; no user action is required.
Information	8/2/2017 1:49:48 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/2/2017 1:49:48 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/2/2017 1:49:48 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/2/2017 1:49:48 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/2/2017 1:49:48 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3716.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/2/2017 1:49:47 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	8/2/2017 1:49:26 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/2/2017 1:49:19 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/2/2017 1:48:56 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/2/2017 1:48:55 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/2/2017 1:48:55 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/2/2017 1:20:37 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 1:20:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 1:09:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:53:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:38:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:23:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:10:59 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8609.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/2/2017 12:08:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 11:52:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 11:48:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 11:48:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-09T06:12:28Z. Reason: GVLK.
Information	8/2/2017 11:45:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 0bc49de3-774a-11e7-a30d-80000bd6758f
Report Status: 0"
Information	8/2/2017 11:43:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 11:43:28 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 11:43:27 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/08/02 06:13"
Information	8/2/2017 11:43:27 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/08/02 06:13, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	8/2/2017 11:38:24 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/2/2017 11:38:24 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 11:38:24 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 11:38:23 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 11:37:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 11:22:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 11:07:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 10:52:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 10:36:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 10:21:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 10:06:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:51:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:35:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:20:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 9:20:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 9:20:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 9:05:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:50:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:35:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:20:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 8:04:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:49:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:34:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:19:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 7:04:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:48:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:45:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1f59d85e-7720-11e7-a30d-80000bd6758f
Report Status: 0"
Information	8/2/2017 6:33:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:18:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 6:03:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:48:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:32:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:20:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 5:20:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 5:17:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 5:02:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:47:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:31:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:16:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 4:01:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:46:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:30:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:19:50 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	8/2/2017 3:15:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 3:11:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	8/2/2017 3:11:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/2/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/2/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21048)(?)])(1 )(2 )]

"
Information	8/2/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21048)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/2/2017 3:06:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/2/2017 3:06:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/2/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/2/2017 3:00:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 2:45:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 2:30:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 2:14:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 1:59:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 1:45:47 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 340d9402-76f6-11e7-a30d-80000bd6758f
Report Status: 0"
Information	8/2/2017 1:44:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 1:29:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 1:20:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 1:19:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/2/2017 1:14:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:58:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:43:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:28:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:13:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/2/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/1/2017 11:58:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:43:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:27:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:12:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:57:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:42:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:27:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:11:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:56:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:41:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:26:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:20:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 9:20:18 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	8/1/2017 9:19:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 9:11:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:55:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:45:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 496a6222-76cc-11e7-a30d-80000bd6758f
Report Status: 0"
Information	8/1/2017 8:40:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:32:24 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 8:32:23 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:23Z. Reason: GVLK.
Information	8/1/2017 8:27:23 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2017 8:27:23 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 8:27:23 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 8:27:23 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 8:25:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:20:35 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/1/2017 8:10:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:55:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:39:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:24:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:09:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:54:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:39:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:23:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:15:04 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 6:10:04 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 6:10:04 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 6:10:04 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 6:08:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:53:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:50:41 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2017 5:50:30 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2017 5:45:03 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 5:40:03 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 5:40:03 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 5:40:03 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 5:38:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:30:15 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	8/1/2017 5:30:07 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	8/1/2017 5:24:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 5:23:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:19:55 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 4, Deleted: 0, Modified: 2, Compared: 11287, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	8/1/2017 5:19:23 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 125

Information	8/1/2017 5:19:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 5:19:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/1/2017 5:19:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21635)(?)])(1 )(2 )]

"
Information	8/1/2017 5:19:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21635)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 5:19:01 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 5:19:01 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 5:19:00 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 5:19:00 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	8/1/2017 5:15:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 5:10:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 5:10:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 5:10:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 5:04:22 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 5:04:22 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:20Z. Reason: GVLK.
Information	8/1/2017 5:03:07 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\MICROSOFT VS CODE\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8608.0000.
Information	8/1/2017 4:58:33 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	8/1/2017 4:57:03 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/1/2017 4:57:01 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/1/2017 4:57:00 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/1/2017 4:56:56 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	8/1/2017 4:56:29 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2017 4:56:29 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 4:56:29 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 4:56:26 PM	ESENT	302	Logging/Recovery	Windows (7564) Windows: The database engine has successfully completed recovery steps.
Information	8/1/2017 4:56:25 PM	ESENT	301	Logging/Recovery	Windows (7564) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	8/1/2017 4:56:25 PM	ESENT	300	Logging/Recovery	Windows (7564) Windows: The database engine is initiating recovery steps.
Information	8/1/2017 4:56:25 PM	ESENT	102	General	Windows (7564) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	8/1/2017 4:56:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 4:56:22 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8608.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/1/2017 4:55:29 PM	PostgreSQL	0	None	Server started and accepting connections

Information	8/1/2017 4:55:27 PM	Service1	0	None	Service started successfully.
Information	8/1/2017 4:55:25 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	8/1/2017 4:55:23 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	8/1/2017 4:55:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	8/1/2017 4:55:22 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	8/1/2017 4:55:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	8/1/2017 4:55:20 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	8/1/2017 4:55:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	8/1/2017 4:55:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:19 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:18 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	8/1/2017 4:55:17 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Error	8/1/2017 4:55:17 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	8/1/2017 4:55:16 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	8/1/2017 4:55:16 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	8/1/2017 4:55:16 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	8/1/2017 4:55:15 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	8/1/2017 4:55:15 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	8/1/2017 4:55:15 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	8/1/2017 4:55:12 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:12 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:12 PM	MSSQL$SQLEXPRESS	3406	Server	34 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	8/1/2017 4:55:11 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	8/1/2017 4:55:11 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	8/1/2017 4:55:11 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	8/1/2017 4:55:11 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3760 at 7/31/2017 11:24:29 AM (local) 7/31/2017 5:54:29 AM (UTC). This is an informational message only; no user action is required.
Information	8/1/2017 4:55:11 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	8/1/2017 4:55:08 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	8/1/2017 4:55:08 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	8/1/2017 4:55:08 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	8/1/2017 4:55:08 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	8/1/2017 4:55:08 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	8/1/2017 4:55:06 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	8/1/2017 4:55:05 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	8/1/2017 4:55:04 PM	PostgreSQL	0	None	"2017-08-01 16:55:04 IST LOG:  redirecting log output to logging collector process
2017-08-01 16:55:04 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	8/1/2017 4:55:03 PM	PostgreSQL	0	None	Waiting for server startup...

Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4064.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	8/1/2017 4:54:50 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	8/1/2017 4:54:49 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	8/1/2017 4:54:49 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	8/1/2017 4:54:49 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	8/1/2017 4:54:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	8/1/2017 4:54:46 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Warning	8/1/2017 4:54:11 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	8/1/2017 4:54:05 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	8/1/2017 4:53:42 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	8/1/2017 4:53:42 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	8/1/2017 4:53:42 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	8/1/2017 4:42:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:27:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:24:25 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 4:19:28 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 359

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 234

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 141

Information	8/1/2017 4:19:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 4:18:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/1/2017 4:18:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21696)(?)])(1 )(2 )]

"
Information	8/1/2017 4:18:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21696)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 4:18:55 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 4:18:55 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 4:18:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 4:16:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 4:16:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:02Z. Reason: GVLK.
Information	8/1/2017 4:12:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:11:02 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2017 4:11:02 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 4:11:02 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 4:11:02 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 3:57:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:45:41 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5ea6db49-76a2-11e7-8d85-80000bd6758f
Report Status: 0"
Information	8/1/2017 3:42:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:27:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:11:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:01:40 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 2:56:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:56:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/1/2017 2:56:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21778)(?)])(1 )(2 )]

"
Information	8/1/2017 2:56:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21778)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 2:56:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 2:56:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 2:56:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 2:41:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:26:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:11:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:56:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:40:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:25:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:10:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:55:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:45:46 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8608.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	8/1/2017 12:40:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:35:54 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	8/1/2017 12:25:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:21:12 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	8/1/2017 12:09:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:54:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:53:14 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	8/1/2017 11:39:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:37:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 11:24:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 11:09:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:53:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:45:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 72c8b0cc-7678-11e7-8d85-80000bd6758f
Report Status: 0"
Information	8/1/2017 10:38:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:23:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 10:08:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:53:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:38:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:22:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 9:07:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:52:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:37:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:22:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 8:07:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:51:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:37:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 7:36:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:21:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:06:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 7:02:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 6:57:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 6:57:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 6:57:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 6:51:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:36:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:20:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 6:05:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:50:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:45:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 886c9c2c-764e-11e7-8d85-80000bd6758f
Report Status: 0"
Information	8/1/2017 5:35:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:20:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 5:05:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:49:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:34:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:34:37 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 4:34:36 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:36Z. Reason: GVLK.
Information	8/1/2017 4:29:36 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	8/1/2017 4:29:36 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 4:29:36 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 4:29:36 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 4:19:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 4:04:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:49:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:37:16 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	8/1/2017 3:34:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:18:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 3:11:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	8/1/2017 3:07:27 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	8/1/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	8/1/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22488)(?)])(1 )(2 )]

"
Information	8/1/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22488)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	8/1/2017 3:06:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	8/1/2017 3:06:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	8/1/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	8/1/2017 3:03:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:48:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:33:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:18:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 2:03:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:47:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:32:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:17:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 1:02:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:47:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:45:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9e64e63b-7624-11e7-8d85-80000bd6758f
Report Status: 0"
Information	8/1/2017 12:32:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:16:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	8/1/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	8/1/2017 12:01:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:46:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:37:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 11:31:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:16:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:45:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:30:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:15:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:00:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 9:45:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 9:30:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 9:14:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 8:59:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 8:44:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 8:29:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 8:14:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 7:59:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 7:45:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b476938b-75fa-11e7-8d85-80000bd6758f
Report Status: 0"
Information	7/31/2017 7:43:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 7:37:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 7:28:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 7:13:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 6:58:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 6:43:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 6:28:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 6:12:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 6:12:32 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/31/2017 5:57:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 5:42:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 5:27:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 5:12:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 4:57:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 4:41:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 4:26:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 4:11:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 3:56:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 3:41:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 3:37:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 3:25:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 3:10:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 2:55:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 2:45:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c9223735-75d0-11e7-8d85-80000bd6758f
Report Status: 0"
Information	7/31/2017 2:40:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 2:25:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 2:10:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 1:55:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 1:39:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 1:24:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 1:09:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 12:54:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 12:44:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 12:39:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 12:39:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 12:39:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 12:39:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 12:24:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 12:14:53 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 12:09:52 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 12:09:52 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 12:09:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 12:08:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:53:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/31/2017 11:53:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/31/2017 11:44:52 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 11:39:17 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 11:39:17 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:17Z. Reason: GVLK.
Information	7/31/2017 11:36:52 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 140

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 62

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 188

Information	7/31/2017 11:36:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 11:36:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2017 11:36:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23418)(?)])(1 )(2 )]

"
Information	7/31/2017 11:36:33 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23418)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2017 11:36:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 11:36:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 11:36:32 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	7/31/2017 11:36:29 AM	Microsoft Office 16	2001	None	Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Information	7/31/2017 11:34:17 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2017 11:34:17 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2017 11:34:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 11:34:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 11:33:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 11:33:02 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:00Z. Reason: GVLK.
Information	7/31/2017 11:27:15 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/31/2017 11:25:52 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2017 11:25:51 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2017 11:25:50 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2017 11:25:49 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/31/2017 11:25:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/31/2017 11:25:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2017 11:25:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 11:25:19 AM	ESENT	302	Logging/Recovery	Windows (3528) Windows: The database engine has successfully completed recovery steps.
Information	7/31/2017 11:25:15 AM	ESENT	301	Logging/Recovery	Windows (3528) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/31/2017 11:25:15 AM	ESENT	300	Logging/Recovery	Windows (3528) Windows: The database engine is initiating recovery steps.
Information	7/31/2017 11:25:15 AM	ESENT	102	General	Windows (3528) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/31/2017 11:25:13 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 11:25:12 AM	Service1	0	None	Service started successfully.
Error	7/31/2017 11:25:01 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/31/2017 11:25:01 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/31/2017 11:24:53 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8607.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	7/31/2017 11:24:47 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/31/2017 11:24:43 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/31/2017 11:24:41 AM	PostgreSQL	0	None	"2017-07-31 11:24:41 IST LOG:  redirecting log output to logging collector process
2017-07-31 11:24:41 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/31/2017 11:24:39 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/31/2017 11:24:38 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/31/2017 11:24:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/31/2017 11:24:35 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/31/2017 11:24:35 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/31/2017 11:24:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/31/2017 11:24:35 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/31/2017 11:24:34 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/31/2017 11:24:33 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/31/2017 11:24:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/31/2017 11:24:33 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/31/2017 11:24:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/31/2017 11:24:32 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/31/2017 11:24:31 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/31/2017 11:24:31 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/31/2017 11:24:29 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3560 at 7/31/2017 11:22:52 AM (local) 7/31/2017 5:52:52 AM (UTC). This is an informational message only; no user action is required.
Information	7/31/2017 11:24:28 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/31/2017 11:24:28 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/31/2017 11:24:28 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/31/2017 11:24:28 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/31/2017 11:24:28 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3760.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/31/2017 11:24:27 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/31/2017 11:24:20 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/31/2017 11:24:13 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/31/2017 11:24:04 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/31/2017 11:24:04 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/31/2017 11:24:04 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/31/2017 11:23:07 AM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	7/31/2017 11:22:54 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	7/31/2017 11:22:52 AM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	7/31/2017 11:22:40 AM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 28 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1456 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	7/31/2017 11:22:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	7/31/2017 11:22:39 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	7/31/2017 11:22:39 AM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	7/31/2017 11:22:33 AM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	7/31/2017 11:21:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 11:06:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:50:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:36:45 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/31/2017 10:36:45 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/31/2017 10:36:05 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/31/2017 10:36:04 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/31/2017 10:36:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: Automatic Reconciliation.
Information	7/31/2017 10:35:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:35:27 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 1, Deleted: 0, Modified: 7, Compared: 11181, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/31/2017 10:26:47 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎31T04:56:47.958877000Z.
Information	7/31/2017 10:26:47 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎31T04:56:47.958877000Z.
Information	7/31/2017 10:20:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:10:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 10:06:48 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/31/2017 10:06:35 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8607.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Generic.Tra!e0bb0b57a878 (ED)
"
Information	7/31/2017 10:06:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/31/2017 10:05:33 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 10:05:33 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 10:05:33 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 10:05:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 10:03:18 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/31/2017 9:58:49 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 9:58:48 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/31/2017 9:58:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/31/2017 9:58:20 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 125

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 1669

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 140

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 78

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 281

Information	7/31/2017 9:58:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/31/2017 9:57:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2017 9:57:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23517)(?)])(1 )(2 )]

"
Information	7/31/2017 9:57:37 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23517)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2017 9:57:36 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 9:57:36 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 9:57:36 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 9:57:34 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/31/2017 9:57:33 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Warning	7/31/2017 9:57:26 AM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	7/31/2017 9:57:23 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/31/2017 9:50:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/31/2017 9:40:33 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/31/2017 9:35:21 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/31/2017 9:35:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {BE57CD04-7884-4968-8310-6E79E23C345B}
Error	7/31/2017 9:35:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {BE57CD04-7884-4968-8310-6E79E23C345B}
Information	7/31/2017 9:35:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/31/2017 9:35:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23539)(?)])(1 )(2 )]

"
Information	7/31/2017 9:35:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23539)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/31/2017 9:35:20 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/31/2017 9:35:20 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/31/2017 9:35:20 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/31/2017 9:35:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 9:29:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 9:21:30 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/30/2017 9:16:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/30/2017 9:16:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/30/2017 9:16:30 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/30/2017 9:15:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/30/2017 9:15:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:21Z. Reason: GVLK.
Information	7/30/2017 9:10:21 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/30/2017 9:10:21 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/30/2017 9:10:21 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/30/2017 9:10:20 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/30/2017 9:09:03 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/30/2017 9:09:03 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:02Z. Reason: GVLK.
Information	7/30/2017 9:03:17 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/30/2017 9:02:20 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/30/2017 9:02:19 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/30/2017 9:02:18 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/30/2017 9:02:15 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/30/2017 9:02:15 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8606.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/30/2017 9:01:58 PM	ESENT	302	Logging/Recovery	Windows (8248) Windows: The database engine has successfully completed recovery steps.
Information	7/30/2017 9:01:48 PM	ESENT	301	Logging/Recovery	Windows (8248) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/30/2017 9:01:47 PM	ESENT	300	Logging/Recovery	Windows (8248) Windows: The database engine is initiating recovery steps.
Information	7/30/2017 9:01:47 PM	ESENT	102	General	Windows (8248) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/30/2017 9:01:14 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/30/2017 9:01:14 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/30/2017 9:01:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/30/2017 9:01:12 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/30/2017 9:01:08 PM	Service1	0	None	Service started successfully.
Error	7/30/2017 9:00:57 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/30/2017 9:00:57 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/30/2017 9:00:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/30/2017 9:00:54 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/30/2017 9:00:54 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/30/2017 9:00:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/30/2017 9:00:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/30/2017 9:00:52 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/30/2017 9:00:51 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/30/2017 9:00:46 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/30/2017 9:00:45 PM	PostgreSQL	0	None	"2017-07-30 21:00:45 IST LOG:  redirecting log output to logging collector process
2017-07-30 21:00:45 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/30/2017 9:00:45 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/30/2017 9:00:44 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/30/2017 9:00:43 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/30/2017 9:00:42 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/30/2017 9:00:41 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:40 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:39 PM	MSSQL$SQLEXPRESS	3406	Server	46 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/30/2017 9:00:37 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/30/2017 9:00:37 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/30/2017 9:00:37 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/30/2017 9:00:37 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/30/2017 9:00:37 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3580 at 7/27/2017 3:04:49 PM (local) 7/27/2017 9:34:49 AM (UTC). This is an informational message only; no user action is required.
Information	7/30/2017 9:00:35 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/30/2017 9:00:35 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/30/2017 9:00:35 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/30/2017 9:00:35 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/30/2017 9:00:35 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3560.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/30/2017 9:00:34 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/30/2017 9:00:25 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/30/2017 9:00:20 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/30/2017 9:00:07 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/30/2017 9:00:07 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/30/2017 9:00:07 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/30/2017 8:52:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 8:37:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 8:22:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 8:13:32 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8606.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	7/30/2017 8:09:12 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/30/2017 8:09:11 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:11Z. Reason: GVLK.
Information	7/30/2017 8:06:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/30/2017 8:04:11 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/30/2017 8:04:11 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/30/2017 8:04:11 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/30/2017 8:04:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/30/2017 8:01:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ceec63ca-7533-11e7-9f2c-80000bd6758f
Report Status: 0"
Information	7/30/2017 7:57:00 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/30/2017 7:51:52 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485947
"
Error	7/30/2017 7:51:52 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0005; CorrelationId: {3243E029-B9A0-4FFF-89EB-345815439BAD}
Information	7/30/2017 7:51:51 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/30/2017 7:51:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24363)(?)])(1 )(2 )]

"
Information	7/30/2017 7:51:50 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24363)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/30/2017 7:51:50 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/30/2017 7:51:50 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/30/2017 7:51:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/30/2017 7:51:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/28/2017 6:55:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/28/2017 6:40:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/28/2017 6:36:02 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 818e547a-7395-11e7-9f2c-80000bd6758f
Report Status: 0"
Information	7/28/2017 6:31:01 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/28/2017 6:27:10 PM	McLogEvent	257	None	The scan of C:\Users\212558710\AppData\Local\atom\app-1.16.0\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8603.0000.
Information	7/28/2017 6:27:10 PM	Microsoft-Windows-Winlogon	1002	None	The shell stopped unexpectedly and Explorer.exe was restarted.
Error	7/28/2017 6:26:01 PM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/28/2017 6:26:01 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {9674E4D8-D1C3-4396-9224-3D57298BAC4D}
Error	7/28/2017 6:26:01 PM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {9674E4D8-D1C3-4396-9224-3D57298BAC4D}
Information	7/28/2017 6:25:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/28/2017 6:25:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27329)(?)])(1 )(2 )]

"
Information	7/28/2017 6:25:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 27329)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/28/2017 6:25:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/28/2017 6:25:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/28/2017 6:25:58 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/28/2017 6:25:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 6:50:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 6:35:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 6:20:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 6:05:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 5:50:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 5:35:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 5:19:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 5:04:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 4:49:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 4:34:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 4:25:16 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 4:20:16 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2017 4:20:16 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 4:20:16 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 4:19:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 4:04:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 3:55:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 3:50:15 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2017 3:50:15 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 3:50:15 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 3:48:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 3:33:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 3:25:29 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 3:21:18 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F32180131F0}. Client Process Id: 6968.
Information	7/27/2017 3:21:18 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java 8 Update 131. Product Version: 8.0.1310.11. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	7/27/2017 3:21:18 PM	MsiInstaller	11724	None	Product: Java 8 Update 131 -- Removal completed successfully.
Information	7/27/2017 3:20:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2017 3:20:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 3:20:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 3:20:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F32180131F0}. Client Process Id: 6968.
Information	7/27/2017 3:20:17 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F64180131F0}. Client Process Id: 6968.
Information	7/27/2017 3:20:17 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java 8 Update 131 (64-bit). Product Version: 8.0.1310.11. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	7/27/2017 3:20:17 PM	MsiInstaller	11724	None	Product: Java 8 Update 131 (64-bit) -- Removal completed successfully.
Information	7/27/2017 3:18:53 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cc283130-72b0-11e7-9f2c-80000bd6758f
Report Status: 0"
Information	7/27/2017 3:18:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎27T09:48:47.007384400Z.
Information	7/27/2017 3:18:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {26A24AE4-039D-4CA4-87B4-2F64180131F0}. Client Process Id: 6968.
Information	7/27/2017 3:18:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144\au.msi. Client Process Id: 6968.
Information	7/27/2017 3:18:48 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java Auto Updater. Product Version: 2.8.144.1. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 0.
Information	7/27/2017 3:18:48 PM	MsiInstaller	11707	None	Product: Java Auto Updater -- Installation completed successfully.
Information	7/27/2017 3:18:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎27T09:48:47.007384400Z.
Information	7/27/2017 3:18:46 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎27T09:48:39.879509700Z.
Information	7/27/2017 3:18:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144\au.msi. Client Process Id: 6968.
Information	7/27/2017 3:18:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {4A03706F-666A-4037-7777-5F2748764D10}. Client Process Id: 6968.
Information	7/27/2017 3:18:46 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Java Auto Updater. Product Version: 2.8.131.11. Product Language: 1033. Manufacturer: Oracle Corporation. Removal success or error status: 0.
Information	7/27/2017 3:18:46 PM	MsiInstaller	11724	None	Product: Java Auto Updater -- Removal completed successfully.
Information	7/27/2017 3:18:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎27T09:48:39.879509700Z.
Information	7/27/2017 3:18:39 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {4A03706F-666A-4037-7777-5F2748764D10}. Client Process Id: 6968.
Information	7/27/2017 3:18:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144_x64\jre1.8.0_144patch64.msi. Client Process Id: 6968.
Information	7/27/2017 3:18:39 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java 8 Update 144 (64-bit). Product Version: 8.0.1440.1. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 0.
Information	7/27/2017 3:18:39 PM	MsiInstaller	11707	None	Product: Java 8 Update 144 (64-bit) -- Installation completed successfully.
Information	7/27/2017 3:18:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144_x64\jre1.8.0_144patch64.msi. Client Process Id: 6968.
Information	7/27/2017 3:18:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144\jre1.8.0_144patch.msi. Client Process Id: 6968.
Information	7/27/2017 3:18:06 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Java 8 Update 144. Product Version: 8.0.1440.1. Product Language: 1033. Manufacturer: Oracle Corporation. Installation success or error status: 0.
Information	7/27/2017 3:18:06 PM	MsiInstaller	11707	None	Product: Java 8 Update 144 -- Installation completed successfully.
Information	7/27/2017 3:17:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 3:17:36 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:35Z. Reason: GVLK.
Information	7/27/2017 3:17:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558710\AppData\LocalLow\Oracle\Java\jre1.8.0_144\jre1.8.0_144patch.msi. Client Process Id: 6968.
Information	7/27/2017 3:07:58 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/27/2017 3:06:43 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2017 3:06:42 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2017 3:06:39 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2017 3:06:37 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/27/2017 3:06:06 PM	ESENT	302	Logging/Recovery	Windows (8816) Windows: The database engine has successfully completed recovery steps.
Information	7/27/2017 3:06:06 PM	ESENT	301	Logging/Recovery	Windows (8816) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/27/2017 3:06:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2017 3:06:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2017 3:06:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 3:05:59 PM	ESENT	301	Logging/Recovery	Windows (8816) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03C42.log.
Information	7/27/2017 3:05:59 PM	ESENT	300	Logging/Recovery	Windows (8816) Windows: The database engine is initiating recovery steps.
Information	7/27/2017 3:05:59 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 3:05:59 PM	ESENT	102	General	Windows (8816) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/27/2017 3:05:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8603.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/27/2017 3:05:43 PM	Service1	0	None	Service started successfully.
Error	7/27/2017 3:05:26 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/27/2017 3:05:24 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/27/2017 3:05:19 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/27/2017 3:05:19 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/27/2017 3:05:16 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/27/2017 3:05:09 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/27/2017 3:05:09 PM	PostgreSQL	0	None	"2017-07-27 15:05:09 IST LOG:  redirecting log output to logging collector process
2017-07-27 15:05:09 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/27/2017 3:05:04 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/27/2017 3:04:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/27/2017 3:04:58 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/27/2017 3:04:58 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/27/2017 3:04:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/27/2017 3:04:58 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/27/2017 3:04:55 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:53 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:52 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/27/2017 3:04:51 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	3406	Server	75 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/27/2017 3:04:49 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3828 at 7/24/2017 3:00:57 PM (local) 7/24/2017 9:30:57 AM (UTC). This is an informational message only; no user action is required.
Information	7/27/2017 3:04:47 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/27/2017 3:04:47 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/27/2017 3:04:47 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/27/2017 3:04:47 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/27/2017 3:04:47 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3580.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/27/2017 3:04:46 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/27/2017 3:04:32 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/27/2017 3:04:27 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/27/2017 3:04:11 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/27/2017 3:04:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/27/2017 3:04:11 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/27/2017 2:37:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 2:29:53 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 2:29:53 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:08:53Z. Reason: GVLK.
Information	7/27/2017 2:24:52 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/27/2017 2:24:52 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2017 2:24:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 2:24:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 2:09:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2017 2:09:36 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/27/2017 2:09:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2017 2:07:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 1:37:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 1:07:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 12:37:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 12:36:18 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/27/2017 12:35:36 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 0, Deleted: 0, Modified: 41, Compared: 11144, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/27/2017 12:35:02 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/27/2017 12:35:02 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: Automatic Reconciliation.
Information	7/27/2017 12:07:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 11:37:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 11:18:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/27/2017 11:18:30 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/27/2017 11:07:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 10:38:15 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8603.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/27/2017 10:37:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/27/2017 10:18:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: db6e8fcb-7286-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/27/2017 10:13:36 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/27/2017 10:09:36 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/27/2017 10:09:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2017 10:09:22 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/27/2017 10:09:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/27/2017 10:08:36 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/27/2017 10:08:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29266)(?)])(1 )(2 )]

"
Information	7/27/2017 10:08:35 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 29266)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/27/2017 10:08:35 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/27/2017 10:08:35 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/27/2017 10:08:34 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/27/2017 10:07:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 8:37:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 8:18:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8d6cd2c3-7211-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/26/2017 8:07:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 7:37:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 7:07:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 6:52:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/26/2017 6:47:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2017 6:47:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30187)(?)])(1 )(2 )]

"
Information	7/26/2017 6:47:09 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30187)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 6:47:09 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2017 6:47:09 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2017 6:47:09 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/26/2017 6:45:57 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/26/2017 6:40:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30194)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30194)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	1016	None	"Proof of Purchase installed successfully. 
ACID=3ad61e22-e4fe-497f-bdb1-3e51bd872173
PKeyId=a82b4eda-c8b9-a341-8ea3-d8f2cfbfb411"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2017 6:40:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2017 6:40:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/26/2017 6:37:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 6:07:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/26/2017 6:07:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 5:37:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 5:07:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 4:37:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 4:07:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 3:37:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 3:35:26 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/26/2017 3:35:09 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/26/2017 3:35:07 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/26/2017 3:18:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a2f1ebca-71e7-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/26/2017 3:07:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 2:37:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 2:07:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/26/2017 2:07:11 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 432 ms, redo 0 ms, undo 880 ms.) This is an informational message only. No user action is required.
Information	7/26/2017 2:07:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 1:37:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 1:06:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 12:36:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 12:06:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 11:43:55 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2017 11:43:55 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-08-02T06:07:55Z. Reason: GVLK.
Information	7/26/2017 11:38:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 11:38:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 11:38:54 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/07/26 06:08"
Information	7/26/2017 11:38:53 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/07/26 06:08, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/26/2017 11:36:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 11:33:50 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2017 11:33:50 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 11:33:50 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2017 11:33:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/26/2017 11:06:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 10:37:01 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8602.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/26/2017 10:36:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/26/2017 10:17:52 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 94ae0012-71bd-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/26/2017 10:15:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/26/2017 10:15:50 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:50Z. Reason: GVLK.
Information	7/26/2017 10:12:31 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/26/2017 10:12:20 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/26/2017 10:10:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/26/2017 10:10:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 10:10:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2017 10:10:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/26/2017 10:08:48 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/26/2017 10:07:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 401

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/26/2017 10:07:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/26/2017 10:07:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30707)(?)])(1 )(2 )]

"
Information	7/26/2017 10:07:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 30707)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/26/2017 10:07:19 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/26/2017 10:07:19 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/26/2017 10:07:18 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/26/2017 10:06:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 8:16:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 8:00:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:45:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:30:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:15:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:00:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:51:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2017 6:44:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:29:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:14:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:06:27 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/25/2017 6:05:55 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/25/2017 5:59:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:44:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:29:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:13:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:58:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:56:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 202bdb7f-712c-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/25/2017 4:43:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:28:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:13:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:57:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:42:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:27:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:21:06 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/25/2017 3:12:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:57:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:51:40 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2017 2:41:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:26:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:11:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:56:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:41:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:26:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:10:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:59:43 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8601.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/25/2017 12:55:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:40:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:25:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:10:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 11:56:36 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35668106-7102-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/25/2017 11:54:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 11:39:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 11:24:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 11:09:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 10:56:25 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/25/2017 10:54:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 10:51:26 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2017 10:51:25 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 31

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 78

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 47

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

Information	7/25/2017 10:51:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/25/2017 10:51:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32103)(?)])(1 )(2 )]

"
Information	7/25/2017 10:51:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32103)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2017 10:51:08 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/25/2017 10:51:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2017 10:51:08 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/25/2017 10:38:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 10:23:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 10:08:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 9:53:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 9:38:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 9:23:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 9:10:58 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2017 9:10:58 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:58Z. Reason: GVLK.
Information	7/25/2017 9:07:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 9:02:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2017 9:02:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250740)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2017 9:02:26 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2017 9:02:26 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/25/2017 8:52:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 8:37:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 8:22:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 8:07:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:52:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:44:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2017 7:36:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:21:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 7:06:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:56:31 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4965703c-70d8-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/25/2017 6:51:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:36:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:21:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 6:05:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:50:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:37:46 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2017 5:37:34 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2017 5:35:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:20:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 5:11:34 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/25/2017 5:05:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:49:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:49:53 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/25/2017 4:44:53 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/25/2017 4:44:53 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2017 4:44:53 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/25/2017 4:34:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:21:02 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/25/2017 4:20:53 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/25/2017 4:19:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 4:04:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:49:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:44:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/25/2017 3:34:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:18:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 3:11:13 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/25/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/25/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32568)(?)])(1 )(2 )]

"
Information	7/25/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32568)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2017 3:06:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/25/2017 3:06:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/25/2017 3:03:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:48:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:33:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:18:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 2:03:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:56:29 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5f688387-70ae-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/25/2017 1:47:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:32:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:17:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 1:02:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:47:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:32:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:24:13 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/25/2017 12:24:13 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:12Z. Reason: GVLK.
Information	7/25/2017 12:19:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/25/2017 12:19:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251280)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/25/2017 12:19:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/25/2017 12:19:12 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/25/2017 12:16:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/25/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/25/2017 12:01:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:46:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:44:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2017 11:31:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:16:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:01:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 10:45:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 10:30:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 10:15:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 10:00:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 9:45:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 9:30:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 9:14:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 8:59:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 8:56:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7543faf0-7084-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/24/2017 8:44:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 8:29:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 8:14:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 7:59:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 7:44:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2017 7:44:02 PM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/24/2017 7:43:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 7:02:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 6:47:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 6:31:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 6:16:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 6:01:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 5:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 5:31:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 5:15:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 5:00:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 4:45:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 4:30:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 4:21:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 4:16:24 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 4:16:24 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 4:16:24 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 4:15:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 3:59:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 3:56:25 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244008
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8b0adae9-705a-11e7-8bbd-80000bd6758f
Report Status: 0"
Information	7/24/2017 3:51:23 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 3:46:23 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 3:46:23 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 3:46:23 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 3:44:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 3:29:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 3:21:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 3:13:51 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 63

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 343

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 234

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 125

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 218

Information	7/24/2017 3:13:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2017 3:13:28 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	7/24/2017 3:13:15 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2017 3:13:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33281)(?)])(1 )(2 )]

"
Information	7/24/2017 3:13:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33281)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 3:13:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 3:13:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 3:13:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 3:10:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 3:10:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:59Z. Reason: GVLK.
Information	7/24/2017 3:04:14 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/24/2017 3:03:02 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 3:03:00 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 3:02:58 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 3:02:56 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/24/2017 3:02:24 PM	ESENT	302	Logging/Recovery	Windows (8720) Windows: The database engine has successfully completed recovery steps.
Information	7/24/2017 3:02:22 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2017 3:02:22 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251820)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 3:02:22 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 3:02:17 PM	ESENT	301	Logging/Recovery	Windows (8720) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/24/2017 3:02:17 PM	ESENT	300	Logging/Recovery	Windows (8720) Windows: The database engine is initiating recovery steps.
Information	7/24/2017 3:02:17 PM	ESENT	102	General	Windows (8720) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/24/2017 3:02:15 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 3:02:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8600.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/24/2017 3:01:56 PM	Service1	0	None	Service started successfully.
Error	7/24/2017 3:01:35 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/24/2017 3:01:35 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/24/2017 3:01:27 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/24/2017 3:01:23 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/24/2017 3:01:23 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/24/2017 3:01:19 PM	PostgreSQL	0	None	"2017-07-24 15:01:19 IST LOG:  redirecting log output to logging collector process
2017-07-24 15:01:19 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/24/2017 3:01:14 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/24/2017 3:01:12 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/24/2017 3:01:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/24/2017 3:01:06 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/24/2017 3:01:06 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/24/2017 3:01:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/24/2017 3:01:06 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/24/2017 3:01:05 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/24/2017 3:01:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/24/2017 3:01:03 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/24/2017 3:01:01 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/24/2017 3:01:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/24/2017 3:00:59 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/24/2017 3:00:59 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/24/2017 3:00:59 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/24/2017 3:00:59 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/24/2017 3:00:59 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/24/2017 3:00:58 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/24/2017 3:00:58 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:00:58 PM	MSSQL$SQLEXPRESS	3406	Server	28 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/24/2017 3:00:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/24/2017 3:00:58 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3712 at 7/24/2017 11:14:55 AM (local) 7/24/2017 5:44:55 AM (UTC). This is an informational message only; no user action is required.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/24/2017 3:00:57 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3828.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/24/2017 3:00:56 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/24/2017 3:00:36 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/24/2017 3:00:28 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 3:00:12 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/24/2017 3:00:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/24/2017 3:00:12 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/24/2017 2:45:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 2:30:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 2:15:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 2:00:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 1:45:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 1:32:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 1:32:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:57Z. Reason: GVLK.
Information	7/24/2017 1:30:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 1:27:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2017 1:27:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 1:27:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 1:27:54 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 1:14:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 12:59:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 12:59:37 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/24/2017 12:48:29 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/24/2017 12:44:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 12:29:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 12:24:10 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8600.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/24/2017 12:14:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:59:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:51:31 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/24/2017 11:51:31 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: Automatic Reconciliation.
Information	7/24/2017 11:43:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 11:35:24 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 13, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/24/2017 11:34:32 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 34, Deleted: 0, Modified: 52, Compared: 10956, Queries: 0, Results: 0, Version: 16.0.7766.6610.
Information	7/24/2017 11:33:09 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 11:33:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2017 11:32:46 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/24/2017 11:28:11 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10988.
Information	7/24/2017 11:28:11 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.7766.2096. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/24/2017 11:28:11 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	7/24/2017 11:28:10 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/24/2017 11:28:09 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33506)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 11:28:09 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/24/2017 11:28:08 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/24/2017 11:28:08 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 11:28:07 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 11:28:07 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 11:28:06 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 11:28:04 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 11:27:44 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:44 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:44 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2096. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/24/2017 11:27:44 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	7/24/2017 11:27:43 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:43 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:43 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2096. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/24/2017 11:27:43 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	7/24/2017 11:27:39 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:39 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/24/2017 11:27:38 AM	ESENT	102	General	Windows (5528) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/24/2017 11:27:38 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:38 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2096. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/24/2017 11:27:38 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	7/24/2017 11:27:22 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:17 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/24/2017 11:27:17 AM	ESENT	103	General	Windows (9992) Windows: The database engine stopped the instance (0).
Information	7/24/2017 11:27:16 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:27:16 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2096. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	7/24/2017 11:27:16 AM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	7/24/2017 11:25:59 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 10988.
Information	7/24/2017 11:25:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/24/2017 11:25:47 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 0

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 15

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 468

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 62

Information	7/24/2017 11:25:42 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	7/24/2017 11:25:41 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/24/2017 11:25:40 AM	ESENT	102	General	Windows (9992) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/24/2017 11:25:37 AM	ESENT	103	General	Windows (7424) Windows: The database engine stopped the instance (0).
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:37 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:36 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:36 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:36 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:36 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:36 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	7/24/2017 11:25:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:34 AM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	7/24/2017 11:25:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2017 11:25:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33509)(?)])(1 )(2 )]

"
Information	7/24/2017 11:25:20 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33509)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 11:25:20 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	7/24/2017 11:25:20 AM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	7/24/2017 11:25:15 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	7/24/2017 11:25:09 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Microsoft Outlook'.
Information	7/24/2017 11:25:08 AM	Microsoft-Windows-RestartManager	10003	None	Restarting application or service 'Send to OneNote Tool'.
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=89fdcb09-5030-4b80-bc8a-8e98c230e2d0"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=52cb0865-4092-4535-bebc-bbad8d5f6500"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=e7be914e-23b4-4cd4-b058-21a0cff6f94f"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7da5c758-9205-4543-b52c-cfac434627f1"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=20ce7206-dad6-4f4f-87f8-fcad4a145355"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=758c1bbf-8ebc-4ac7-b053-a326920e8b68"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=cf3ed145-dfd8-4e97-bf91-11e01f057d5e"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5b5ea619-1170-4d9e-8fc8-0960888b7431"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6f429561-d63d-42e3-8b66-e2d61597c80e"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bbf7509f-b3a2-4713-a815-71e1d96d7490"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=aa746716-d1e2-44d9-8f47-c07f894832df"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0d1964ec-3df5-4502-a64a-f36512f035f9"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=613452e6-1730-4764-8ef6-b2115d970264"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ebfd22a7-76e0-46d1-9a2c-658aa3fe5a96"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=47745e77-0f59-438c-88cc-f1f4c2935f65"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=987e2dfd-9019-49b1-8f46-48e3b6af2b74"
Information	7/24/2017 11:25:08 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=81ce275d-af14-4c87-9270-86028e12069f"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2571a19e-089a-4969-b5e8-ddffbf9fa049"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d31537c8-d813-4cfd-96ee-044661f5e16e"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=871ba58b-a95c-4e66-8f30-b7af01d7767d"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5d37def8-1e50-4fe6-97dc-373e1b68f743"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=80f4fb6c-b614-430b-8949-b76a82b9feb1"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6a75e296-2f1d-4a3c-acb8-b96a377f6e54"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5ea9fc4d-7f3f-404c-9ee7-269a78dd29cd"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=37339799-7bda-47f7-9b01-0160d6ec30ee"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7be03f78-fec3-481c-9b83-0cb67664675e"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=835b0016-93af-42ef-bb26-5fc1960509f8"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=9b3eca54-55d1-4c70-b00b-04d742afa893"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=545f91f2-7de4-40d3-b8a8-516609dba545"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f8ef987c-d49b-4575-b3d2-ad3ba94441fb"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6ced6197-e10b-4252-9e5d-c71b30302235"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=ac8ed6d5-96bb-47ac-8f6c-13d269009f86"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f2ed2aa1-f04a-495f-af23-bac9060aaee1"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a14fd7bb-507b-4e24-9fd2-0a69eca78cb4"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=65f86812-c661-47b1-9c4f-31850f714943"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=02857536-cf15-4c0d-b44a-a1b64c46d07d"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=60f9f3e8-c1be-4b13-aead-7005b2c806b6"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=0db9cf5f-dfa7-4d40-b430-1da4b8e2259a"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8e25612b-ee1d-4f26-8799-740f69243a17"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=87b19075-f273-4502-9167-158800827d43"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=85815fb6-f287-4ff9-9155-d13103ce14f1"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2379f603-aa01-44d3-92c2-d8aa002523c1"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bbb7ec1c-d627-4371-a4a7-b311eda6dbcc"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=57d699dc-639e-495f-8c22-d4af696034ed"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=bc1b8bd5-96cf-4c77-9c52-08590fa81818"
Information	7/24/2017 11:25:07 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=be089e7b-571b-4330-9a09-63cb6d7c8d59"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ce62428d-1958-4a99-9d9d-83d4260f990e"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ab7bd8f5-8934-47d2-9ee9-7c09aeeaabf4"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=22be7fa2-ca89-4e32-b4c3-41ede6a99d71"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=13351a6e-df68-443d-8edd-d9f4cae1ff67"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=303d5c42-d5db-413c-a214-043c26110ff2"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32814545-fe45-4806-bfab-db23cb8ed04f"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fcd5ee65-6dc1-4ede-9830-c75ffa9e4733"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe73e4ab-0060-4888-9b1b-83cc923cd076"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bbbd973-6d0f-448f-aa0e-91c43fa94eb7"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f0a52c37-71c8-4b1c-b178-43b4ef6b145a"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ee2c65f4-85f2-4006-8e11-7dc63f23b498"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c9ce7541-001c-4779-b883-f5169b882b41"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d153ef14-af6e-474c-84d5-2303e980041a"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7d86124e-eb3b-46a0-b815-3b697f47fd7c"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=91370939-d8a9-49f2-a80e-836f8d3676bc"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2665797f-c833-48db-a0ea-9b88351cbc44"
Information	7/24/2017 11:25:06 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	7/24/2017 11:25:05 AM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	7/24/2017 11:25:04 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 11:25:04 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 11:25:03 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 11:24:34 AM	Microsoft-Windows-RestartManager	10005	None	Machine restart is required.
Warning	7/24/2017 11:24:18 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The filtering process has been terminated  (HRESULT : 0x80040db4) (0x80040db4)
"
Information	7/24/2017 11:23:46 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/24/2017 11:23:45 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:41Z. Reason: GVLK.
Information	7/24/2017 11:22:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/24/2017 11:22:18 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <mapi16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The filtering process has been terminated  (HRESULT : 0x80040db4) (0x80040db4)
"
Information	7/24/2017 11:17:55 AM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/24/2017 11:17:33 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Microsoft Outlook'.
Error	7/24/2017 11:17:33 AM	Microsoft-Windows-RestartManager	10006	None	Application or service 'Microsoft Outlook' could not be shut down.
Information	7/24/2017 11:17:33 AM	Microsoft-Windows-RestartManager	10002	None	Shutting down application or service 'Send to OneNote Tool'.
Information	7/24/2017 11:17:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954430

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/24/2017 11:17:27 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 218

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 983

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 577

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 62

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 390

Information	7/24/2017 11:17:04 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst for the following reason: The store was last opened on a different machine.
Information	7/24/2017 11:16:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2017 11:16:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33518)(?)])(1 )(2 )]

"
Information	7/24/2017 11:16:57 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33518)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 11:16:57 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 11:16:57 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 11:16:55 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 11:16:49 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8598.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/24/2017 11:16:44 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎24T05:46:44.153498000Z.
Information	7/24/2017 11:16:44 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	7/24/2017 11:16:38 AM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 11:16:36 AM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 11:16:35 AM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 11:16:34 AM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/24/2017 11:15:54 AM	ESENT	302	Logging/Recovery	Windows (7424) Windows: The database engine has successfully completed recovery steps.
Information	7/24/2017 11:15:52 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/24/2017 11:15:52 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 11:15:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 11:15:49 AM	ESENT	301	Logging/Recovery	Windows (7424) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/24/2017 11:15:49 AM	ESENT	300	Logging/Recovery	Windows (7424) Windows: The database engine is initiating recovery steps.
Information	7/24/2017 11:15:49 AM	ESENT	102	General	Windows (7424) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/24/2017 11:15:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 11:15:38 AM	Service1	0	None	Service started successfully.
Error	7/24/2017 11:15:19 AM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/24/2017 11:15:19 AM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/24/2017 11:15:14 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/24/2017 11:15:10 AM	PostgreSQL	0	None	"2017-07-24 11:15:10 IST LOG:  redirecting log output to logging collector process
2017-07-24 11:15:10 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/24/2017 11:15:09 AM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/24/2017 11:15:08 AM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/24/2017 11:15:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/24/2017 11:15:07 AM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/24/2017 11:15:07 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/24/2017 11:15:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/24/2017 11:15:07 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/24/2017 11:15:07 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/24/2017 11:15:07 AM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/24/2017 11:15:01 AM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/24/2017 11:15:00 AM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/24/2017 11:15:00 AM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/24/2017 11:15:00 AM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/24/2017 11:15:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:59 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/24/2017 11:14:58 AM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/24/2017 11:14:57 AM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/24/2017 11:14:57 AM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/24/2017 11:14:57 AM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/24/2017 11:14:56 AM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:56 AM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:56 AM	MSSQL$SQLEXPRESS	3406	Server	181 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/24/2017 11:14:55 AM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3500 at 7/19/2017 6:26:49 PM (local) 7/19/2017 12:56:49 PM (UTC). This is an informational message only; no user action is required.
Information	7/24/2017 11:14:53 AM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/24/2017 11:14:53 AM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/24/2017 11:14:53 AM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/24/2017 11:14:53 AM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/24/2017 11:14:53 AM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3712.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/24/2017 11:14:52 AM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/24/2017 11:14:42 AM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/24/2017 11:14:36 AM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/24/2017 11:14:22 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/24/2017 11:14:22 AM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/24/2017 11:14:22 AM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/24/2017 11:01:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/24/2017 10:51:45 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Error	7/24/2017 10:46:30 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/24/2017 10:46:30 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {4041C79B-ADE0-42C0-92C0-3F8F20911DC6}
Error	7/24/2017 10:46:30 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {4041C79B-ADE0-42C0-92C0-3F8F20911DC6}
Information	7/24/2017 10:46:30 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/24/2017 10:46:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33548)(?)])(1 )(2 )]

"
Information	7/24/2017 10:46:29 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33548)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/24/2017 10:46:29 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/24/2017 10:46:29 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/24/2017 10:46:28 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/24/2017 10:46:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/24/2017 10:46:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 4:54:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 4:39:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 4:33:48 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8598.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/22/2017 4:24:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 4:09:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 3:53:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/22/2017 3:49:08 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 32013d9a-6ec7-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/22/2017 3:44:22 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/22/2017 3:39:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/22/2017 3:39:21 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36135)(?)])(1 )(2 )]

"
Information	7/22/2017 3:39:20 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 36135)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/22/2017 3:39:20 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/22/2017 3:39:20 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/22/2017 3:39:19 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/22/2017 3:38:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/22/2017 3:38:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 4:53:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/21/2017 4:48:20 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 16

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 218

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 172

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 93

Information	7/21/2017 4:48:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 4:47:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/21/2017 4:47:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37507)(?)])(1 )(2 )]

"
Information	7/21/2017 4:47:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37507)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/21/2017 4:47:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/21/2017 4:47:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/21/2017 4:47:54 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/21/2017 4:44:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 4:29:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 4:14:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 3:59:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 3:44:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 3:28:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 3:21:40 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 31494c6a-6dfa-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/21/2017 3:13:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 2:58:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 2:43:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 2:28:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 2:13:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 2:11:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 2:10:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 2:10:29 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 2:03:47 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/21/2017 2:03:32 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/21/2017 1:57:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 1:42:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 1:27:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 1:12:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 12:59:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/21/2017 12:59:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:54Z. Reason: GVLK.
Information	7/21/2017 12:57:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 12:54:53 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/21/2017 12:54:53 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/21/2017 12:54:53 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/21/2017 12:54:53 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/21/2017 12:42:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 12:36:17 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8597.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/21/2017 12:32:50 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/21/2017 12:32:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:50Z. Reason: GVLK.
Warning	7/21/2017 12:32:00 PM	MsiInstaller	1015	None	Failed to connect to server. Error: 0x80070005
Warning	7/21/2017 12:32:00 PM	MsiInstaller	1001	None	Detection of product '{BC685733-C000-4BCC-90A8-395BB5877A54}', feature 'Device_Driver_Files' failed during request for component '{F8D90E48-3887-4919-942B-D87160FB64D6}'
Warning	7/21/2017 12:32:00 PM	MsiInstaller	1004	None	Detection of product '{BC685733-C000-4BCC-90A8-395BB5877A54}', feature 'Device_Driver_Files', component '{03713515-5282-0076-6E38-09A302E781B0}' failed.  The resource 'C:\Windows\inf\AMC\AMC_USB_Serial_Function.cat' does not exist.
Information	7/21/2017 12:27:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/21/2017 12:27:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256320)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/21/2017 12:27:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/21/2017 12:27:49 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/21/2017 12:26:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 12:25:19 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎21T06:55:01.924522200Z.
Information	7/21/2017 12:25:19 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 9948.
Information	7/21/2017 12:25:19 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: Driver Manager. Product Version: 1.3.0.0. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	7/21/2017 12:25:19 PM	MsiInstaller	11724	None	Product: Driver Manager -- Removal completed successfully.
Information	7/21/2017 12:25:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎21T06:55:01.924522200Z.
Information	7/21/2017 12:24:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {7264C78A-E895-4A98-A41D-4AA910A77A27}. Client Process Id: 9948.
Information	7/21/2017 12:11:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 11:56:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 11:41:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 11:26:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 11:15:10 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎21T05:45:10.616993000Z.
Information	7/21/2017 11:11:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 10:55:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 10:40:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 10:25:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/21/2017 10:22:01 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 54fe2b33-6dd0-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/21/2017 10:15:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/21/2017 10:12:23 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/21/2017 10:10:58 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 10:10:55 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/21/2017 10:10:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/21/2017 10:10:44 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/21/2017 10:10:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37904)(?)])(1 )(2 )]

"
Information	7/21/2017 10:10:43 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 37904)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/21/2017 10:10:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/21/2017 10:10:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/21/2017 10:10:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/21/2017 10:10:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 9:00:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 8:45:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 8:30:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 8:25:46 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/20/2017 8:25:36 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/20/2017 8:15:17 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/20/2017 8:14:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 7:37:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 7:22:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 7:07:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 6:59:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2017 6:59:12 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/20/2017 6:56:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2017 6:52:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 6:37:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 6:22:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 6:06:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 5:51:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 5:36:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 5:21:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 5:06:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 4:51:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 4:35:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 4:20:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 4:05:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 3:50:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 3:35:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 3:20:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 3:13:26 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e09593f2-6d2f-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/20/2017 3:04:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 2:56:30 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2017 2:49:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 2:34:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 2:19:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 2:04:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 1:48:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 1:39:04 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/20/2017 1:33:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 1:18:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 1:03:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 12:48:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 12:33:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 12:17:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 12:11:51 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8596.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/20/2017 12:02:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 12:01:54 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2017 12:01:54 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:51Z. Reason: GVLK.
Information	7/20/2017 11:56:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2017 11:56:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257760)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2017 11:56:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2017 11:56:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2017 11:47:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 11:32:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 11:17:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 11:03:09 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 0, Queries: 0, Results: 0, Version: 16.0.7766.6598.
Information	7/20/2017 11:02:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\Documents\Outlook Files\archive.pst. Stats: Added: 0, Deleted: 0, Modified: 0, Compared: 5, Queries: 0, Results: 0, Version: 16.0.7766.6598.
Information	7/20/2017 11:02:28 AM	Outlook	38	None	Reconciliation completed for the following store: C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost. Stats: Added: 43, Deleted: 0, Modified: 127, Compared: 10877, Queries: 0, Results: 0, Version: 16.0.7766.6598.
Information	7/20/2017 11:02:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 11:02:00 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/20/2017 10:57:12 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 172

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 718

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 171

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 1591

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 16

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 62

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 1358

Warning	7/20/2017 10:57:02 AM	Outlook	59	None	Outlook disabled the following add-in(s):



ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
Load Behavior: 3
HKLM: 1
Location: c:\program files (x86)\microsoft office\root\office16\socialconnector.dll
Threshold Time (Milliseconds): 1000
Time Taken (Milliseconds): 1060
Disable Reason: This add-in caused Outlook to start slowly.
Policy Exception (Allow List): 0 
Information	7/20/2017 10:56:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/20/2017 10:55:43 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/20/2017 10:55:42 AM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	7/20/2017 10:55:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/20/2017 10:55:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39299)(?)])(1 )(2 )]

"
Information	7/20/2017 10:55:42 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39299)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2017 10:55:42 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/20/2017 10:55:42 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2017 10:55:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	7/20/2017 10:55:32 AM	Microsoft Office 16	2001	None	Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.

Do you want to start in safe mode?.
Information	7/20/2017 10:46:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 10:31:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 10:18:15 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/20/2017 10:18:15 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:13Z. Reason: GVLK.
Information	7/20/2017 10:16:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/20/2017 10:13:12 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/20/2017 10:13:12 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257880)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2017 10:13:12 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2017 10:13:09 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/20/2017 10:12:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d06eb864-6d05-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/20/2017 10:06:22 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/20/2017 10:03:27 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/20/2017 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/20/2017 10:01:19 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39353)(?)])(1 )(2 )]

"
Information	7/20/2017 10:01:18 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 39353)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/20/2017 10:01:16 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/20/2017 10:01:16 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/20/2017 10:01:16 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/20/2017 10:01:12 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 131 ms, redo 0 ms, undo 190 ms.) This is an informational message only. No user action is required.
Information	7/20/2017 10:01:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 8:28:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 8:12:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:57:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:49:12 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 7:44:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2017 7:44:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 7:44:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 7:42:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:27:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:19:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 7:14:12 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2017 7:14:12 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 7:14:11 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 7:12:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/19/2017 6:52:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:52:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/19/2017 6:52:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/19/2017 6:49:13 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 6:44:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2017 6:44:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 6:44:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 6:36:21 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 6:36:21 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:21Z. Reason: GVLK.
Information	7/19/2017 6:35:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e98c51f0-6c82-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/19/2017 6:33:57 PM	Microsoft-Windows-LoadPerf	1000	None	Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Information	7/19/2017 6:33:56 PM	Microsoft-Windows-LoadPerf	1001	None	Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Information	7/19/2017 6:30:31 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/19/2017 6:30:30 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Microsoft VS Code\Code.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8595.0000.
Information	7/19/2017 6:30:25 PM	McLogEvent	257	None	The scan of C:\ProgramData\SquirrelMachineInstalls\atom.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8595.0000.
Information	7/19/2017 6:30:09 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/19/2017 6:29:40 PM	ESENT	302	Logging/Recovery	Windows (1504) Windows: The database engine has successfully completed recovery steps.
Information	7/19/2017 6:29:36 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/19/2017 6:29:36 PM	ESENT	301	Logging/Recovery	Windows (1504) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/19/2017 6:29:36 PM	ESENT	300	Logging/Recovery	Windows (1504) Windows: The database engine is initiating recovery steps.
Information	7/19/2017 6:29:35 PM	ESENT	102	General	Windows (1504) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/19/2017 6:29:30 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/19/2017 6:29:28 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/19/2017 6:28:54 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/19/2017 6:28:54 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/19/2017 6:28:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/19/2017 6:28:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/19/2017 6:27:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2017 6:27:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 0 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258840)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 6:27:50 PM	Microsoft-Windows-Security-SPP	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Microsoft.Windows.Smc-Enabled) (Shell-InBoxGames-FreeCell-EnableGame) (Shell-InBoxGames-Hearts-EnableGame) (Shell-InBoxGames-Minesweeper-EnableGame) (Shell-InBoxGames-PurblePlace-EnableGame) (Shell-InBoxGames-Shanghai-EnableGame) (Shell-InBoxGames-Solitaire-EnableGame) (Shell-InBoxGames-SpiderSolitaire-EnableGame) (Shell-MultiplayerInboxGames-Backgammon-EnableGame) (Shell-MultiplayerInboxGames-Checkers-EnableGame) (Shell-MultiplayerInboxGames-Spades-EnableGame) (Shell-PremiumInBoxGames-Chess-EnableGame) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (WindowsAnytimeUpgrade-CanUpgrade) 
App Id=55c92734-d682-4d71-983e-d6ec3f16059f
Sku Id=b92e9980-b9d5-4821-9c94-140f632f6312"
Information	7/19/2017 6:27:49 PM	Microsoft-Windows-Security-SPP	1004	None	"The Software Protection service has successfully installed the license.
License Title=Microsoft-Windows-IE-InternetExplorer Component PPD License
License Id=cde4d5c7-2f36-dfac-49ee-b4ef7966706a"
Information	7/19/2017 6:27:49 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 6:27:48 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 6:27:21 PM	Service1	0	None	Service started successfully.
Information	7/19/2017 6:27:12 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8595.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Error	7/19/2017 6:27:06 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/19/2017 6:27:03 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/19/2017 6:27:03 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/19/2017 6:27:01 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/19/2017 6:27:01 PM	PostgreSQL	0	None	"2017-07-19 18:27:01 IST LOG:  redirecting log output to logging collector process
2017-07-19 18:27:01 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/19/2017 6:26:59 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/19/2017 6:26:59 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/19/2017 6:26:58 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/19/2017 6:26:53 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/19/2017 6:26:52 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/19/2017 6:26:51 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/19/2017 6:26:51 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/19/2017 6:26:51 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/19/2017 6:26:49 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3424 at 7/19/2017 6:21:24 PM (local) 7/19/2017 12:51:24 PM (UTC). This is an informational message only; no user action is required.
Information	7/19/2017 6:26:46 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/19/2017 6:26:46 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/19/2017 6:26:46 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/19/2017 6:26:46 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/19/2017 6:26:46 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3500.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/19/2017 6:26:45 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	7/19/2017 6:26:17 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/19/2017 6:25:34 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: Wlansvc
P2: wlansvc.dll
P3: 6.1.7600.16385
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8bfe4c19-6c81-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/19/2017 6:25:32 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: odClientService
P2: odClientService.exe""
P3: 0.0.0.0
P4: 10
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8bfe4c18-6c81-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/19/2017 6:25:27 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: ServiceHang
Response: Not available
Cab Id: 0

Problem signature:
P1: dot3svc
P2: dot3svc.dll
P3: 6.1.7601.17514
P4: 20
P5: 2
P6: 
P7: 
P8: 
P9: 
P10: 

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 842542b1-6c81-11e7-aebb-80000bd6758f
Report Status: 0"
Information	7/19/2017 6:23:48 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/19/2017 6:23:48 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/19/2017 6:23:48 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/19/2017 6:21:31 PM	Microsoft-Windows-User Profiles Service	1532	None	"The User Profile Service has stopped.  

"
Information	7/19/2017 6:21:24 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Information	7/19/2017 6:21:23 PM	McLogEvent	257	None	The scan of C:\Windows\System32\sspicli.dll has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8595.0000.
Warning	7/19/2017 6:21:21 PM	Microsoft-Windows-Winlogon	6004	None	The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Information	7/19/2017 6:20:26 PM	Service1	0	None	Service started successfully.
Information	7/19/2017 6:20:23 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8595.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/19/2017 6:20:22 PM	PostgreSQL	0	None	Server started and accepting connections

Error	7/19/2017 6:20:19 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/19/2017 6:20:17 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/19/2017 6:20:02 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/19/2017 6:20:01 PM	PostgreSQL	0	None	"2017-07-19 18:20:01 IST LOG:  redirecting log output to logging collector process
2017-07-19 18:20:01 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/19/2017 6:20:01 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/19/2017 6:19:59 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/19/2017 6:19:57 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/19/2017 6:19:57 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/19/2017 6:19:52 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/19/2017 6:19:51 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:51 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:50 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/19/2017 6:19:50 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/19/2017 6:19:50 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/19/2017 6:19:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/19/2017 6:19:49 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/19/2017 6:19:48 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/19/2017 6:19:47 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	3406	Server	162 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/19/2017 6:19:44 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 4124 at 7/11/2017 5:59:02 PM (local) 7/11/2017 12:29:02 PM (UTC). This is an informational message only; no user action is required.
Information	7/19/2017 6:19:38 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/19/2017 6:19:38 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/19/2017 6:19:38 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/19/2017 6:19:38 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/19/2017 6:19:38 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3424.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/19/2017 6:19:37 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	7/19/2017 6:18:55 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/19/2017 6:16:28 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/19/2017 6:16:29 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/19/2017 6:16:29 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/19/2017 5:15:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 5:00:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:45:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:30:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:15:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:00:14 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 1603.
Information	7/19/2017 4:00:14 PM	MsiInstaller	11708	None	Product: Adobe Reader XI (11.0.08) -- Installation operation failed.
Information	7/19/2017 4:00:14 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.07). Installation success or error status: 1603.
Error	7/19/2017 4:00:14 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.07)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI7b215.LOG.
Information	7/19/2017 4:00:14 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.08). Installation success or error status: 1603.
Error	7/19/2017 4:00:14 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.08)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI7b215.LOG.
Error	7/19/2017 4:00:12 PM	MsiInstaller	1013	None	Product: Adobe Reader XI (11.0.08) -- Setup has detected that you already have a more functional product installed.  Setup will now terminate.
Information	7/19/2017 4:00:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:58:10 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Driver Manager. Product Version: 1.3.0.0. Product Language: 1033. Manufacturer: GE. Installation success or error status: 0.
Information	7/19/2017 3:58:10 PM	MsiInstaller	11707	None	Product: Driver Manager -- Installation operation completed successfully.
Information	7/19/2017 3:57:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎19T10:27:40.436874900Z.
Information	7/19/2017 3:57:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3A5A3490-6765-4B23-B433-FEFBF2BF1C58}\Driver Manager.msi. Client Process Id: 8904.
Information	7/19/2017 3:57:40 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎19T10:27:40.436874900Z.
Information	7/19/2017 3:57:40 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3A5A3490-6765-4B23-B433-FEFBF2BF1C58}\Driver Manager.msi. Client Process Id: 8904.
Information	7/19/2017 3:57:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Installation success or error status: 1603.
Information	7/19/2017 3:57:02 PM	MsiInstaller	11708	None	Product: Adobe Reader XI (11.0.08) -- Installation operation failed.
Information	7/19/2017 3:57:02 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.07). Installation success or error status: 1603.
Error	7/19/2017 3:57:02 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.07)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI4b476.LOG.
Information	7/19/2017 3:57:02 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Reader XI (11.0.08). Product Version: 11.0.08. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Reader XI (11.0.08). Installation success or error status: 1603.
Error	7/19/2017 3:57:02 PM	MsiInstaller	1023	None	Product: Adobe Reader XI (11.0.08) - Update 'Adobe Reader XI (11.0.08)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\212558~1\AppData\Local\Temp\MSI4b476.LOG.
Error	7/19/2017 3:57:01 PM	MsiInstaller	1013	None	Product: Adobe Reader XI (11.0.08) -- Setup has detected that you already have a more functional product installed.  Setup will now terminate.
Information	7/19/2017 3:44:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:29:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:14:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:59:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:44:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:38:32 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/19/2017 2:36:54 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/19/2017 2:32:23 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/19/2017 2:29:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:25:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:24:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:24:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:13:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:58:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:51:05 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 1:51:05 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:05Z. Reason: GVLK.
Information	7/19/2017 1:46:04 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2017 1:46:04 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 1:46:04 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 1:46:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 1:43:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:40:14 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/19/2017 1:28:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:13:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:58:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:43:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3b14a4f-6c51-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/19/2017 12:42:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:41:54 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8595.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/19/2017 12:41:25 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 12:41:25 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:04:25Z. Reason: GVLK.
Information	7/19/2017 12:36:25 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2017 12:36:25 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 12:36:24 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 12:36:24 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 12:27:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:12:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 11:57:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 11:42:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 11:39:50 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 11:39:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-26T06:03:49Z. Reason: GVLK.
Information	7/19/2017 11:34:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 11:34:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 11:34:49 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/07/19 06:04"
Information	7/19/2017 11:34:48 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/07/19 06:04, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/19/2017 11:29:45 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/19/2017 11:29:45 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 11:29:45 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 11:29:45 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 11:27:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 11:11:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 10:56:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 10:41:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 10:26:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 10:25:07 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 10:24:40 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 10:24:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 10:23:38 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/19/2017 10:11:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 9:56:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 9:40:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 9:25:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 9:10:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 8:55:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 8:40:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 8:25:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/19/2017 8:20:43 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/19/2017 8:20:43 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/19/2017 8:09:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:54:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:42:54 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c5a23990-6c27-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/19/2017 7:39:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:24:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 7:09:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:53:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:38:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:25:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 6:24:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 6:24:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 6:23:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 6:08:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 5:53:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 5:38:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 5:23:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 5:07:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:52:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:37:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:22:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 4:07:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:51:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/19/2017 3:40:35 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/19/2017 3:40:35 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/19/2017 3:36:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:21:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:11:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/19/2017 3:06:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41208)(?)])(1 )(2 )]

"
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 41208)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/19/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/19/2017 2:51:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:41:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b86045f8-6bfd-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/19/2017 2:36:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:25:03 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:24:30 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:24:23 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/19/2017 2:20:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 2:05:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:50:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:35:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:20:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 1:05:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:49:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:34:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:19:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:04:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/19/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/18/2017 11:49:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:33:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:18:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:03:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:48:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:33:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:25:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 10:25:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 10:24:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 10:18:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:02:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:01:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2017 10:01:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:45Z. Reason: GVLK.
Information	7/18/2017 9:56:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2017 9:56:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2017 9:56:44 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2017 9:56:44 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2017 9:47:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:40:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aab2f8a5-6bd3-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/18/2017 9:32:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:17:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:02:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:47:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:31:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:16:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:01:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:56:07 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/18/2017 7:46:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:31:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:15:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:00:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:45:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:30:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:24:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 6:24:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 6:15:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:00:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:44:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:29:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:14:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:59:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:44:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:40:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a76ed82b-6ba9-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/18/2017 4:28:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:13:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:58:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:43:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:28:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:13:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:57:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:42:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:27:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:24:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:24:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:12:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:57:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:42:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:26:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:11:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:56:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:43:47 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8594.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/18/2017 12:41:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:26:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:11:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:55:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:40:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 11:39:05 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244022
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 99b3b5b7-6b7f-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/18/2017 11:25:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/18/2017 11:20:33 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/18/2017 11:20:33 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/18/2017 11:16:12 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2017 11:16:12 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:11Z. Reason: GVLK.
Information	7/18/2017 11:11:11 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2017 11:11:11 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250620)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2017 11:11:11 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2017 11:11:11 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2017 11:10:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:55:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:40:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:24:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 10:24:34 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 10:24:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 10:23:28 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/18/2017 10:09:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:54:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:39:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:24:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 9:09:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:53:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:38:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:23:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 8:08:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:53:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:38:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:22:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 7:07:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:52:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:38:53 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: aa012759-6b55-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/18/2017 6:37:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:24:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 6:24:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 6:23:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 6:22:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 6:06:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:51:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:36:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:21:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:06:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 5:06:11 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/18/2017 5:06:01 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/18/2017 4:51:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:35:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:30:20 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/18/2017 4:30:20 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:20Z. Reason: GVLK.
Information	7/18/2017 4:25:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2017 4:25:18 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/18/2017 4:25:18 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251040)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2017 4:25:17 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/18/2017 4:20:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 4:05:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:50:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:35:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:20:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:11:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/18/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/18/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42648)(?)])(1 )(2 )]

"
Information	7/18/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 42648)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/18/2017 3:04:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 3:01:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/18/2017 3:01:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/18/2017 3:01:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/18/2017 2:49:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:34:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:25:55 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/18/2017 2:24:22 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:24:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:24:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:23:53 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/18/2017 2:19:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 2:04:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/18/2017 1:56:33 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/18/2017 1:56:33 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/18/2017 1:49:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:37:51 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c421a8a-6b2b-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/18/2017 1:33:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:18:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 1:03:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:48:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:33:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:18:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/18/2017 12:02:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:47:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:32:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:17:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:02:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:47:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:31:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:24:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 10:24:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 10:24:02 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/17/2017 10:23:54 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 10:16:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:01:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 9:46:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/17/2017 9:35:37 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/17/2017 9:35:37 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/17/2017 9:31:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 9:15:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 9:00:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 8:48:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2017 8:48:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:10Z. Reason: GVLK.
Information	7/17/2017 8:45:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 8:39:16 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2017 8:39:16 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2017 8:39:16 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2017 8:39:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2017 8:36:50 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8eb47ffe-6b01-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/17/2017 8:30:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 8:15:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 8:00:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 7:44:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 7:29:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 7:14:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 6:59:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 6:44:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 6:29:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 6:24:19 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 6:23:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 6:23:58 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/17/2017 6:23:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 6:13:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 6:02:12 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎17T12:32:12.554581100Z.
Information	7/17/2017 6:02:12 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎17T12:32:12.554581100Z.
Information	7/17/2017 5:58:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 5:43:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 5:28:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 5:13:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 4:57:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 4:56:19 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/17/2017 4:56:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/17/2017 4:42:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 4:27:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/17/2017 4:25:14 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/17/2017 4:25:14 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/17/2017 4:24:16 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/17/2017 4:12:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 3:57:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 3:42:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 3:35:47 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 80ca91c1-6ad7-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/17/2017 3:26:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 3:11:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 2:56:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 2:41:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 2:26:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 2:24:17 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 2:23:49 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 2:23:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 2:11:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 2:00:24 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/17/2017 1:56:31 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/17/2017 1:55:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 1:40:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 1:25:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 1:11:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2017 1:11:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:07Z. Reason: GVLK.
Information	7/17/2017 1:10:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 1:06:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2017 1:06:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2017 1:06:07 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2017 1:06:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2017 1:00:05 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/17/2017 12:55:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 12:52:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2017 12:52:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:06Z. Reason: GVLK.
Information	7/17/2017 12:47:06 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2017 12:47:06 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 251940)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2017 12:47:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2017 12:47:04 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2017 12:40:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 12:24:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 12:23:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8593.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/17/2017 12:09:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:54:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:39:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:26:33 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/17/2017 11:24:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 11:09:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:53:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:38:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/17/2017 10:34:40 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6fc776a0-6aad-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/17/2017 10:34:04 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/17/2017 10:34:03 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:02Z. Reason: GVLK.
Information	7/17/2017 10:29:06 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/17/2017 10:25:47 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/17/2017 10:24:53 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/17/2017 10:24:53 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2017 10:24:52 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2017 10:24:49 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/17/2017 10:24:15 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 10:24:13 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/17/2017 10:24:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/17/2017 10:24:02 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43650)(?)])(1 )(2 )]

"
Information	7/17/2017 10:24:01 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 43650)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/17/2017 10:24:01 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/17/2017 10:24:01 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/17/2017 10:23:58 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/17/2017 10:23:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/17/2017 10:23:30 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/17/2017 10:23:28 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 483 ms, redo 0 ms, undo 382 ms.) This is an informational message only. No user action is required.
Information	7/17/2017 10:23:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 7:10:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 6:55:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 6:49:40 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/14/2017 6:40:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 6:25:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 6:10:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 5:54:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 5:49:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2017 5:49:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2017 5:49:35 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/14/2017 5:49:27 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2017 5:39:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 5:24:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 5:17:49 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2017 5:17:49 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:49Z. Reason: GVLK.
Information	7/14/2017 5:12:49 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2017 5:12:49 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256020)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2017 5:12:48 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2017 5:12:46 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/14/2017 5:09:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 4:54:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 4:39:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 4:23:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 4:08:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 4:00:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:30:43.079737800Z.
Information	7/14/2017 4:00:43 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:30:43.079737800Z.
Information	7/14/2017 4:00:42 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:30:42.278737800Z.
Information	7/14/2017 4:00:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:30:42.278737800Z.
Information	7/14/2017 4:00:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:30:41.454737800Z.
Information	7/14/2017 4:00:41 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:30:41.454737800Z.
Information	7/14/2017 4:00:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:30:39.720737800Z.
Information	7/14/2017 4:00:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:30:39.720737800Z.
Information	7/14/2017 3:59:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:29:55.706737800Z.
Information	7/14/2017 3:59:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:29:55.706737800Z.
Information	7/14/2017 3:59:50 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:29:50.960737800Z.
Information	7/14/2017 3:59:50 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:29:50.960737800Z.
Information	7/14/2017 3:53:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 3:50:38 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 3:50:38 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 3:38:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 3:33:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:03:55.499956600Z.
Information	7/14/2017 3:33:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:03:55.499956600Z.
Information	7/14/2017 3:33:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:03:54.775884200Z.
Information	7/14/2017 3:33:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:03:54.775884200Z.
Information	7/14/2017 3:33:44 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T10:03:44.554862200Z.
Information	7/14/2017 3:33:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T10:03:44.554862200Z.
Information	7/14/2017 3:23:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 3:16:15 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T09:46:15.208938100Z.
Information	7/14/2017 3:16:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T09:46:15.208938100Z.
Information	7/14/2017 3:16:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T09:46:14.582875500Z.
Information	7/14/2017 3:16:14 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T09:46:14.582875500Z.
Information	7/14/2017 3:16:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T09:46:01.991616500Z.
Information	7/14/2017 3:16:01 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T09:46:01.991616500Z.
Information	7/14/2017 3:07:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 3:00:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244022
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 1bcd3165-6877-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/14/2017 2:52:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 2:52:29 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 2:52:29 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/14/2017 2:48:24 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 2:48:24 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 2:37:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 2:22:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 2:11:17 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 2:11:17 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 2:07:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 1:52:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 1:49:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2017 1:49:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/14/2017 1:36:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 1:34:12 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 1:34:12 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 1:21:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 1:06:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 12:51:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 12:36:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 12:20:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 12:17:42 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8590.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/14/2017 12:05:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 12:02:12 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/14/2017 11:50:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 11:35:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 11:25:46 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 11:25:46 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 11:20:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/14/2017 11:17:11 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 11:17:11 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 11:12:16 AM	PostgreSQL	0	None	Server started and accepting connections

Information	7/14/2017 11:12:15 AM	PostgreSQL	0	None	"2017-07-14 11:12:15 IST LOG:  redirecting log output to logging collector process
2017-07-14 11:12:15 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/14/2017 11:12:15 AM	PostgreSQL	0	None	Waiting for server startup...

Information	7/14/2017 11:05:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 10:49:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 10:48:49 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 1 started ‎2017‎-‎07‎-‎14T05:17:04.538892700Z.
Information	7/14/2017 10:47:04 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 1 - ‎2017‎-‎07‎-‎14T05:17:04.538892700Z.
Information	7/14/2017 10:34:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 10:29:05 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/14/2017 10:28:36 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/14/2017 10:24:18 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎14T04:52:36.912135300Z.
Information	7/14/2017 10:24:18 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/14/2017 10:24:18 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/14/2017 10:24:18 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/14/2017 10:22:36 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎14T04:52:36.912135300Z.
Information	7/14/2017 10:19:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 10:04:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/14/2017 10:03:51 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/14/2017 10:00:20 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 24856ca8-684d-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/14/2017 9:58:38 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/14/2017 9:58:38 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:38Z. Reason: GVLK.
Information	7/14/2017 9:54:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/14/2017 9:53:34 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2017 9:50:54 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/14/2017 9:49:54 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/14/2017 9:49:54 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2017 9:49:53 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2017 9:49:53 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/14/2017 9:49:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/14/2017 9:49:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/14/2017 9:49:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48005)(?)])(1 )(2 )]

"
Information	7/14/2017 9:49:27 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 48005)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/14/2017 9:49:26 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/14/2017 9:49:26 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/14/2017 9:49:26 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/14/2017 9:49:21 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/14/2017 9:49:21 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/14/2017 9:49:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 7:02:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:57:54 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	7/13/2017 6:57:52 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 6:57:52 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 6:51:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 6:49:34 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/13/2017 6:47:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:32:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:17:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:13:30 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: df873707-67c8-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 6:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:46:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:31:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:16:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:01:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:45:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:30:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:15:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:00:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/13/2017 3:48:58 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 3:48:58 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 3:45:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:29:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:14:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/13/2017 3:01:23 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 3:01:23 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 2:59:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:51:16 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 2:51:10 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 2:44:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:29:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:13:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:00:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2017 2:00:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:57Z. Reason: GVLK.
Information	7/13/2017 1:58:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:55:56 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2017 1:55:56 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257640)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2017 1:55:56 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2017 1:55:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2017 1:43:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:28:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:12:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:12:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d1563a92-679e-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 12:57:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:42:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:27:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:25:15 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Warning	7/13/2017 12:22:50 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 12:22:50 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/13/2017 12:14:11 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 12:14:11 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 12:12:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:09:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 160a5432-6796-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 12:09:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 160a5431-6796-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 12:08:45 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8589.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Warning	7/13/2017 12:05:40 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 11:57:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 11:47:14 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 11:41:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 11:26:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 11:11:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 11:09:47 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/13/2017 11:04:12 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/13/2017 10:56:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/13/2017 10:52:54 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/13/2017 10:52:54 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/13/2017 10:51:08 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 10:41:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 10:26:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 10:10:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 9:55:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 9:40:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 9:25:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 9:10:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 8:55:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 8:39:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 8:24:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 8:12:02 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d9480643-6774-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 8:09:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 7:54:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 7:39:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 7:24:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 7:08:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:53:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:51:05 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 6:51:01 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 6:38:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:23:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 6:08:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:53:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:37:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:22:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 5:07:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:52:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:49:49 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2017 4:49:49 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:49Z. Reason: GVLK.
Information	7/13/2017 4:44:49 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2017 4:44:49 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2017 4:44:49 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2017 4:44:48 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2017 4:42:29 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/13/2017 4:42:29 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:29Z. Reason: GVLK.
Information	7/13/2017 4:37:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2017 4:37:26 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/13/2017 4:37:26 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2017 4:37:25 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2017 4:37:25 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/13/2017 4:37:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:22:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 4:06:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:51:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:39:49 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/13/2017 3:39:40 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/13/2017 3:36:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:21:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 3:11:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ecf9986b-674a-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/13/2017 3:11:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/13/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/13/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49848)(?)])(1 )(2 )]

"
Information	7/13/2017 3:06:11 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 49848)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/13/2017 3:06:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/13/2017 3:06:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/13/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/13/2017 3:06:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:51:04 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 2:50:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:50:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/13/2017 2:35:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:20:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:05:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 2:00:24 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/13/2017 1:59:45 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/13/2017 1:50:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:35:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:19:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 1:04:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:49:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:34:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:19:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:04:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/13/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/12/2017 11:48:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:33:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:18:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:03:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:51:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 10:50:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 10:48:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:32:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:17:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:09:58 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: bd5fd2c9-6720-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/12/2017 10:02:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:47:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:32:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:17:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:01:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:46:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:31:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:16:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:04:14 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/12/2017 8:01:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:46:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:30:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:15:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:00:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:51:00 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 6:50:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 6:49:34 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/12/2017 6:45:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:30:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:15:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:59:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:44:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:29:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:24:42 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/12/2017 5:24:42 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	7/12/2017 5:24:40 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T11:53:47.305263200Z.
Information	7/12/2017 5:24:40 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0D9A4549-2942-4DD9-B4F4-558B8A7E5ECF}\DeviceManager.msi. Client Process Id: 11336.
Information	7/12/2017 5:23:57 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2017 5:23:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:56Z. Reason: GVLK.
Information	7/12/2017 5:23:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T11:53:47.305263200Z.
Information	7/12/2017 5:23:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{0D9A4549-2942-4DD9-B4F4-558B8A7E5ECF}\DeviceManager.msi. Client Process Id: 11336.
Information	7/12/2017 5:23:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T11:53:11.213654400Z.
Information	7/12/2017 5:23:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2B3E8ECB-AA34-4F42-B62B-C4AFD186E23F}\DeviceDriver.msi. Client Process Id: 2760.
Information	7/12/2017 5:23:28 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/12/2017 5:23:28 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	7/12/2017 5:23:11 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T11:53:11.213654400Z.
Information	7/12/2017 5:23:10 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2B3E8ECB-AA34-4F42-B62B-C4AFD186E23F}\DeviceDriver.msi. Client Process Id: 2760.
Warning	7/12/2017 5:21:14 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 5:21:14 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/12/2017 5:19:14 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 5:19:14 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 5:18:55 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2017 5:18:55 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 5:18:55 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2017 5:18:55 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/12/2017 5:15:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 99446ee5-66f7-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/12/2017 5:14:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 5:10:11 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 5:10:11 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 5:08:55 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: af08b44a-66f6-11e7-9ab8-0205857feb80
Report Status: 0"
Warning	7/12/2017 5:06:04 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 5:06:04 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 4:59:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:44:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:28:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:27:35 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/12/2017 4:27:35 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/12/2017 4:27:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T10:54:33.840736900Z.
Information	7/12/2017 4:27:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2D353F1B-91EB-416A-BE3D-71D1D82F0424}\4Sight™ 2.msi. Client Process Id: 5360.
Information	7/12/2017 4:24:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T10:54:33.840736900Z.
Information	7/12/2017 4:24:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{2D353F1B-91EB-416A-BE3D-71D1D82F0424}\4Sight™ 2.msi. Client Process Id: 5360.
Information	7/12/2017 4:16:29 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T10:44:34.847046400Z.
Information	7/12/2017 4:16:29 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/12/2017 4:16:29 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/12/2017 4:16:29 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/12/2017 4:14:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T10:44:34.847046400Z.
Information	7/12/2017 4:14:17 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/12/2017 4:13:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 3:58:41 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 3:58:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:42:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:38:36 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2017 3:38:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T06:00:35Z. Reason: GVLK.
Information	7/12/2017 3:33:35 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2017 3:33:35 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 3:33:35 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2017 3:33:34 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/12/2017 3:26:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:11:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:56:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:51:05 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 2:50:58 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 2:50:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 2:41:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:26:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:10:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:55:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:40:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:25:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:10:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 1:03:51 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 1:03:51 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 12:57:58 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8588.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/12/2017 12:54:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:39:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 12:26:40 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 12:26:40 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 12:24:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 12:17:21 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 12:17:21 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 12:09:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:07:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244022
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9feda723-66cc-11e7-9ab8-0205857feb80
Report Status: 0"
Warning	7/12/2017 12:00:34 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 12:00:34 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/12/2017 12:00:11 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 12:00:11 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/12/2017 11:59:14 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 11:59:14 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 11:54:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 11:42:38 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 11:42:38 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 11:39:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:35:42 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/12/2017 11:35:42 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-19T05:59:42Z. Reason: GVLK.
Information	7/12/2017 11:30:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 11:30:41 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 11:30:41 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/07/12 06:00"
Information	7/12/2017 11:30:39 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/07/12 06:00, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Warning	7/12/2017 11:26:12 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 11:26:12 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 11:25:35 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/12/2017 11:25:35 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 11:25:35 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2017 11:25:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/12/2017 11:23:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:08:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 11:06:27 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/12/2017 11:06:27 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/12/2017 11:03:54 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T05:29:42.534117100Z.
Information	7/12/2017 11:03:54 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AD85CE87-6611-468E-A9DF-A26C6DB1E01B}\4Sight™ 2.msi. Client Process Id: 9792.
Information	7/12/2017 10:59:42 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T05:29:42.534117100Z.
Information	7/12/2017 10:59:41 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{AD85CE87-6611-468E-A9DF-A26C6DB1E01B}\4Sight™ 2.msi. Client Process Id: 9792.
Warning	7/12/2017 10:59:13 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 10:59:13 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 10:55:53 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T05:24:24.251717100Z.
Information	7/12/2017 10:55:53 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10188.
Information	7/12/2017 10:55:53 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/12/2017 10:55:53 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	7/12/2017 10:54:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T05:24:24.251717100Z.
Information	7/12/2017 10:53:27 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10188.
Information	7/12/2017 10:53:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:53:17 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T05:22:52.055317100Z.
Information	7/12/2017 10:53:17 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10188.
Information	7/12/2017 10:53:17 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/12/2017 10:53:17 AM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	7/12/2017 10:52:52 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T05:22:52.055317100Z.
Information	7/12/2017 10:52:20 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10188.
Information	7/12/2017 10:52:04 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T05:20:22.091317100Z.
Information	7/12/2017 10:52:04 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/12/2017 10:52:04 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/12/2017 10:52:04 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/12/2017 10:50:54 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 10:50:27 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/12/2017 10:50:25 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 10:50:25 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 10:50:22 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T05:20:22.091317100Z.
Information	7/12/2017 10:50:16 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10188.
Information	7/12/2017 10:38:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/12/2017 10:34:05 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/12/2017 10:34:05 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/12/2017 10:25:34 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.7. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/12/2017 10:25:34 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/12/2017 10:25:32 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎12T04:50:23.177917100Z.
Information	7/12/2017 10:25:32 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{CB48941B-AC56-42F1-A0BE-24D7FE37ADAC}\4Sight™ 2.msi. Client Process Id: 8232.
Information	7/12/2017 10:22:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 10:20:23 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎12T04:50:23.177917100Z.
Information	7/12/2017 10:19:35 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{CB48941B-AC56-42F1-A0BE-24D7FE37ADAC}\4Sight™ 2.msi. Client Process Id: 8232.
Information	7/12/2017 10:07:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:52:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:37:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:22:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 9:07:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:51:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:36:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:21:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 8:06:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:51:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:36:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:20:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 7:06:58 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 97eeedd9-66a2-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/12/2017 7:05:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:50:51 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 6:50:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:50:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 6:35:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:20:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 6:05:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:49:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:34:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:19:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 5:04:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:49:14 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:34:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:18:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 4:03:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:48:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:33:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:18:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 3:11:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/12/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/12/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51288)(?)])(1 )(2 )]

"
Information	7/12/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51288)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/12/2017 3:06:12 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/12/2017 3:06:12 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/12/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/12/2017 3:04:36 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/12/2017 3:03:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:50:50 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 2:50:21 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/12/2017 2:47:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:32:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:17:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 2:11:13 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/12/2017 2:10:41 AM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/12/2017 2:05:56 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8a31e104-6678-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/12/2017 2:02:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:47:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:32:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:16:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 1:01:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:46:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:31:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:16:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/12/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/12/2017 12:01:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:45:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:30:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:15:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:00:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 10:50:34 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 10:50:18 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 10:45:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 10:33:34 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 10:33:34 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:34Z. Reason: GVLK.
Information	7/11/2017 10:30:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 10:28:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2017 10:28:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249900)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2017 10:28:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 10:28:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 10:14:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 10:12:47 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/11/2017 10:12:08 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/11/2017 10:11:51 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/11/2017 9:59:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 9:44:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 9:29:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 9:28:04 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	7/11/2017 9:28:04 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/11/2017 9:28:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎11T15:57:53.036124200Z.
Information	7/11/2017 9:28:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{266F9BE4-987A-47B2-BCAF-0BAA5787365E}\4Sight™ 2.msi. Client Process Id: 3908.
Information	7/11/2017 9:27:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎11T15:57:53.036124200Z.
Information	7/11/2017 9:26:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{266F9BE4-987A-47B2-BCAF-0BAA5787365E}\4Sight™ 2.msi. Client Process Id: 3908.
Information	7/11/2017 9:25:43 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/11/2017 9:25:42 PM	PostgreSQL	0	None	"2017-07-11 21:25:42 IST LOG:  redirecting log output to logging collector process
2017-07-11 21:25:42 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/11/2017 9:25:42 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/11/2017 9:18:00 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/11/2017 9:18:00 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/11/2017 9:14:59 PM	Microsoft-Windows-Winlogon	1002	None	The shell stopped unexpectedly and Explorer.exe was restarted.
Information	7/11/2017 9:14:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 9:06:32 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1603.
Information	7/11/2017 9:06:32 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/11/2017 9:04:56 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7d0e9c8d-664e-11e7-9ab8-0205857feb80
Report Status: 0"
Information	7/11/2017 9:01:08 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/11/2017 9:01:08 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/11/2017 8:59:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 8:55:43 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/11/2017 8:55:43 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/11/2017 8:51:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎11T15:18:31.803685900Z.
Information	7/11/2017 8:51:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 11976.
Information	7/11/2017 8:51:51 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/11/2017 8:51:51 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/11/2017 8:48:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎11T15:18:31.803685900Z.
Information	7/11/2017 8:48:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 11976.
Information	7/11/2017 8:43:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 8:36:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 11976.
Information	7/11/2017 8:36:06 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	7/11/2017 8:36:06 PM	MsiInstaller	11729	None	Product: 4Sight™ 2 -- Configuration failed.
Information	7/11/2017 8:33:41 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 11976.
Information	7/11/2017 8:33:27 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\Sparx Systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8587.0000.
Warning	7/11/2017 8:33:02 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 8:33:02 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/11/2017 8:28:49 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 8:28:49 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 8:28:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/11/2017 8:26:48 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 8:26:48 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 8:13:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 7:58:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 7:43:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/11/2017 7:29:03 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 7:29:03 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 7:27:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/11/2017 7:27:49 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 7:27:49 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 7:19:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 7:14:28 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2017 7:14:28 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 7:14:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 7:12:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 6:57:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 6:56:08 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 6:53:20 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 6:53:19 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:17Z. Reason: GVLK.
Information	7/11/2017 6:51:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/11/2017 6:51:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51783)(?)])(1 )(2 )]

"
Information	7/11/2017 6:51:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51783)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	7/11/2017 6:50:40 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 6:50:40 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 6:50:25 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 6:50:24 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Warning	7/11/2017 6:50:24 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	7/11/2017 6:50:22 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 6:50:22 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	7/11/2017 6:50:22 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\Documents\Outlook Files\archive.pst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 6:50:19 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/11/2017 6:50:15 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 905

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 265

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 1373

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 733

Information	7/11/2017 6:49:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 6:49:24 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/11/2017 6:49:23 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/11/2017 6:49:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/11/2017 6:49:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51785)(?)])(1 )(2 )]

"
Information	7/11/2017 6:49:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 51785)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2017 6:49:22 PM	ESENT	102	General	Windows (9724) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Warning	7/11/2017 6:49:14 PM	Outlook	58	None	During launch an existing non-responsive instance of Outlook was closed.
Information	7/11/2017 6:48:17 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2017 6:48:17 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250140)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2017 6:48:17 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 6:48:16 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 6:44:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2017 6:44:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 6:44:26 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 6:42:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 6:27:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 6:19:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 6:14:27 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2017 6:14:27 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 6:14:27 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 6:12:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8768.
Information	7/11/2017 6:12:11 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.009.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 0.
Information	7/11/2017 6:12:11 PM	MsiInstaller	11728	None	Product: Adobe Acrobat Reader DC -- Configuration completed successfully.
Information	7/11/2017 6:12:11 PM	MsiInstaller	1036	None	Windows Installer installed an update. Product Name: Adobe Acrobat Reader DC. Product Version: 17.009.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Update Name: Adobe Acrobat Reader DC
 (17.009.20058). Installation success or error status: 0.
Information	7/11/2017 6:12:11 PM	MsiInstaller	1022	None	Product: Adobe Acrobat Reader DC - Update 'Adobe Acrobat Reader DC
 (17.009.20058)' installed successfully.
Information	7/11/2017 6:11:53 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	7/11/2017 6:11:53 PM	ESENT	103	General	Windows (7804) Windows: The database engine stopped the instance (0).
Information	7/11/2017 6:11:49 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 8768.
Information	7/11/2017 6:11:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 9584.
Information	7/11/2017 6:11:43 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Adobe Acrobat Reader DC. Product Version: 17.009.20058. Product Language: 1033. Manufacturer: Adobe Systems Incorporated. Reconfiguration success or error status: 1602.
Information	7/11/2017 6:11:43 PM	MsiInstaller	11729	None	Product: Adobe Acrobat Reader DC -- Configuration failed.
Information	7/11/2017 6:11:31 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {AC76BA86-7AD7-1033-7B44-AC0F074E4100}. Client Process Id: 9584.
Information	7/11/2017 6:07:59 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 6:07:59 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:54:58Z. Reason: GVLK.
Information	7/11/2017 6:02:13 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Warning	7/11/2017 6:00:59 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/11/2017 6:00:56 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/11/2017 6:00:54 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/11/2017 6:00:53 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/11/2017 6:00:51 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/11/2017 6:00:18 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/11/2017 6:00:18 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2017 6:00:18 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 6:00:17 PM	ESENT	302	Logging/Recovery	Windows (7804) Windows: The database engine has successfully completed recovery steps.
Information	7/11/2017 6:00:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/11/2017 6:00:12 PM	ESENT	301	Logging/Recovery	Windows (7804) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/11/2017 6:00:12 PM	ESENT	300	Logging/Recovery	Windows (7804) Windows: The database engine is initiating recovery steps.
Information	7/11/2017 6:00:12 PM	ESENT	102	General	Windows (7804) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/11/2017 6:00:07 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8587.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/11/2017 5:59:54 PM	Service1	0	None	Service started successfully.
Error	7/11/2017 5:59:44 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/11/2017 5:59:44 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/11/2017 5:59:40 PM	Microsoft-Windows-WMI	5611	None	The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Information	7/11/2017 5:59:36 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/11/2017 5:59:32 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/11/2017 5:59:31 PM	PostgreSQL	0	None	"2017-07-11 17:59:31 IST LOG:  redirecting log output to logging collector process
2017-07-11 17:59:31 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/11/2017 5:59:30 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/11/2017 5:59:27 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/11/2017 5:59:09 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/11/2017 5:59:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/11/2017 5:59:09 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/11/2017 5:59:09 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/11/2017 5:59:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/11/2017 5:59:09 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/11/2017 5:59:08 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/11/2017 5:59:08 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/11/2017 5:59:08 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/11/2017 5:59:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/11/2017 5:59:06 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:06 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/11/2017 5:59:06 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:05 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/11/2017 5:59:04 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	3406	Server	52 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/11/2017 5:59:02 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3972 at 7/6/2017 8:50:23 PM (local) 7/6/2017 3:20:23 PM (UTC). This is an informational message only; no user action is required.
Information	7/11/2017 5:59:00 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/11/2017 5:59:00 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/11/2017 5:59:00 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/11/2017 5:59:00 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/11/2017 5:59:00 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 4124.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/11/2017 5:58:59 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/11/2017 5:58:13 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/11/2017 5:58:02 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/11/2017 5:57:53 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/11/2017 5:57:53 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/11/2017 5:57:53 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/11/2017 5:26:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 5:11:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 4:56:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 4:41:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 4:25:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 4:10:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 4:03:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 6ea47965-6624-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/11/2017 3:55:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 3:49:26 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 3:40:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 3:25:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 3:09:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 3:03:42 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8696.
Information	7/11/2017 3:03:42 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 1602.
Information	7/11/2017 3:03:42 PM	MsiInstaller	11729	None	Product: 4Sight™ 2 -- Configuration failed.
Information	7/11/2017 3:03:25 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 8696.
Information	7/11/2017 2:54:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 2:39:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 2:24:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 2:09:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 2:08:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 2:08:53 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/11/2017 2:08:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/11/2017 1:54:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 1:38:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 1:23:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 1:08:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 12:53:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 12:38:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 12:29:56 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8587.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/11/2017 12:23:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 12:07:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:52:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/11/2017 11:49:25 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 11:49:25 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/11/2017 11:37:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:22:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:06:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/11/2017 11:02:50 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 609732dd-65fa-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/11/2017 10:56:17 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/11/2017 10:56:13 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/11/2017 10:54:31 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Warning	7/11/2017 10:52:04 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/11/2017 10:52:03 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/11/2017 10:51:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	7/11/2017 10:08:46 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/11/2017 10:08:46 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0FA69A28-F847-4E5D-9D31-6B595837919A}
Error	7/11/2017 10:08:46 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {0FA69A28-F847-4E5D-9D31-6B595837919A}
Information	7/11/2017 10:08:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/11/2017 10:08:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52306)(?)])(1 )(2 )]

"
Information	7/11/2017 10:08:45 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 52306)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/11/2017 10:08:44 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/11/2017 10:08:44 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/11/2017 10:08:43 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	7/11/2017 10:08:39 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/11/2017 10:08:33 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/11/2017 10:08:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 12:18:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 12:03:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 11:47:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/10/2017 11:41:08 AM	Microsoft-Windows-Search	10023	Gatherer	The protocol host process 12600 did not respond and is being forcibly terminated {filter host process 13484}. 

Error	7/10/2017 11:40:26 AM	RasClient	20227	None	CoId={FAF3B5F3-A3B0-4D05-BE38-B2AED690B32A}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has failed. The error code returned on failure is 0.
Information	7/10/2017 11:39:51 AM	RasClient	20224	None	CoId={FAF3B5F3-A3B0-4D05-BE38-B2AED690B32A}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	7/10/2017 11:39:51 AM	RasClient	20223	None	CoId={FAF3B5F3-A3B0-4D05-BE38-B2AED690B32A}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	7/10/2017 11:39:51 AM	RasClient	20222	None	CoId={FAF3B5F3-A3B0-4D05-BE38-B2AED690B32A}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	7/10/2017 11:39:51 AM	RasClient	20221	None	CoId={FAF3B5F3-A3B0-4D05-BE38-B2AED690B32A}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	7/10/2017 11:39:50 AM	RasClient	20226	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The user LOGON\212558710 dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly which has terminated. The reason code returned on termination is 828.
Information	7/10/2017 11:37:42 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/10/2017 11:32:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 11:17:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 11:02:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 10:47:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 10:32:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 10:16:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 10:01:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 9:46:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 9:31:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 9:23:12 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/10/2017 9:19:24 AM	RasClient	20225	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The user LOGON\212558710 has dialed a connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly to the Remote Access Server which has successfully connected. The connection parameters are:
TunnelIpAddress = 3.202.253.203
TunnelIpv6Address = None
Dial-in User = .
Information	7/10/2017 9:19:20 AM	RasClient	20224	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The link to the Remote Access Server has been established by user LOGON\212558710.
Information	7/10/2017 9:19:20 AM	RasClient	20223	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The user LOGON\212558710 has successfully established a link to the Remote Access Server using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	7/10/2017 9:19:20 AM	RasClient	20222	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The user LOGON\212558710 is trying to establish a link to the Remote Access Server for the connection named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly using the following device: 
Server address/Phone Number = 16777343:40109:100000000
Device = F5 Networks VPN Adapter
Port = GENERIC17-0
MediaType = GENERIC.
Information	7/10/2017 9:19:20 AM	RasClient	20221	None	CoId={787F3652-0913-49E7-901D-638FFBBFA467}: The user LOGON\212558710 has started dialing a Dial-up connection using a per-user connection profile named _Common_GE_VPN_ST_na_res - Go to cincinnati-01-us.connectge.com instead of dialing directly. The connection settings are: 
Dial-in User = 
VpnStrategy =Not Applicable
DataEncryption = Requested
PrerequisiteEntry = 
AutoLogon = No
UseRasCredentials = Yes
Authentication Type = PAP/CHAP/MS-CHAPv2 
Ipv4DefaultGateway = No
Ipv4AddressAssignment = By Server
Ipv4DNSServerAssignment = By Phonebook Entry
Ipv6DefaultGateway = No
Ipv6AddressAssignment = By Server
Ipv6DNSServerAssignment = By Server
IpDnsFlags = Register primary domain suffix
IpNBTEnabled = Yes
UseFlags = Private Connection
ConnectOnWinlogon = No.
Information	7/10/2017 9:16:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/10/2017 9:12:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: cde756ad-6521-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/10/2017 9:06:37 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/10/2017 9:03:00 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Error	7/10/2017 9:01:21 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	7/10/2017 9:01:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {2620BAC6-2AF1-4B79-9DCA-BDAE0A0596C0}
Error	7/10/2017 9:01:21 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {2620BAC6-2AF1-4B79-9DCA-BDAE0A0596C0}
Information	7/10/2017 9:01:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/10/2017 9:01:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53813)(?)])(1 )(2 )]

"
Information	7/10/2017 9:01:21 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 53813)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/10/2017 9:01:21 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/10/2017 9:01:21 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/10/2017 9:01:19 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/10/2017 9:01:12 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Warning	7/10/2017 9:01:12 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/10/2017 9:00:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:20:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:04:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:49:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:34:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:18:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:03:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:48:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:33:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:18:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:02:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:47:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:32:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:22:31 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c1b97db9-630a-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/7/2017 5:17:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:02:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:57:45 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/7/2017 4:46:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:31:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:16:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:01:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:46:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:30:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:15:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:00:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:45:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:30:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:15:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/7/2017 2:13:24 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/7/2017 2:13:24 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/7/2017 1:59:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:44:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:29:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:14:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/7/2017 1:08:37 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/7/2017 12:59:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:57:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/7/2017 12:44:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:36:49 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8583.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/7/2017 12:28:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:22:28 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d719ea18-62e0-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/7/2017 12:13:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 11:58:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 11:43:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 11:28:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 11:13:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 10:57:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 10:42:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 10:27:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 10:11:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 9:56:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 9:41:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 9:26:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 9:21:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/7/2017 9:21:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:54:51Z. Reason: GVLK.
Warning	7/7/2017 9:19:05 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/7/2017 9:19:05 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/7/2017 9:16:51 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/7/2017 9:16:51 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256500)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/7/2017 9:16:51 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/7/2017 9:16:50 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/7/2017 9:11:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:57:28 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/7/2017 8:56:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:41:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:25:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 8:10:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:55:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:40:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:25:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 7:22:26 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ed0e3c65-62b6-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/7/2017 7:10:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:54:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:39:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:24:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 6:09:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:54:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:39:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:23:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 5:08:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:57:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/7/2017 4:53:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:38:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 4:28:28 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/7/2017 4:23:28 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/7/2017 4:23:28 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/7/2017 4:23:27 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/7/2017 4:23:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/7/2017 4:15:19 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/7/2017 4:15:19 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/7/2017 4:07:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:52:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:41:42 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/7/2017 3:37:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:22:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:11:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/7/2017 3:07:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/7/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58488)(?)])(1 )(2 )]

"
Information	7/7/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58488)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/7/2017 3:06:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/7/2017 3:06:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/7/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/7/2017 2:52:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:37:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:22:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 03031599-628d-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/7/2017 2:21:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 2:06:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:51:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:36:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 1:21:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/7/2017 1:08:31 AM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/7/2017 1:06:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:57:13 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/7/2017 12:50:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:35:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:20:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:05:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/7/2017 12:03:00 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/6/2017 11:50:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 11:35:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 11:19:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 11:04:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:49:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:39:28 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	7/6/2017 10:35:39 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	7/6/2017 10:34:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:20:43 PM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	7/6/2017 10:20:20 PM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	7/6/2017 10:19:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:10:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/6/2017 10:08:26 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/6/2017 10:05:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 10:05:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 10:05:36 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 10:04:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:03:21 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/6/2017 9:48:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:40:36 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 9:35:35 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 9:35:35 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 9:35:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 9:33:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:31:52 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 9:31:52 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/6/2017 9:30:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T15:57:18.710905700Z.
Information	7/6/2017 9:30:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{73713CDD-E4DA-4A2D-8331-67ECD8DCB41C}\4Sight™ 2.msi. Client Process Id: 4184.
Information	7/6/2017 9:27:18 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T15:57:18.710905700Z.
Information	7/6/2017 9:27:18 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{73713CDD-E4DA-4A2D-8331-67ECD8DCB41C}\4Sight™ 2.msi. Client Process Id: 4184.
Information	7/6/2017 9:23:49 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/6/2017 9:23:49 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/6/2017 9:22:22 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 18d9c5fc-6263-11e7-b65c-0205857feb80
Report Status: 0"
Information	7/6/2017 9:20:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T15:46:53.127953500Z.
Information	7/6/2017 9:20:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E4156F80-2C37-4C0D-AEF8-36B5D9247FC2}\4Sight™ 2.msi. Client Process Id: 6068.
Information	7/6/2017 9:18:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:16:53 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T15:46:53.127953500Z.
Information	7/6/2017 9:16:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E4156F80-2C37-4C0D-AEF8-36B5D9247FC2}\4Sight™ 2.msi. Client Process Id: 6068.
Information	7/6/2017 9:16:37 PM	PostgreSQL	0	None	Server started and accepting connections

Information	7/6/2017 9:16:36 PM	PostgreSQL	0	None	"2017-07-06 21:16:36 IST LOG:  redirecting log output to logging collector process
2017-07-06 21:16:36 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	7/6/2017 9:16:36 PM	PostgreSQL	0	None	Waiting for server startup...

Information	7/6/2017 9:13:20 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/6/2017 9:08:23 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	No protocol handler is available. Install a protocol handler that can process this URL type.  (HRESULT : 0x80040d37) (0x80040d37)
"
Warning	7/6/2017 9:08:23 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <ONEINDEX16://{S-1-5-21-3672398596-3227583511-885490141-1389459}/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	(HRESULT : 0x80004005) (0x80004005)
"
Information	7/6/2017 9:07:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2017 9:07:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58847)(?)])(1 )(2 )]

"
Information	7/6/2017 9:07:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58847)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 9:05:37 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 9:05:37 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 9:05:36 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 9:02:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 8:59:52 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 8:59:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:35Z. Reason: GVLK.
Warning	7/6/2017 8:58:37 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 8:58:37 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/6/2017 8:57:32 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 8:57:21 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 951

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 2200

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 484

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 1060

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 94

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 265

Information	7/6/2017 8:57:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 8:56:25 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/6/2017 8:56:22 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Information	7/6/2017 8:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2017 8:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58858)(?)])(1 )(2 )]

"
Information	7/6/2017 8:56:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58858)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 8:53:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2017 8:53:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58861)(?)])(1 )(2 )]

"
Information	7/6/2017 8:53:49 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 58861)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 8:53:49 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 8:53:49 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 8:53:48 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 8:53:47 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	7/6/2017 8:52:24 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/6/2017 8:52:22 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/6/2017 8:52:21 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/6/2017 8:52:20 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	7/6/2017 8:52:03 PM	ESENT	302	Logging/Recovery	Windows (8124) Windows: The database engine has successfully completed recovery steps.
Information	7/6/2017 8:52:00 PM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	7/6/2017 8:51:51 PM	ESENT	301	Logging/Recovery	Windows (8124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03B6F.log.
Information	7/6/2017 8:51:50 PM	ESENT	300	Logging/Recovery	Windows (8124) Windows: The database engine is initiating recovery steps.
Information	7/6/2017 8:51:50 PM	ESENT	102	General	Windows (8124) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	7/6/2017 8:51:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 8:51:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 8:51:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 8:51:39 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 8:51:38 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8582.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/6/2017 8:51:08 PM	Service1	0	None	Service started successfully.
Error	7/6/2017 8:50:57 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	7/6/2017 8:50:57 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	7/6/2017 8:50:36 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	7/6/2017 8:50:31 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	7/6/2017 8:50:30 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	7/6/2017 8:50:30 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0xffffffff, state: 63. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:29 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	7/6/2017 8:50:27 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	7/6/2017 8:50:26 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	7/6/2017 8:50:26 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	7/6/2017 8:50:26 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	7/6/2017 8:50:26 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	7/6/2017 8:50:25 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:25 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:25 PM	MSSQL$SQLEXPRESS	3406	Server	84 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	7/6/2017 8:50:23 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	7/6/2017 8:50:23 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	7/6/2017 8:50:23 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	7/6/2017 8:50:23 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	7/6/2017 8:50:23 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3544 at 7/6/2017 8:47:17 PM (local) 7/6/2017 3:17:17 PM (UTC). This is an informational message only; no user action is required.
Information	7/6/2017 8:50:21 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	7/6/2017 8:50:20 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	7/6/2017 8:50:20 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	7/6/2017 8:50:20 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	7/6/2017 8:50:20 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	7/6/2017 8:50:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	7/6/2017 8:50:11 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	7/6/2017 8:50:11 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	7/6/2017 8:50:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	7/6/2017 8:50:11 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3972.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	7/6/2017 8:50:06 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Warning	7/6/2017 8:49:36 PM	Cirrato Client Service	0	None	"The description for Event ID 0 from source Cirrato Client Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Unable get ComputerDomainAccountSID, error code: 1789: The trust relationship between this workstation and the primary domain failed.


"
Information	7/6/2017 8:49:29 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	7/6/2017 8:49:15 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	7/6/2017 8:49:16 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	7/6/2017 8:49:15 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	7/6/2017 8:47:20 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	7/6/2017 8:47:17 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	7/6/2017 8:47:10 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 31 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 2424 (\Device\HarddiskVolume1\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 972 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1784 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	7/6/2017 8:47:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	7/6/2017 8:47:08 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	7/6/2017 8:47:08 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	7/6/2017 8:46:52 PM	Microsoft-Windows-Winsrv	10001	None	The following application attempted to veto the shutdown: mctray.exe.
Information	7/6/2017 8:46:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:44:23 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/6/2017 8:44:23 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/6/2017 8:37:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 8:37:50 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:54:50Z. Reason: GVLK.
Information	7/6/2017 8:36:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T15:05:04.545973300Z.
Information	7/6/2017 8:36:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 8:36:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 8:36:28 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/6/2017 8:35:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T15:05:04.545973300Z.
Information	7/6/2017 8:34:59 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 8:32:50 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 8:32:50 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257220)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 8:32:50 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 8:32:50 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 8:31:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:17:07 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 8:17:07 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	7/6/2017 8:16:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:46:03.167972900Z.
Information	7/6/2017 8:16:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{6A14753E-914F-4A99-8B0D-A18D0DE9686D}\DeviceManager.msi. Client Process Id: 9992.
Information	7/6/2017 8:16:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:16:03 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:46:03.167972900Z.
Information	7/6/2017 8:16:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{6A14753E-914F-4A99-8B0D-A18D0DE9686D}\DeviceManager.msi. Client Process Id: 9992.
Information	7/6/2017 8:15:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:45:29.226972900Z.
Information	7/6/2017 8:15:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E331B8B1-0084-4DB7-AABD-8DD3F88FB44C}\DeviceDriver.msi. Client Process Id: 15104.
Information	7/6/2017 8:15:56 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.0.0.11. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 8:15:56 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	7/6/2017 8:15:29 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:45:29.226972900Z.
Information	7/6/2017 8:15:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E331B8B1-0084-4DB7-AABD-8DD3F88FB44C}\DeviceDriver.msi. Client Process Id: 15104.
Information	7/6/2017 8:13:43 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.4. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 8:13:43 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/6/2017 8:13:37 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:40:42.885372900Z.
Information	7/6/2017 8:13:37 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B20AF39D-C491-489B-B788-0A74949AF947}\4Sight™ 2.msi. Client Process Id: 15452.
Information	7/6/2017 8:10:42 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:40:42.885372900Z.
Information	7/6/2017 8:10:42 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B20AF39D-C491-489B-B788-0A74949AF947}\4Sight™ 2.msi. Client Process Id: 15452.
Information	7/6/2017 8:04:05 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:33:58.834772900Z.
Information	7/6/2017 8:04:05 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10084.
Information	7/6/2017 8:04:05 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 8:04:05 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	7/6/2017 8:03:58 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:33:58.834772900Z.
Information	7/6/2017 8:03:57 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10084.
Information	7/6/2017 8:02:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:32:24.537372900Z.
Information	7/6/2017 8:02:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10084.
Information	7/6/2017 8:02:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 8:02:59 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	7/6/2017 8:02:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:32:24.537372900Z.
Information	7/6/2017 8:02:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10084.
Information	7/6/2017 8:00:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:56:48 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T14:25:24.212972900Z.
Information	7/6/2017 7:56:48 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 7:56:48 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.3. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 7:56:48 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/6/2017 7:55:24 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T14:25:24.212972900Z.
Information	7/6/2017 7:55:12 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 7:45:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:30:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:15:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:00:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:44:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:29:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:14:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:59:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:44:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:29:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:13:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:58:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:56:08 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 4:55:55 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 4:43:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:41:10 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 4:41:10 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:10Z. Reason: GVLK.
Information	7/6/2017 4:36:10 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 4:36:10 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257460)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 4:36:10 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 4:36:09 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 4:28:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:22:21 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2f27791d-6239-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/6/2017 4:20:12 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: e2b5c55d-6238-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/6/2017 4:13:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:57:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:42:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:27:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:12:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:08:09 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.3. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 3:08:09 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/6/2017 3:07:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T09:33:07.553982100Z.
Information	7/6/2017 3:07:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{172DD477-D2BD-4D95-818F-BED52EB7D15D}\4Sight™ 2.msi. Client Process Id: 7272.
Information	7/6/2017 3:03:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T09:33:07.553982100Z.
Information	7/6/2017 3:02:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{172DD477-D2BD-4D95-818F-BED52EB7D15D}\4Sight™ 2.msi. Client Process Id: 7272.
Information	7/6/2017 3:00:41 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.3. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/6/2017 3:00:41 PM	MsiInstaller	11708	None	Product: 4Sight™ 2 -- Installation operation failed.
Information	7/6/2017 2:57:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:49:39 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T09:17:22.730982100Z.
Information	7/6/2017 2:49:39 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 2:49:39 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.1. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 2:49:39 PM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/6/2017 2:47:22 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T09:17:22.730982100Z.
Information	7/6/2017 2:47:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10084.
Information	7/6/2017 2:44:07 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 2:44:07 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:07Z. Reason: GVLK.
Information	7/6/2017 2:42:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:39:07 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 2:39:07 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257580)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 2:39:06 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 2:39:05 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 2:26:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:11:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:56:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:41:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:26:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:10:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:10:38 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 1:10:38 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:38Z. Reason: GVLK.
Warning	7/6/2017 1:06:09 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 1:06:09 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 1:05:38 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 1:05:38 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 1:05:38 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 1:05:35 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 12:56:02 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 12:55:53 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 12:55:51 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/6/2017 12:55:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:55:43 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 12:44:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8582.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/6/2017 12:44:12 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 12:44:12 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	7/6/2017 12:44:06 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T07:13:31.219865400Z.
Information	7/6/2017 12:44:06 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{335014F9-886E-4CE5-926E-C8341CFE9719}\DeviceManager.msi. Client Process Id: 15024.
Information	7/6/2017 12:43:31 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T07:13:31.219865400Z.
Information	7/6/2017 12:43:30 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{335014F9-886E-4CE5-926E-C8341CFE9719}\DeviceManager.msi. Client Process Id: 15024.
Information	7/6/2017 12:42:34 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T07:09:28.392865400Z.
Information	7/6/2017 12:42:34 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E6F8E9A0-2437-41DD-9D7E-6BFA0AE2C2AA}\DeviceDriver.msi. Client Process Id: 13992.
Information	7/6/2017 12:42:34 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Information	7/6/2017 12:42:34 PM	MsiInstaller	11728	None	Product: DeviceDriver -- Configuration completed successfully.
Information	7/6/2017 12:40:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:39:28 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T07:09:28.392865400Z.
Information	7/6/2017 12:39:28 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E6F8E9A0-2437-41DD-9D7E-6BFA0AE2C2AA}\DeviceDriver.msi. Client Process Id: 13992.
Information	7/6/2017 12:39:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: DeviceDriver. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Warning	7/6/2017 12:38:56 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 12:38:56 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 12:35:02 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 1602.
Information	7/6/2017 12:35:02 PM	MsiInstaller	11708	None	Product: DeviceManager -- Installation operation failed.
Information	7/6/2017 12:34:58 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T07:04:13.724865400Z.
Information	7/6/2017 12:34:58 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9B7F9D5C-C150-49F9-8D86-1ADB359FF66B}\DeviceDriver.msi. Client Process Id: 16592.
Information	7/6/2017 12:34:58 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.0.0.5. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 12:34:58 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	7/6/2017 12:34:13 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T07:04:13.724865400Z.
Information	7/6/2017 12:34:13 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9B7F9D5C-C150-49F9-8D86-1ADB359FF66B}\DeviceDriver.msi. Client Process Id: 16592.
Warning	7/6/2017 12:30:18 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 12:30:18 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 12:25:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:10:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/6/2017 12:02:27 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 12:02:27 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 12:00:59 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 11:57:26 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.1. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/6/2017 11:57:26 AM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/6/2017 11:57:00 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T06:21:59.432865400Z.
Information	7/6/2017 11:57:00 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E641DEC8-7489-4D43-BB28-907B5698AAFC}\4Sight™ 2.msi. Client Process Id: 12728.
Information	7/6/2017 11:55:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2017 11:55:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59399)(?)])(1 )(2 )]

"
Information	7/6/2017 11:55:46 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59399)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 11:55:46 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 11:55:46 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 11:55:41 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 11:54:58 AM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 2 second(s) (analysis 959 ms, redo 0 ms, undo 278 ms.) This is an informational message only. No user action is required.
Information	7/6/2017 11:54:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 11:54:11 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	7/6/2017 11:53:51 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Warning	7/6/2017 11:53:31 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:53:31 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 11:51:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T06:21:59.432865400Z.
Information	7/6/2017 11:51:17 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{E641DEC8-7489-4D43-BB28-907B5698AAFC}\4Sight™ 2.msi. Client Process Id: 12728.
Information	7/6/2017 11:39:44 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/6/2017 11:37:07 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:37:07 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/6/2017 11:36:50 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:36:50 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/6/2017 11:36:30 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:36:30 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/6/2017 11:36:15 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:36:15 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 11:32:08 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T06:01:59.757931000Z.
Information	7/6/2017 11:32:08 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10608.
Information	7/6/2017 11:32:08 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 11:32:08 AM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	7/6/2017 11:31:59 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T06:01:59.757931000Z.
Information	7/6/2017 11:31:57 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 10608.
Information	7/6/2017 11:29:12 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T05:58:30.582873000Z.
Information	7/6/2017 11:29:12 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10608.
Information	7/6/2017 11:29:12 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 11:29:12 AM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	7/6/2017 11:28:30 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T05:58:30.582873000Z.
Information	7/6/2017 11:28:25 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 10608.
Warning	7/6/2017 11:28:05 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 11:28:05 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 11:27:38 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎06T05:54:24.995635000Z.
Information	7/6/2017 11:27:38 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10608.
Information	7/6/2017 11:27:38 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.752. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/6/2017 11:27:38 AM	MsiInstaller	11724	None	Product: 4Sight™ 2 -- Removal completed successfully.
Information	7/6/2017 11:24:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 11:24:24 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎06T05:54:24.995635000Z.
Information	7/6/2017 11:21:21 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 10608.
Information	7/6/2017 11:21:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2042ea9f-620f-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/6/2017 11:20:47 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Error	7/6/2017 11:20:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/6/2017 11:20:37 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/6/2017 11:09:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:54:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:38:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:26:52 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/6/2017 10:23:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 10:08:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:53:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:38:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:22:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 9:07:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:55:55 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/6/2017 8:55:37 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/6/2017 8:52:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:37:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:21:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 8:06:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:51:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:36:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:21:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 7:06:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:50:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:35:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:20:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 6:05:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:50:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:34:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:19:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 5:04:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:55:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/6/2017 4:55:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/6/2017 4:49:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:34:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:18:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 4:03:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:48:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:33:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:18:25 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 3:18:25 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:25Z. Reason: GVLK.
Information	7/6/2017 3:18:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 3:13:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 3:13:21 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 3:13:21 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 3:13:21 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 3:13:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 3:11:12 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/6/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59928)(?)])(1 )(2 )]

"
Information	7/6/2017 3:06:12 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 59928)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 3:06:11 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/6/2017 3:06:11 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 3:06:11 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 3:02:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:47:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:32:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:17:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 2:02:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:46:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:31:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:21:09 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4a2855dd-61bb-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/6/2017 1:16:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 1:01:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:55:47 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 12:55:45 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/6/2017 12:55:19 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/6/2017 12:45:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:30:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:15:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/6/2017 12:12:06 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/6/2017 12:12:06 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:55:06Z. Reason: GVLK.
Warning	7/6/2017 12:09:52 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/6/2017 12:09:52 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/6/2017 12:07:05 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/6/2017 12:07:05 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258480)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/6/2017 12:07:05 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/6/2017 12:07:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/6/2017 12:00:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 11:45:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 11:30:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 11:14:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 10:59:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 10:44:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 10:29:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 10:14:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 9:58:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 9:43:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 9:28:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 9:13:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 8:58:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 8:54:59 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2017 8:42:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 8:27:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 8:21:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 5f995123-6191-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/5/2017 8:17:11 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d363bb53-6190-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/5/2017 8:12:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 8:04:18 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4Sight™ 2. Product Version: 1.0.0.752. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/5/2017 8:04:18 PM	MsiInstaller	11707	None	Product: 4Sight™ 2 -- Installation operation completed successfully.
Information	7/5/2017 8:03:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎05T14:30:44.029996300Z.
Information	7/5/2017 8:03:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{41D59B3E-EE60-4DEE-BF4B-3E70051D52CB}\4Sight™ 2.msi. Client Process Id: 7344.
Information	7/5/2017 8:00:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎05T14:30:44.029996300Z.
Information	7/5/2017 8:00:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{41D59B3E-EE60-4DEE-BF4B-3E70051D52CB}\4Sight™ 2.msi. Client Process Id: 7344.
Information	7/5/2017 7:57:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 7:57:01 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 01dbc59b-618e-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/5/2017 7:49:51 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎05T14:18:06.362296300Z.
Information	7/5/2017 7:49:51 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7352.
Information	7/5/2017 7:49:51 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.749. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/5/2017 7:49:51 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	7/5/2017 7:48:06 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎05T14:18:06.362296300Z.
Information	7/5/2017 7:47:48 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 7352.
Information	7/5/2017 7:42:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 7:27:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 7:11:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 6:56:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 6:41:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 6:26:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 6:13:51 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 6:13:51 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 6:11:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 6:11:16 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 6:11:16 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 5:56:14 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/5/2017 5:54:06 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 5:54:06 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/5/2017 5:52:12 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 5:52:12 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	7/5/2017 5:51:56 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 5:51:56 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 5:51:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2017 5:51:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60483)(?)])(1 )(2 )]

"
Information	7/5/2017 5:51:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60483)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 5:50:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2017 5:50:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60484)(?)])(1 )(2 )]

"
Information	7/5/2017 5:50:57 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60484)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 5:50:57 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/5/2017 5:50:57 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2017 5:50:56 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/5/2017 5:41:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 5:11:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 5:04:34 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 5:04:34 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Error	7/5/2017 5:01:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/5/2017 5:01:40 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/5/2017 5:01:34 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/5/2017 5:00:34 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 5:00:34 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 4:56:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2017 4:56:29 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60538)(?)])(1 )(2 )]

"
Information	7/5/2017 4:56:28 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60538)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	7/5/2017 4:55:55 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 4:55:55 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 4:55:25 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 15

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 63

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 156

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 156

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 0

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 32

Warning	7/5/2017 4:55:06 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	7/5/2017 4:55:04 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 4:55:04 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	7/5/2017 4:55:04 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\Documents\Outlook Files\archive.pst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 4:55:03 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	7/5/2017 4:54:56 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2017 4:54:49 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	7/5/2017 4:54:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2017 4:54:39 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60540)(?)])(1 )(2 )]

"
Information	7/5/2017 4:54:38 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60540)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 4:54:38 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/5/2017 4:54:38 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2017 4:54:38 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	7/5/2017 4:54:29 PM	Microsoft Office 16	1000	None	Faulting application outlook.exe, version 16.0.7766.2092, stamp 59346a45, faulting module mso20win32client.dll, version 16.0.7726.1042, stamp 5932cbb5, debug? 0, fault address 0x00107b6b.
Information	7/5/2017 4:41:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 4:11:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 4:08:29 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 4:08:29 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 3:41:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 3:21:03 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 74e10499-6167-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/5/2017 3:11:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 2:41:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 2:11:06 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2017 2:10:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 2:10:42 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2017 1:40:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 1:10:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 12:40:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 12:16:06 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 12:16:06 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 12:10:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/5/2017 12:07:27 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/5/2017 11:40:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 11:30:43 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/5/2017 11:30:43 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-12T05:54:43Z. Reason: GVLK.
Information	7/5/2017 11:25:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 11:25:43 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 11:25:42 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/07/05 05:55"
Information	7/5/2017 11:25:41 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/07/05 05:55, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	7/5/2017 11:20:38 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/5/2017 11:20:38 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 11:20:38 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2017 11:20:37 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/5/2017 11:10:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 11:02:13 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/5/2017 11:02:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Error	7/5/2017 10:59:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	7/5/2017 10:59:32 AM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	7/5/2017 10:41:48 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8581.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/5/2017 10:40:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/5/2017 10:20:55 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 870cb5dc-613d-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/5/2017 10:20:41 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/5/2017 10:20:41 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:37Z. Reason: GVLK.
Information	7/5/2017 10:15:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/5/2017 10:15:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/5/2017 10:15:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249240)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 10:15:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2017 10:15:34 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/5/2017 10:12:41 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/5/2017 10:10:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/5/2017 10:10:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60944)(?)])(1 )(2 )]

"
Information	7/5/2017 10:10:50 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 60944)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/5/2017 10:10:49 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/5/2017 10:10:49 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/5/2017 10:10:49 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/5/2017 10:10:46 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/5/2017 10:10:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 7:54:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 7:39:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 7:24:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 7:09:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 6:54:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 6:39:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 6:24:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 6:08:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 6:03:41 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2017 6:02:32 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.749. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/4/2017 6:02:32 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	7/4/2017 6:01:14 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎04T12:27:47.232480400Z.
Information	7/4/2017 6:01:14 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3E45ED53-D14B-4A40-A63F-181F19779FF4}\4SightV2.msi. Client Process Id: 11932.
Information	7/4/2017 5:57:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎04T12:27:47.232480400Z.
Information	7/4/2017 5:57:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3E45ED53-D14B-4A40-A63F-181F19779FF4}\4SightV2.msi. Client Process Id: 11932.
Information	7/4/2017 5:54:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎04T12:23:16.138680400Z.
Information	7/4/2017 5:54:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/4/2017 5:54:43 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.749. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/4/2017 5:54:43 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	7/4/2017 5:53:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 5:53:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎04T12:23:16.138680400Z.
Information	7/4/2017 5:53:00 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/4/2017 5:42:50 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/4/2017 5:38:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 5:37:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/4/2017 5:37:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61937)(?)])(1 )(2 )]

"
Information	7/4/2017 5:37:45 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 61937)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2017 5:37:45 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/4/2017 5:37:45 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/4/2017 5:37:44 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/4/2017 5:23:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 5:08:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 4:52:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 4:37:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 4:22:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 4:07:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 3:52:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 3:37:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 3:21:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 3:13:20 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 368822fb-609d-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/4/2017 3:06:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 2:51:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 2:36:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 2:21:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 2:16:44 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.749. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/4/2017 2:16:44 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	7/4/2017 2:16:41 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎04T08:43:34.264204500Z.
Information	7/4/2017 2:16:41 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9AFF3DFC-5441-416E-9DF4-E4A244641F29}\4SightV2.msi. Client Process Id: 15884.
Information	7/4/2017 2:16:35 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/4/2017 2:16:35 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:34Z. Reason: GVLK.
Information	7/4/2017 2:13:34 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎04T08:43:34.264204500Z.
Information	7/4/2017 2:13:33 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{9AFF3DFC-5441-416E-9DF4-E4A244641F29}\4SightV2.msi. Client Process Id: 15884.
Information	7/4/2017 2:11:34 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/4/2017 2:11:34 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 250440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2017 2:11:34 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/4/2017 2:11:33 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/4/2017 2:05:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 2:03:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/4/2017 1:50:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 1:35:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 1:20:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 1:05:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 12:50:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 12:34:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 12:19:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 12:11:33 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎04T06:39:54.522913700Z.
Information	7/4/2017 12:11:33 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/4/2017 12:11:33 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.746. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/4/2017 12:11:33 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	7/4/2017 12:09:54 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎04T06:39:54.522913700Z.
Information	7/4/2017 12:09:38 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/4/2017 12:04:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 11:49:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 11:34:11 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 11:19:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 11:03:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 10:48:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 10:33:50 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8580.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/4/2017 10:33:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 10:26:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/4/2017 10:18:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/4/2017 10:13:17 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4b722b2b-6073-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/4/2017 10:08:47 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	7/4/2017 10:07:54 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/4/2017 10:07:54 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/4/2017 10:04:38 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/4/2017 10:03:40 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/4/2017 10:03:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62391)(?)])(1 )(2 )]

"
Information	7/4/2017 10:03:39 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 62391)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/4/2017 10:03:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/4/2017 10:03:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Warning	7/4/2017 10:03:37 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/4/2017 10:03:37 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/4/2017 10:03:35 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/4/2017 10:03:24 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	7/4/2017 10:03:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 8:37:51 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 61820851-6001-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/3/2017 8:33:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 8:18:21 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/3/2017 8:10:46 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/3/2017 8:10:46 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/3/2017 8:03:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 7:48:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 7:32:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 7:17:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 7:02:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 6:47:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 6:31:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 6:27:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 6:27:23 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 6:26:52 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 6:16:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 6:01:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/3/2017 5:59:26 PM	ASP.NET 4.0.30319.0	1309	Web Event	"Event code: 3005 
Event message: An unhandled exception has occurred. 
Event time: 7/3/2017 5:59:26 PM 
Event time (UTC): 7/3/2017 12:29:26 PM 
Event ID: 6ae041b7345f47eeb9ef5e54de1430bc 
Event sequence: 4 
Event occurrence: 3 
Event detail code: 0 
 
Application information: 
    Application domain: /LM/W3SVC/1/ROOT-1-131435585034644940 
    Trust level: Full 
    Application Virtual Path: / 
    Application Path: C:\inetpub\wwwroot\ 
    Machine name: GGPBK882E 
 
Process information: 
    Process ID: 6756 
    Process name: w3wp.exe 
    Account name: IIS APPPOOL\DefaultAppPool 
 
Exception information: 
    Exception type: HttpException 
    Exception message: A potentially dangerous Request.Path value was detected from the client (<).
   at System.Web.HttpRequest.ValidateInputIfRequiredByConfig()
   at System.Web.HttpApplication.PipelineStepManager.ValidateHelper(HttpContext context)

 
 
Request information: 
    Request URL: http://ggpbk882e/indexd.html/<script>alert(1)</script> 
    Request path: /indexd.html/<script>alert(1)</script> 
    User host address: 10.7.127.118 
    User:  
    Is authenticated: False 
    Authentication Type:  
    Thread account name: IIS APPPOOL\DefaultAppPool 
 
Thread information: 
    Thread ID: 8 
    Thread account name: IIS APPPOOL\DefaultAppPool 
    Is impersonating: False 
    Stack trace:    at System.Web.HttpRequest.ValidateInputIfRequiredByConfig()
   at System.Web.HttpApplication.PipelineStepManager.ValidateHelper(HttpContext context)
 
 
Custom event details: 
"
Warning	7/3/2017 5:58:23 PM	ASP.NET 4.0.30319.0	1309	Web Event	"Event code: 3005 
Event message: An unhandled exception has occurred. 
Event time: 7/3/2017 5:58:23 PM 
Event time (UTC): 7/3/2017 12:28:23 PM 
Event ID: bc54531e52214e01a787a6341b421d84 
Event sequence: 2 
Event occurrence: 1 
Event detail code: 0 
 
Application information: 
    Application domain: /LM/W3SVC/1/ROOT-1-131435585034644940 
    Trust level: Full 
    Application Virtual Path: / 
    Application Path: C:\inetpub\wwwroot\ 
    Machine name: GGPBK882E 
 
Process information: 
    Process ID: 6756 
    Process name: w3wp.exe 
    Account name: IIS APPPOOL\DefaultAppPool 
 
Exception information: 
    Exception type: HttpException 
    Exception message: A potentially dangerous Request.Path value was detected from the client (<).
   at System.Web.HttpRequest.ValidateInputIfRequiredByConfig()
   at System.Web.HttpApplication.PipelineStepManager.ValidateHelper(HttpContext context)

 
 
Request information: 
    Request URL: http://ggpbk882e/indexd.html/<script>alert(1)</script> 
    Request path: /indexd.html/<script>alert(1)</script> 
    User host address: 10.7.127.118 
    User:  
    Is authenticated: False 
    Authentication Type:  
    Thread account name: IIS APPPOOL\DefaultAppPool 
 
Thread information: 
    Thread ID: 6 
    Thread account name: IIS APPPOOL\DefaultAppPool 
    Is impersonating: False 
    Stack trace:    at System.Web.HttpRequest.ValidateInputIfRequiredByConfig()
   at System.Web.HttpApplication.PipelineStepManager.ValidateHelper(HttpContext context)
 
 
Custom event details: 
"
Information	7/3/2017 5:46:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 5:31:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 5:16:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 5:00:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 4:54:24 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/3/2017 4:49:23 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/3/2017 4:49:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63425)(?)])(1 )(2 )]

"
Information	7/3/2017 4:49:22 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63425)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 4:48:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/3/2017 4:48:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63426)(?)])(1 )(2 )]

"
Information	7/3/2017 4:48:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63426)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 4:48:56 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/3/2017 4:48:56 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2017 4:48:55 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/3/2017 4:45:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 4:30:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 4:17:57 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.746. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	7/3/2017 4:17:57 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	7/3/2017 4:15:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 4:15:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎03T10:40:33.828404200Z.
Information	7/3/2017 4:15:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F2E5E24A-4B92-4C62-A46D-C692BC2033F2}\4SightV2.msi. Client Process Id: 15016.
Information	7/3/2017 4:10:33 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎03T10:40:33.828404200Z.
Information	7/3/2017 4:10:21 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{F2E5E24A-4B92-4C62-A46D-C692BC2033F2}\4SightV2.msi. Client Process Id: 15016.
Information	7/3/2017 4:00:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 3:45:07 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 3:37:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 76a4a542-5fd7-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/3/2017 3:29:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 3:14:47 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 2:59:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/3/2017 2:57:36 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/3/2017 2:57:36 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/3/2017 2:44:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 2:29:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 2:27:38 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 2:27:12 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 2:26:46 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Warning	7/3/2017 2:20:22 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/3/2017 2:20:22 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/3/2017 2:14:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 2:05:11 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎07‎-‎03T08:32:44.434480400Z.
Information	7/3/2017 2:05:11 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/3/2017 2:05:11 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	7/3/2017 2:05:11 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	7/3/2017 2:02:44 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎07‎-‎03T08:32:44.434480400Z.
Information	7/3/2017 2:02:02 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	7/3/2017 1:58:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 1:43:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 1:28:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 1:27:02 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	7/3/2017 1:13:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 12:58:15 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/3/2017 12:51:00 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/3/2017 12:51:00 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/3/2017 12:43:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	7/3/2017 12:42:24 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	7/3/2017 12:27:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 12:12:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 12:10:58 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/3/2017 12:10:57 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:57Z. Reason: GVLK.
Information	7/3/2017 12:08:58 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	7/3/2017 12:05:57 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/3/2017 12:05:57 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252000)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 12:05:57 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2017 12:05:56 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/3/2017 11:57:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 11:42:23 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 11:33:54 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/3/2017 11:28:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/3/2017 11:28:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63746)(?)])(1 )(2 )]

"
Information	7/3/2017 11:28:51 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63746)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 11:28:51 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/3/2017 11:28:51 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2017 11:28:50 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/3/2017 11:27:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 11:12:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 10:57:24 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8579.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	7/3/2017 10:56:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 10:41:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	7/3/2017 10:37:44 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80072ee2
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 8bba62e6-5fad-11e7-b61a-80000bd6758f
Report Status: 0"
Information	7/3/2017 10:36:47 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	7/3/2017 10:36:47 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:45Z. Reason: GVLK.
Information	7/3/2017 10:32:07 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	7/3/2017 10:30:56 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 10:28:53 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	7/3/2017 10:28:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	7/3/2017 10:28:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 252060)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 10:28:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2017 10:28:40 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	7/3/2017 10:27:25 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 10:27:24 AM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	7/3/2017 10:27:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	7/3/2017 10:27:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63807)(?)])(1 )(2 )]

"
Information	7/3/2017 10:27:03 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 63807)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	7/3/2017 10:27:03 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	7/3/2017 10:27:03 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	7/3/2017 10:27:02 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	7/3/2017 10:26:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	7/3/2017 10:26:35 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	7/3/2017 10:26:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:50:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:35:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:25:28 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 7:20:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 7:20:26 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67594)(?)])(1 )(2 )]

"
Information	6/30/2017 7:20:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67594)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 7:20:25 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/30/2017 7:20:25 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 7:20:25 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 7:20:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:16:20 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/30/2017 7:16:20 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/30/2017 7:15:53 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T13:41:55.264537000Z.
Information	6/30/2017 7:15:53 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{5DEAFC4D-ABF0-4F96-884F-7967CC9C247A}\4SightV2.msi. Client Process Id: 13404.
Information	6/30/2017 7:11:55 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T13:41:55.264537000Z.
Information	6/30/2017 7:11:52 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{5DEAFC4D-ABF0-4F96-884F-7967CC9C247A}\4SightV2.msi. Client Process Id: 13404.
Information	6/30/2017 7:08:20 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T13:36:48.343848000Z.
Information	6/30/2017 7:08:20 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	6/30/2017 7:08:20 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/30/2017 7:08:20 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/30/2017 7:07:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 7:06:48 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T13:36:48.343848000Z.
Information	6/30/2017 7:06:43 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	6/30/2017 7:05:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:02:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 7:02:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67612)(?)])(1 )(2 )]

"
Information	6/30/2017 7:02:46 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67612)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 7:01:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 7:01:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67614)(?)])(1 )(2 )]

"
Information	6/30/2017 7:00:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67614)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 7:00:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 7:00:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67614)(?)])(1 )(2 )]

"
Information	6/30/2017 7:00:27 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67614)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 6:59:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 6:59:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67615)(?)])(1 )(2 )]

"
Information	6/30/2017 6:59:37 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67615)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 6:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 6:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67616)(?)])(1 )(2 )]

"
Information	6/30/2017 6:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67616)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 6:58:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/30/2017 6:58:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 6:58:53 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 6:49:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:44:15 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 6:39:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 6:39:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67635)(?)])(1 )(2 )]

"
Information	6/30/2017 6:39:12 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67635)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Warning	6/30/2017 6:37:34 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/30/2017 6:37:34 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/30/2017 6:34:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:32:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 6:32:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67642)(?)])(1 )(2 )]

"
Information	6/30/2017 6:32:01 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67642)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 6:32:01 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	6/30/2017 6:32:00 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 67642)(?)])(1 )(2 )]

"
Information	6/30/2017 6:32:00 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/30/2017 6:32:00 PM	Office Software Protection Platform Service	1036	None	Validity period has been started. Validity minutes=110842  Grace type=8.
Information	6/30/2017 6:31:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}
License Id=032a4a7d-b23c-4896-b8ef-dcb0c5175113"
Information	6/30/2017 6:31:59 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PUBLIC}
License Id=6a49b5d4-d75b-493e-927a-57d0c7d387e9"
Information	6/30/2017 6:31:59 PM	Office Software Protection Platform Service	1013	None	"Acquisition of End User License was successful.
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/30/2017 6:31:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 6:31:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21563)(?)])(1 )(2 )]

"
Information	6/30/2017 6:31:53 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 21563)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 6:31:53 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/30/2017 6:31:53 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 6:31:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Warning	6/30/2017 6:29:00 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/30/2017 6:29:00 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/30/2017 6:19:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:04:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/30/2017 5:52:07 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/30/2017 5:52:07 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/30/2017 5:51:45 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/30/2017 5:51:45 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/30/2017 5:51:43 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T12:18:16.443140600Z.
Information	6/30/2017 5:51:43 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B926E6CB-B0CB-49B3-930C-59BF7FD136B7}\4SightV2.msi. Client Process Id: 4120.
Information	6/30/2017 5:49:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:48:16 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T12:18:16.443140600Z.
Information	6/30/2017 5:48:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{B926E6CB-B0CB-49B3-930C-59BF7FD136B7}\4SightV2.msi. Client Process Id: 4120.
Information	6/30/2017 5:44:31 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T12:13:04.016140600Z.
Information	6/30/2017 5:44:31 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	6/30/2017 5:44:31 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/30/2017 5:44:31 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/30/2017 5:43:04 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T12:13:04.016140600Z.
Information	6/30/2017 5:43:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 4460.
Information	6/30/2017 5:39:40 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.740. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/30/2017 5:39:40 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/30/2017 5:39:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T12:04:56.697140600Z.
Information	6/30/2017 5:39:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{701ED099-4A36-43BC-BD20-FB3F121FB35F}\4SightV2.msi. Client Process Id: 13604.
Information	6/30/2017 5:34:56 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T12:04:56.697140600Z.
Information	6/30/2017 5:34:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{701ED099-4A36-43BC-BD20-FB3F121FB35F}\4SightV2.msi. Client Process Id: 13604.
Information	6/30/2017 5:34:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:18:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:03:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:57:39 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/30/2017 4:48:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:46:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎30T11:15:05.503527300Z.
Information	6/30/2017 4:46:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9680.
Information	6/30/2017 4:46:55 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.738. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/30/2017 4:46:55 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/30/2017 4:45:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎30T11:15:05.503527300Z.
Information	6/30/2017 4:44:49 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 9680.
Information	6/30/2017 4:33:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:28:47 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 4:28:21 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 4:18:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:02:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:47:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:41:51 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 3:41:51 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:51Z. Reason: GVLK.
Information	6/30/2017 3:36:51 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/30/2017 3:36:51 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256080)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 3:36:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 3:36:51 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 3:32:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:17:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:02:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:47:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:32:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:16:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:01:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:46:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:31:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:16:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/30/2017 1:09:03 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/30/2017 1:01:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:45:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:30:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:28:36 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 12:28:04 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 12:17:39 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/30/2017 12:15:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:00:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 11:45:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 11:30:00 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 11:14:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 10:59:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 10:44:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 10:33:24 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 71a86131-5d51-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/30/2017 10:29:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 10:14:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 10:14:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/30/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22066)(?)])(1 )(2 )]

"
Information	6/30/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 22066)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 10:09:22 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/30/2017 10:09:22 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 10:09:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 9:58:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 9:43:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 9:35:28 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	6/30/2017 9:28:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 9:13:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 8:58:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 8:43:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 8:28:32 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 8:28:02 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 8:27:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 8:17:55 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/30/2017 8:17:44 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/30/2017 8:12:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:57:34 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:42:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:27:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 7:12:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:56:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:53:39 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 6:48:39 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/30/2017 6:48:39 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 6:48:38 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 6:41:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:26:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 6:11:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:55:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:40:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:33:21 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 86b723cc-5d27-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/30/2017 5:25:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 5:10:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:55:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:39:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:28:20 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 4:27:52 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 4:24:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:09:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 4:00:51 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/30/2017 4:00:51 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:50Z. Reason: GVLK.
Information	6/30/2017 3:55:47 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 3:55:46 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/30/2017 3:55:46 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256800)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/30/2017 3:55:46 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/30/2017 3:55:46 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/30/2017 3:54:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:53:19 AM	Outlook	26	None	Connection to Microsoft Exchange has been restored.
Information	6/30/2017 3:53:07 AM	Outlook	26	None	Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible.
Information	6/30/2017 3:39:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:23:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 3:08:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:53:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:38:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:23:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 2:08:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:52:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:37:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:22:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 1:21:19 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8576.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	6/30/2017 1:07:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:52:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:37:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:33:18 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 9c188364-5cfd-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/30/2017 12:28:10 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 12:27:41 AM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/30/2017 12:21:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/30/2017 12:16:57 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/30/2017 12:06:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:51:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:36:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:21:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:07:42 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2017 11:07:42 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:42Z. Reason: GVLK.
Information	6/29/2017 11:06:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:02:42 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2017 11:02:42 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257100)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2017 11:02:42 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2017 11:02:42 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2017 10:55:29 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: f1aec53a-5cef-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 10:50:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/29/2017 10:50:49 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/29/2017 10:26:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 10:11:46 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:56:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:41:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:26:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:11:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:55:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:40:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:30:01 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/29/2017 8:29:58 PM	PostgreSQL	0	None	"2017-06-29 20:29:58 IST LOG:  redirecting log output to logging collector process
2017-06-29 20:29:58 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/29/2017 8:29:55 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/29/2017 8:27:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2017 8:27:37 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/29/2017 8:27:11 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2017 8:25:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:12:09 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/29/2017 8:10:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:55:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:40:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:33:15 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: b160969f-5cd3-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 7:24:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:09:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:54:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:39:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:24:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/29/2017 6:22:55 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/29/2017 6:22:55 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/29/2017 6:16:33 PM	McLogEvent	257	None	The scan of C:\Program Files (x86)\sparx systems\EA Trial\EA.exe has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8575.0000.
Information	6/29/2017 6:08:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/29/2017 6:05:29 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/29/2017 6:05:29 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/29/2017 5:53:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:38:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:23:55 PM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	6/29/2017 5:23:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:08:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:04:08 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/29/2017 4:53:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:38:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:32:11 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	6/29/2017 4:27:14 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/29/2017 4:27:07 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 47

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 281

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 140

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 234

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 47

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 109

Information	6/29/2017 4:27:03 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/29/2017 4:26:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/29/2017 4:26:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23128)(?)])(1 )(2 )]

"
Information	6/29/2017 4:26:59 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23128)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2017 4:26:59 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/29/2017 4:26:59 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2017 4:26:57 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/29/2017 4:26:53 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\Documents\Outlook Files\archive.pst for the following reason: The store was last opened on a different machine.
Information	6/29/2017 4:26:53 PM	Outlook	30	None	Starting reconciliation for the store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost for the following reason: The store was last opened on a different machine.
Error	6/29/2017 4:23:42 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	6/29/2017 4:23:42 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/29/2017 4:22:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:07:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:52:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:37:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:22:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:06:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:51:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:36:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:33:07 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: c3f21f29-5ca9-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 2:21:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:09:44 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024402c
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: ChkWuDrv
P9: {9482F4B4-E343-43B6-B170-9A65BC822C77}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 7fcd488f-5ca6-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 2:06:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:51:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:35:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:20:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:15:09 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2017 1:15:09 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:51:09Z. Reason: GVLK.
Information	6/29/2017 1:10:09 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2017 1:10:09 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 257700)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2017 1:10:09 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2017 1:10:08 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2017 1:05:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:50:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:43:53 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8575.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	6/29/2017 12:35:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:19:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:12:41 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.738. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/29/2017 12:12:41 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/29/2017 12:12:35 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎29T06:37:45.843442200Z.
Information	6/29/2017 12:12:35 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{06F2EF5F-22E5-4F99-AD80-C931E53B4B37}\4SightV2.msi. Client Process Id: 6012.
Information	6/29/2017 12:07:45 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎29T06:37:45.843442200Z.
Information	6/29/2017 12:07:29 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{06F2EF5F-22E5-4F99-AD80-C931E53B4B37}\4SightV2.msi. Client Process Id: 6012.
Information	6/29/2017 12:04:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:00:28 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎29T06:28:46.458641900Z.
Information	6/29/2017 12:00:28 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/29/2017 12:00:28 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/29/2017 12:00:28 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/29/2017 11:58:46 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎29T06:28:46.458641900Z.
Information	6/29/2017 11:58:28 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/29/2017 11:49:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:44:11 AM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Reconfiguration success or error status: 0.
Error	6/29/2017 11:41:40 AM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x297c
Faulting application start time: 0x01d2f093237b6f43
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: d06709c3-5c91-11e7-b61a-80000bd6758f"
Information	6/29/2017 11:34:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:19:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 11:03:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 10:48:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 10:33:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	6/29/2017 10:18:49 AM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x2acc
Faulting application start time: 0x01d2f089d68fed5d
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: 3d50eda3-5c86-11e7-b61a-80000bd6758f"
Information	6/29/2017 10:18:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 10:14:24 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/29/2017 10:09:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/29/2017 10:09:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23506)(?)])(1 )(2 )]

"
Information	6/29/2017 10:09:24 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 23506)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2017 10:09:24 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/29/2017 10:09:24 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2017 10:09:23 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/29/2017 10:03:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:48:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:33:04 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: d92089e5-5c7f-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 9:32:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 9:17:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	6/29/2017 9:12:14 AM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x2668
Faulting application start time: 0x01d2f08998202cf8
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: f06a94c4-5c7c-11e7-b61a-80000bd6758f"
Error	6/29/2017 9:11:07 AM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x24e0
Faulting application start time: 0x01d2f0195c6dfba6
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: c8807934-5c7c-11e7-b61a-80000bd6758f"
Information	6/29/2017 9:02:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:47:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:32:03 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:16:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 8:01:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:46:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:31:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:16:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 7:00:50 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:45:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:30:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:15:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 6:03:02 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/29/2017 6:03:01 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:51:01Z. Reason: GVLK.
Information	6/29/2017 6:00:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:58:01 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/29/2017 5:58:01 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258120)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/29/2017 5:58:01 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/29/2017 5:58:00 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/29/2017 5:44:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:29:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 5:14:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:59:13 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:44:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:32:57 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: ec5062b4-5c55-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/29/2017 4:28:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 4:13:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:58:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:43:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:28:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 3:12:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:57:42 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:42:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:27:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 2:11:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:56:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:41:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:26:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 1:11:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:56:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:40:53 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:39:32 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	6/29/2017 12:25:47 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:10:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/29/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/28/2017 11:55:19 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:39:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:32:52 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 00862981-5c2c-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/28/2017 11:24:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:09:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:54:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:39:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:23:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:08:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:53:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:38:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:32:15 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on New Volume (D:)
Information	6/28/2017 9:29:49 PM	Microsoft-Windows-Defrag	258	None	The disk defragmenter successfully completed defragmentation on Windows7 (C:)
Information	6/28/2017 9:23:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:07:57 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:52:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:37:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:22:19 PM	MSSQL$SQLEXPRESS	3421	Server	Recovery completed for database mydb (database ID 7) in 1 second(s) (analysis 1157 ms, redo 0 ms, undo 2 ms.) This is an informational message only. No user action is required.
Information	6/28/2017 8:22:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:20:45 PM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/28/2017 8:07:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 7:51:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	6/28/2017 7:47:42 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x10ac
Faulting application start time: 0x01d2f0190d77c608
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: 8c21f348-5c0c-11e7-b61a-80000bd6758f"
Error	6/28/2017 7:45:25 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x2f3c
Faulting application start time: 0x01d2f018dca5cc6a
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: 3a1c54a8-5c0c-11e7-b61a-80000bd6758f"
Error	6/28/2017 7:43:40 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x1cc0
Faulting application start time: 0x01d2f0174315e684
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: fbad43d6-5c0b-11e7-b61a-80000bd6758f"
Information	6/28/2017 7:36:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Error	6/28/2017 7:32:04 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x19b0
Faulting application start time: 0x01d2f01716b9c8d4
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: 5cf04698-5c0a-11e7-b61a-80000bd6758f"
Error	6/28/2017 7:30:49 PM	Application Error	1000	(100)	"Faulting application name: DeviceManagerApi.exe, version: 1.0.0.952, time stamp: 0x5947b104
Faulting module name: GEDevice2.dll, version: 1.6.0.0, time stamp: 0x5947b09c
Exception code: 0xc0000417
Fault offset: 0x000847fe
Faulting process id: 0x1d68
Faulting application start time: 0x01d2f008f78f6ca9
Faulting application path: C:\Program Files (x86)\GE Measurement & Sensing\DeviceManager\DeviceManagerApi.exe
Faulting module path: C:\Program Files (x86)\GE Measurement & Sensing\drivers\GEDevice2.dll
Report Id: 30654f85-5c0a-11e7-b61a-80000bd6758f"
Information	6/28/2017 7:21:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 7:06:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 6:51:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 6:47:34 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 6:47:34 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/28/2017 6:47:27 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T13:15:23.894864400Z.
Information	6/28/2017 6:47:27 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FDEB8D13-8990-40D8-A067-88CCB1168DD7}\4SightV2.msi. Client Process Id: 10104.
Information	6/28/2017 6:45:23 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T13:15:23.894864400Z.
Information	6/28/2017 6:45:22 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FDEB8D13-8990-40D8-A067-88CCB1168DD7}\4SightV2.msi. Client Process Id: 10104.
Information	6/28/2017 6:36:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 6:32:48 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 15621ba8-5c02-11e7-b61a-80000bd6758f
Report Status: 0"
Information	6/28/2017 6:20:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 6:05:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 5:50:55 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceManager. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 5:50:55 PM	MsiInstaller	11707	None	Product: DeviceManager -- Installation operation completed successfully.
Information	6/28/2017 5:50:52 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:20:05.183569300Z.
Information	6/28/2017 5:50:52 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{82697EBA-13E8-4BD4-BF27-10E88995B6D3}\DeviceManager.msi. Client Process Id: 11448.
Information	6/28/2017 5:50:36 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 5:50:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:20:05.183569300Z.
Information	6/28/2017 5:50:04 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{82697EBA-13E8-4BD4-BF27-10E88995B6D3}\DeviceManager.msi. Client Process Id: 11448.
Error	6/28/2017 5:50:04 PM	MsiInstaller	11500	None	Product: DeviceManager -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.
Information	6/28/2017 5:49:54 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:19:05.375505800Z.
Information	6/28/2017 5:49:54 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FA1DD05C-33A6-4FAE-A213-EEED565EE16A}\DeviceDriver.msi. Client Process Id: 9688.
Information	6/28/2017 5:49:54 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: DeviceDriver. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 5:49:54 PM	MsiInstaller	11707	None	Product: DeviceDriver -- Installation operation completed successfully.
Information	6/28/2017 5:49:05 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:19:05.375505800Z.
Information	6/28/2017 5:49:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{FA1DD05C-33A6-4FAE-A213-EEED565EE16A}\DeviceDriver.msi. Client Process Id: 9688.
Information	6/28/2017 5:47:59 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:16:32.275710700Z.
Information	6/28/2017 5:47:59 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/28/2017 5:47:59 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/28/2017 5:47:59 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/28/2017 5:46:32 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:16:32.275710700Z.
Information	6/28/2017 5:46:27 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/28/2017 5:45:00 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.737. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 5:45:00 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/28/2017 5:44:56 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:12:47.291349900Z.
Information	6/28/2017 5:44:56 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{55C37E3B-3826-43B0-9498-94258BD2AAA4}\4SightV2.msi. Client Process Id: 11224.
Information	6/28/2017 5:42:47 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:12:47.291349900Z.
Information	6/28/2017 5:42:46 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{55C37E3B-3826-43B0-9498-94258BD2AAA4}\4SightV2.msi. Client Process Id: 11224.
Information	6/28/2017 5:38:07 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:08:00.177053400Z.
Information	6/28/2017 5:38:07 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 6716.
Information	6/28/2017 5:38:07 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceDriver. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	6/28/2017 5:38:07 PM	MsiInstaller	11724	None	Product: DeviceDriver -- Removal completed successfully.
Information	6/28/2017 5:38:00 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:08:00.177053400Z.
Information	6/28/2017 5:37:58 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {BC685733-C000-4BCC-90A8-395BB5877A54}. Client Process Id: 6716.
Information	6/28/2017 5:37:52 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:07:09.438764300Z.
Information	6/28/2017 5:37:52 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 6716.
Information	6/28/2017 5:37:52 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: DeviceManager. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	6/28/2017 5:37:52 PM	MsiInstaller	11724	None	Product: DeviceManager -- Removal completed successfully.
Information	6/28/2017 5:37:09 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:07:09.438764300Z.
Information	6/28/2017 5:37:05 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {6EBD4556-2F78-4149-A4C8-4F004AE4DE43}. Client Process Id: 6716.
Information	6/28/2017 5:36:47 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T12:05:19.287320100Z.
Information	6/28/2017 5:36:47 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/28/2017 5:36:47 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/28/2017 5:36:47 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/28/2017 5:35:19 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T12:05:19.287320100Z.
Information	6/28/2017 5:35:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 5:35:14 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 6716.
Information	6/28/2017 5:20:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 5:04:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 5:02:43 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 4:57:46 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:46 PM	MsiInstaller	1029	None	Product: Office 16 Click-to-Run Licensing Component. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time.
Information	6/28/2017 4:57:46 PM	MsiInstaller	1038	None	Windows Installer requires a system restart. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Type of System Restart: 2. Reason for Restart: 1.
Information	6/28/2017 4:57:46 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Licensing Component. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:46 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Licensing Component -- Configuration completed successfully.
Error	6/28/2017 4:57:45 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/28/2017 4:57:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24537)(?)])(1 )(2 )]
2: 24fc428e-a37e-4996-ac66-8ea0304a152d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
6: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 7984d9ed-81f9-4d50-913d-317ecd863065, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: b27b3d00-9a95-4fcd-a0c2-118cbd5e699b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: cbecb6f5-da49-4029-be25-5945ac9750b3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:57:43 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=3ad61e22-e4fe-497f-bdb1-3e51bd872173"
Information	6/28/2017 4:57:43 PM	Office Software Protection Platform Service	1033	None	"These policies are being excluded since they are only defined with override-only attribute.
Policy Names=(Security-SPP-Reserved-EnableNotificationMode) 
App Id=0ff1ce15-a989-479d-af46-f275c6370663
Sku Id=149dbce7-a48e-44db-8364-a53386cd4580"
Information	6/28/2017 4:57:43 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 4:57:42 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 4:57:42 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 4:57:41 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 4:57:39 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 10936.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: java , Id 9308.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: chrome , Id 9328.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: OfficeClickToRun , Id 9412.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\vcruntime140.dll is being used by the following process: Name: explorer , Id 4764.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 10936.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: java , Id 9308.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: chrome , Id 9328.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: OfficeClickToRun , Id 9412.
Information	6/28/2017 4:57:39 PM	MsiInstaller	1025	None	Product: Office 16 Click-to-Run Licensing Component. The file c:\Windows\system32\msvcp140.dll is being used by the following process: Name: explorer , Id 4764.
Information	6/28/2017 4:57:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\sppredist64.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:26 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:26 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Localization Component. Product Version: 16.0.7668.2066. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:26 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Localization Component -- Configuration completed successfully.
Information	6/28/2017 4:57:26 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rintloc.en-us.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:25 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:25 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	6/28/2017 4:57:25 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:25 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:25 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component 64-bit Registration. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:25 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component 64-bit Registration -- Configuration completed successfully.
Information	6/28/2017 4:57:23 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/28/2017 4:57:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint64.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:23 PM	ESENT	102	General	Windows (6776) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/28/2017 4:57:22 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:22 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:22 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	6/28/2017 4:57:06 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:02 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	6/28/2017 4:57:02 PM	ESENT	103	General	Windows (10756) Windows: The database engine stopped the instance (0).
Information	6/28/2017 4:57:02 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:57:02 PM	MsiInstaller	1035	None	Windows Installer reconfigured the product. Product Name: Office 16 Click-to-Run Extensibility Component. Product Version: 16.0.7766.2092. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
Information	6/28/2017 4:57:02 PM	MsiInstaller	11728	None	Product: Office 16 Click-to-Run Extensibility Component -- Configuration completed successfully.
Information	6/28/2017 4:56:23 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: c:\program files (x86)\microsoft office\root\integration\c2rint.16.msi. Client Process Id: 11388.
Information	6/28/2017 4:56:23 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Windows\TEMP\mfeBC0F.tmp\MFEagent_x64.msi. Client Process Id: 11804.
Information	6/28/2017 4:56:23 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: McAfee Agent. Product Version: 5.00.5008. Product Language: 1033. Manufacturer: McAfee, Inc.. Installation success or error status: 0.
Information	6/28/2017 4:56:23 PM	MsiInstaller	11707	None	Product: McAfee Agent -- Installation operation completed successfully.
Warning	6/28/2017 4:54:15 PM	Microsoft-Windows-Search	3036	Gatherer	"The content source <file:C:/Program Files (x86)/Microsoft Office/root/Office16/Visio Content/> cannot be accessed.

Context:  Application, SystemIndex Catalog

Details:
	The object was not found.  (HRESULT : 0x80041201) (0x80041201)
"
Information	6/28/2017 4:54:15 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/28/2017 4:54:14 PM	ESENT	102	General	Windows (10756) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/28/2017 4:54:11 PM	Microsoft-Windows-Search	1013	Search service	Windows Search Service stopped normally.

Information	6/28/2017 4:54:11 PM	ESENT	103	General	Windows (8232) Windows: The database engine stopped the instance (0).
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.TaggedNotes' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 3)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.PageEditHistory' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 2)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:09 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'
Omitting: 'Microsoft.OneNote.LinkedNoteUri' ({641064BA-9329-47E6-8F36-5FA81AA461A0} 4)  Publisher: 'Microsoft'  Product: 'OneNote'  URL: 'custom.propdesc'"
Information	6/28/2017 4:54:08 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:54:08 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:54:08 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersKeywords' ({A4790B72-7113-4348-97EA-292BBC1F6770} 5)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:54:08 PM	Microsoft-Windows-propsys	1006	None	"Omitted duplicate property.
Keeping: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'
Omitting: 'Microsoft.Visio.MastersDetails' ({A4790B72-7113-4348-97EA-292BBC1F6770} 6)  Publisher: 'Microsoft'  Product: 'Visio'  URL: 'visiocustom.propdesc'"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeDFC5A8B0-E9FD-43F7-B4CA-D63F1E749711 PPD License
License Id=f7fe38ac-364b-f4bd-7fb9-f893cecfda55"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=89fdcb09-5030-4b80-bc8a-8e98c230e2d0"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=52cb0865-4092-4535-bebc-bbad8d5f6500"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=e7be914e-23b4-4cd4-b058-21a0cff6f94f"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=7da5c758-9205-4543-b52c-cfac434627f1"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE538D623-C066-433D-A6B7-E0708B1FADF7 PPD License
License Id=ad074621-f7d3-65e0-c284-36b96210175c"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=20ce7206-dad6-4f4f-87f8-fcad4a145355"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=758c1bbf-8ebc-4ac7-b053-a326920e8b68"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=cf3ed145-dfd8-4e97-bf91-11e01f057d5e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5b5ea619-1170-4d9e-8fc8-0960888b7431"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB6B47040-B38E-4BE2-BF6A-DABF0C41540A PPD License
License Id=c6c810c9-be79-8903-dbf9-e042a03d8d28"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=6f429561-d63d-42e3-8b66-e2d61597c80e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=bbf7509f-b3a2-4713-a815-71e1d96d7490"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=aa746716-d1e2-44d9-8f47-c07f894832df"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=0d1964ec-3df5-4502-a64a-f36512f035f9"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office26B6A7CE-B174-40AA-A114-316AA56BA9FC PPD License
License Id=776cd868-053a-1561-adf6-407c43ec688a"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=613452e6-1730-4764-8ef6-b2115d970264"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ebfd22a7-76e0-46d1-9a2c-658aa3fe5a96"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=47745e77-0f59-438c-88cc-f1f4c2935f65"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=987e2dfd-9019-49b1-8f46-48e3b6af2b74"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office46D2C0BD-F912-4DDC-8E67-B90EADC3F83C PPD License
License Id=903f0d79-fb37-4706-3779-1fb9e17a8fde"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=81ce275d-af14-4c87-9270-86028e12069f"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2571a19e-089a-4969-b5e8-ddffbf9fa049"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=d31537c8-d813-4cfd-96ee-044661f5e16e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=871ba58b-a95c-4e66-8f30-b7af01d7767d"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeFF02E86C-FEF0-4063-B39F-74275CDDD7C3 PPD License
License Id=3c061f75-c879-76de-a8fd-328709dd9522"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=5d37def8-1e50-4fe6-97dc-373e1b68f743"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=80f4fb6c-b614-430b-8949-b76a82b9feb1"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6a75e296-2f1d-4a3c-acb8-b96a377f6e54"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=5ea9fc4d-7f3f-404c-9ee7-269a78dd29cd"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office6E5DB8A5-78E6-4953-B793-7422351AFE88 PPD License
License Id=51998d31-5bbb-2da1-28d0-143d3622a51e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=37339799-7bda-47f7-9b01-0160d6ec30ee"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7be03f78-fec3-481c-9b83-0cb67664675e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=835b0016-93af-42ef-bb26-5fc1960509f8"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=9b3eca54-55d1-4c70-b00b-04d742afa893"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeA8119E32-B17C-4BD3-8950-7D1853F4B412 PPD License
License Id=5030ae0a-fae7-c88e-0803-7856aea4cc5f"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=545f91f2-7de4-40d3-b8a8-516609dba545"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f8ef987c-d49b-4575-b3d2-ad3ba94441fb"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=6ced6197-e10b-4252-9e5d-c71b30302235"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=ac8ed6d5-96bb-47ac-8f6c-13d269009f86"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeE3DACC06-3BC2-4E13-8E59-8E05F3232325 PPD License
License Id=5bdbd507-73c3-5f87-d372-f0e5bb6a31cd"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=f2ed2aa1-f04a-495f-af23-bac9060aaee1"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=a14fd7bb-507b-4e24-9fd2-0a69eca78cb4"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=65f86812-c661-47b1-9c4f-31850f714943"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=02857536-cf15-4c0d-b44a-a1b64c46d07d"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office149DBCE7-A48E-44DB-8364-A53386CD4580 PPD License
License Id=9dc6cf18-3bdc-6b55-055c-77d5e1c67e08"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=60f9f3e8-c1be-4b13-aead-7005b2c806b6"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=0db9cf5f-dfa7-4d40-b430-1da4b8e2259a"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=8e25612b-ee1d-4f26-8799-740f69243a17"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=87b19075-f273-4502-9167-158800827d43"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office3AD61E22-E4FE-497F-BDB1-3E51BD872173 PPD License
License Id=32757964-6b92-d375-42e1-fbbd7da16454"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=85815fb6-f287-4ff9-9155-d13103ce14f1"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=2379f603-aa01-44d3-92c2-d8aa002523c1"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeB27B3D00-9A95-4FCD-A0C2-118CBD5E699B PPD License
License Id=d25bdc86-1b23-f231-8b98-db36cc3b4b7b"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=bbb7ec1c-d627-4371-a4a7-b311eda6dbcc"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=57d699dc-639e-495f-8c22-d4af696034ed"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=bc1b8bd5-96cf-4c77-9c52-08590fa81818"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=be089e7b-571b-4330-9a09-63cb6d7c8d59"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=OfficeCBECB6F5-DA49-4029-BE25-5945AC9750B3 PPD License
License Id=62eec107-c849-49d8-d78e-10daa0a5c173"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=ce62428d-1958-4a99-9d9d-83d4260f990e"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=ab7bd8f5-8934-47d2-9ee9-7c09aeeaabf4"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=22be7fa2-ca89-4e32-b4c3-41ede6a99d71"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=13351a6e-df68-443d-8edd-d9f4cae1ff67"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office24FC428E-A37E-4996-AC66-8EA0304A152D PPD License
License Id=5fb7168b-b17b-81fc-a5cd-efac97cde83c"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=303d5c42-d5db-413c-a214-043c26110ff2"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=32814545-fe45-4806-bfab-db23cb8ed04f"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=fcd5ee65-6dc1-4ede-9830-c75ffa9e4733"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=fe73e4ab-0060-4888-9b1b-83cc923cd076"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office7984D9ED-81F9-4D50-913D-317ECD863065 PPD License
License Id=2a9a2991-4b78-245f-e862-11366e07a43f"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=0bbbd973-6d0f-448f-aa0e-91c43fa94eb7"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=f0a52c37-71c8-4b1c-b178-43b4ef6b145a"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=ee2c65f4-85f2-4006-8e11-7dc63f23b498"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=c9ce7541-001c-4779-b883-f5169b882b41"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office35EC6E0E-2DF4-4629-9EE3-D525E806B988 PPD License
License Id=5acfc3a7-97b1-0683-9c66-fa18579ff15c"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Private)
License Id=d153ef14-af6e-474c-84d5-2303e980041a"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 UL oob License (Public)
License Id=7d86124e-eb3b-46a0-b815-3b697f47fd7c"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Private)
License Id=91370939-d8a9-49f2-a80e-836f8d3676bc"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=Office 16 Publishing License (Public)
License Id=2665797f-c833-48db-a0ea-9b88351cbc44"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-bridge-office Issuance License
License Id=4d4a5396-01a7-4ae5-9973-b53bb1af5c30"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root-bridge-test Issuance License
License Id=7256a55f-e989-4e06-b2c2-c527f49e4527"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul-oob Issuance License
License Id=7209e8e3-cce2-49dd-8f6e-2cc8a611f202"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-ul Issuance License
License Id=ce939c0e-53f7-4011-a286-78b6975fa5f0"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-stil Issuance License
License Id=285583cd-fc43-4806-ace6-d247b7edd434"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=client-issuance-root Issuance License
License Id=7cbeb41c-1778-47f2-aa36-51a5a618f716"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=dc6454b3-ceba-4e40-b6cc-26afb8fe8fa6"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1004	None	"The Software Protection service has successfully installed the license.
License Title=XrML 2.1 License - Product Key Configuration
License Id=6040a6e7-445d-4609-b6c4-8a66b709cb54"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 4:53:48 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 4:53:47 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 4:53:15 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T11:23:15.365432600Z.
Information	6/28/2017 4:50:50 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Windows\TEMP\mfeBC0F.tmp\MFEagent_x64.msi. Client Process Id: 11804.
Information	6/28/2017 4:49:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 4:48:18 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24552)(?)])(1 )(2 )]

"
Information	6/28/2017 4:43:14 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24552)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:41:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:41:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]

"
Information	6/28/2017 4:41:56 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:41:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:41:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]

"
Information	6/28/2017 4:41:35 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24553)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:37:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:37:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24558)(?)])(1 )(2 )]

"
Information	6/28/2017 4:37:13 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24558)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:37:13 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 4:37:13 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 4:37:12 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 4:34:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 4:33:47 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 4:28:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:28:43 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24566)(?)])(1 )(2 )]

"
Information	6/28/2017 4:28:42 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24566)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24567)(?)])(1 )(2 )]

"
Information	6/28/2017 4:27:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24567)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24568)(?)])(1 )(2 )]

"
Information	6/28/2017 4:26:41 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24568)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:25:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:25:18 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24570)(?)])(1 )(2 )]

"
Information	6/28/2017 4:25:17 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24570)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:23:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:23:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24571)(?)])(1 )(2 )]

"
Information	6/28/2017 4:23:48 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24571)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:23:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:23:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24572)(?)])(1 )(2 )]

"
Information	6/28/2017 4:23:10 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24572)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:31 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:30 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24573)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 4:21:30 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 4:21:30 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 4:21:29 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 4:18:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 4:14:04 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 4:14:04 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/28/2017 4:14:00 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T10:36:02.177677200Z.
Information	6/28/2017 4:14:00 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1A1BDF39-B1C4-4E4D-809D-FDB50D6B0AA3}\4SightV2.msi. Client Process Id: 9944.
Information	6/28/2017 4:06:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T10:36:02.177677200Z.
Information	6/28/2017 4:05:15 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{1A1BDF39-B1C4-4E4D-809D-FDB50D6B0AA3}\4SightV2.msi. Client Process Id: 9944.
Information	6/28/2017 4:00:04 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 4:00:04 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:51:01Z. Reason: GVLK.
Information	6/28/2017 3:54:14 PM	SecurityCenter	1	None	The Windows Security Center Service has started.
Information	6/28/2017 3:53:23 PM	Bluetooth Media Service	0	None	"The description for Event ID 0 from source Bluetooth Media Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/28/2017 3:53:22 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/28/2017 3:53:21 PM	Bluetooth Device Monitor	0	None	"The description for Event ID 0 from source Bluetooth Device Monitor cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/28/2017 3:53:17 PM	Microsoft-Windows-Search	1003	Search service	The Windows Search Service started.

Information	6/28/2017 3:52:54 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2017 3:52:54 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 258960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 3:52:51 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 3:52:43 PM	ESENT	302	Logging/Recovery	Windows (8232) Windows: The database engine has successfully completed recovery steps.
Information	6/28/2017 3:52:41 PM	ESENT	301	Logging/Recovery	Windows (8232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
Information	6/28/2017 3:52:27 PM	ESENT	301	Logging/Recovery	Windows (8232) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS03ABB.log.
Information	6/28/2017 3:52:27 PM	ESENT	300	Logging/Recovery	Windows (8232) Windows: The database engine is initiating recovery steps.
Information	6/28/2017 3:52:26 PM	ESENT	102	General	Windows (8232) Windows: The database engine (6.01.7601.0000) started a new instance (0).
Information	6/28/2017 3:52:26 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 3:52:08 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8573.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	6/28/2017 3:50:58 PM	Service1	0	None	Service started successfully.
Error	6/28/2017 3:50:52 PM	Microsoft-Windows-WMI	10	None	"Event filter with query ""SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA ""Win32_Processor"" AND TargetInstance.LoadPercentage > 99"" could not be reactivated in namespace ""//./root/CIMV2"" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected."
Information	6/28/2017 3:50:51 PM	Microsoft-Windows-WMI	5617	None	Windows Management Instrumentation Service subsystems initialized successfully
Information	6/28/2017 3:50:23 PM	PostgreSQL	0	None	Server started and accepting connections

Information	6/28/2017 3:50:21 PM	Microsoft-Windows-WMI	5615	None	Windows Management Instrumentation Service started sucessfully
Information	6/28/2017 3:50:20 PM	PostgreSQL	0	None	"2017-06-28 15:50:20 IST LOG:  redirecting log output to logging collector process
2017-06-28 15:50:20 IST HINT:  Future log output will appear in directory ""pg_log"".
"
Information	6/28/2017 3:50:19 PM	PostgreSQL	0	None	Waiting for server startup...

Information	6/28/2017 3:50:17 PM	MSSQL$SQLEXPRESS	6253	Server	Common language runtime (CLR) functionality initialized using CLR version v4.0.30319 from C:\Windows\Microsoft.NET\Framework64\v4.0.30319\.
Information	6/28/2017 3:50:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 1

"
Information	6/28/2017 3:50:12 PM	Microsoft-Windows-Winlogon	6000	None	The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
Information	6/28/2017 3:50:12 PM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/28/2017 3:50:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 1

"
Information	6/28/2017 3:50:12 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/28/2017 3:50:11 PM	MSSQL$SQLEXPRESS	26067	Server	The SQL Server Network Interface library could not register the Service Principal Name (SPN) [ MSSQLSvc/GGPBK882E.logon.ds.ge.com:SQLEXPRESS ] for the SQL Server service. Windows return code: 0x200b, state: 15. Failure to register a SPN might cause integrated authentication to use NTLM instead of Kerberos. This is an informational message. Further action is only required if Kerberos authentication is required by authentication policies and if the SPN has not been manually registered.
Information	6/28/2017 3:50:07 PM	MSSQL$SQLEXPRESS	3408	Server	Recovery is complete. This is an informational message only. No user action is required.
Information	6/28/2017 3:50:07 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:07 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database '4sight' (12:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	9688	Server	Service Broker manager has started.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	9666	Server	The Database Mirroring endpoint is in disabled or stopped state.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	9666	Server	The Service Broker endpoint is in disabled or stopped state.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'tempdb'.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	17136	Server	Clearing tempdb database.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'model'.
Information	6/28/2017 3:50:05 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database '4sight'.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'EntityFSDB' (10:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'SignalDB' (6:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'JPAdemo' (11:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'TrainingDB' (5:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'msdb' (4:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'POCfilestream' (9:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	26076	Server	SQL Server is attempting to register a Service Principal Name (SPN) for the SQL Server service. Kerberos authentication will not be possible until a SPN is registered for the SQL Server service. This is an informational message. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	17126	Server	SQL Server is now ready for client connections. This is an informational message; no user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	17199	Server	Dedicated administrator connection support was not started because it is disabled on this edition of SQL Server. If you want to use a dedicated administrator connection, restart SQL Server using the trace flag 7806. This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\MSSQL$SQLEXPRESS\sql\query ].
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	26048	Server	Server local connection provider is ready to accept connection on [ \\.\pipe\SQLLocal\SQLEXPRESS ].
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	26018	Server	A self-generated certificate was successfully loaded for encryption.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	3406	Server	1 transactions rolled forward in database 'LoginDB' (8:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:04 PM	MSSQL$SQLEXPRESS	958	Server	The resource database build version is 12.00.2000. This is an informational message only. No user action is required.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'EntityFSDB'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'JPAdemo'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mssqlsystemresource'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'LoginDB'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'POCfilestream'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'TrainingDB'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'msdb'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'SignalDB'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	17663	Server	Server name is 'GGPBK882E\SQLEXPRESS'. This is an informational message only. No user action is required.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	19030	Server	"SQL Trace ID 1 was started by login ""sa""."
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	5544	Server	FILESTREAM: effective level = 2 (remote access enabled), configured level = 2, file system access share name = 'SQLEXPRESS'.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	33218	Server	SQL Server Audit has started the audits. This is an informational message. No user action is required.
Information	6/28/2017 3:50:03 PM	MSSQL$SQLEXPRESS	33217	Server	SQL Server Audit is starting the audits. This is an informational message. No user action is required.
Information	6/28/2017 3:50:02 PM	MSSQL$SQLEXPRESS	3454	Server	Recovery is writing a checkpoint in database 'master' (1). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:02 PM	MSSQL$SQLEXPRESS	3407	Server	0 transactions rolled back in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:02 PM	MSSQL$SQLEXPRESS	3406	Server	119 transactions rolled forward in database 'master' (1:0). This is an informational message only. No user action is required.
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'master'.
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	49910	Server	Software Usage Metrics is disabled.
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17811	Server	The maximum number of dedicated administrator connections for this instance is '1'
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17125	Server	Using dynamic lock allocation.  Initial allocation of 2500 Lock blocks and 5000 Lock Owner blocks per node.  This is an informational message only.  No user action is required.
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17152	Server	Node configuration: node 0: CPU mask: 0x00000000000000ff:0 Active CPU mask: 0x00000000000000ff:0. This message provides a description of the NUMA configuration for this computer. This is an informational message only. No user action is required.
Information	6/28/2017 3:50:01 PM	MSSQL$SQLEXPRESS	17176	Server	This instance of SQL Server last reported using a process ID of 3920 at 6/28/2017 3:42:32 PM (local) 6/28/2017 10:12:32 AM (UTC). This is an informational message only; no user action is required.
Information	6/28/2017 3:49:59 PM	MSSQL$SQLEXPRESS	49917	Server	Default collation: SQL_Latin1_General_CP1_CI_AS (us_english 1033)
Information	6/28/2017 3:49:59 PM	MSSQL$SQLEXPRESS	852	Server	Using conventional memory in the memory manager.
Information	6/28/2017 3:49:59 PM	MSSQL$SQLEXPRESS	49903	Server	Detected 16289 MB of RAM. This is an informational message; no user action is required.
Information	6/28/2017 3:49:59 PM	MSSQL$SQLEXPRESS	17162	Server	SQL Server is starting at normal priority base (=7). This is an informational message only. No user action is required.
Information	6/28/2017 3:49:59 PM	MSSQL$SQLEXPRESS	17164	Server	SQL Server detected 1 sockets with 4 cores per socket and 8 logical processors per socket, 8 total logical processors; using 8 logical processors based on SQL Server licensing. This is an informational message; no user action is required.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17115	Server	"Command Line Startup Parameters:
	 -s ""SQLEXPRESS"""
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17110	Server	"Registry startup parameters: 
	 -d C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\master.mdf
	 -e C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG
	 -l C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\DATA\mastlog.ldf"
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	49904	Server	The service account is 'NT Service\MSSQL$SQLEXPRESS'. This is an informational message; no user action is required.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17111	Server	Logging SQL Server messages in file 'C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Log\ERRORLOG'.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	15268	Server	Authentication mode is MIXED.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	18496	Server	System Manufacturer: 'Dell Inc.', System Model: 'Latitude E6540'.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17104	Server	Server process ID is 3544.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17103	Server	All rights reserved.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17101	Server	(c) Microsoft Corporation.
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	49916	Server	UTC adjustment: 5:30
Information	6/28/2017 3:49:58 PM	MSSQL$SQLEXPRESS	17069	Server	"Microsoft SQL Server 2014 - 12.0.2269.0 (X64) 
	Jun 10 2015 03:35:45 
	Copyright (c) Microsoft Corporation
	Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
"
Information	6/28/2017 3:49:41 PM	AdobeARMservice	0	None	"The description for Event ID 0 from source AdobeARMservice cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started
"
Information	6/28/2017 3:49:27 PM	Microsoft-Windows-User Profiles Service	1531	None	"The User Profile Service has started successfully.  

"
Information	6/28/2017 3:49:28 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service started/resumed
"
Information	6/28/2017 3:49:27 PM	Microsoft-Windows-EventSystem	4625	None	The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
Information	6/28/2017 3:42:41 PM	Bluetooth OBEX Service	0	None	"The description for Event ID 0 from source Bluetooth OBEX Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Service stopped
"
Information	6/28/2017 3:42:32 PM	MSSQL$SQLEXPRESS	17147	Server	SQL Server is terminating because of a system shutdown. This is an informational message only. No user action is required.
Warning	6/28/2017 3:42:20 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459_Classes:
Process 14052 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459_CLASSES
"
Warning	6/28/2017 3:42:17 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 29 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 14052 (\Device\HarddiskVolume1\Program Files\DGAgent\DgPrompt.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 12164 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	6/28/2017 3:42:14 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 2

"
Information	6/28/2017 3:42:10 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	6/28/2017 3:42:09 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	6/28/2017 3:41:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 3:40:38 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T10:04:39.257588900Z.
Information	6/28/2017 3:40:38 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/28/2017 3:40:38 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/28/2017 3:40:38 PM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/28/2017 3:39:26 PM	McLogEvent	257	None	The scan of C:\Config.Msi\2fabd8ea.rbf has taken too long to complete and is being canceled.  Scan engine version used is 5900.7806 DAT version 8573.0000.
Warning	6/28/2017 3:37:15 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 3:37:15 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 3:34:39 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T10:04:39.257588900Z.
Information	6/28/2017 3:27:44 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/28/2017 3:25:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/28/2017 3:20:02 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 3:20:02 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	6/28/2017 3:15:22 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 3:15:22 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	6/28/2017 3:12:18 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 3:12:18 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 3:10:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 3:05:31 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Warning	6/28/2017 3:03:48 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 3:03:48 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 3:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 3:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24655)(?)])(1 )(2 )]

"
Information	6/28/2017 3:00:25 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24655)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 2:58:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 2:58:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 2:58:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24656)(?)])(1 )(2 )]

"
Information	6/28/2017 2:58:55 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24656)(?)])(1 )(2 )]

"
Information	6/28/2017 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24656)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 2:58:54 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24656)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 2:58:54 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 2:58:54 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 2:58:52 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 2:55:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 2:40:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 2:25:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 2:10:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/28/2017 2:06:34 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 2:06:34 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 1:54:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 1:39:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 1:32:46 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 2b721658-5bd8-11e7-a409-80000bd6758f
Report Status: 0"
Warning	6/28/2017 1:29:44 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 1:29:44 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 1:24:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/28/2017 1:12:59 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 1:12:59 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	6/28/2017 1:11:31 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 1:11:31 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 1:09:18 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/28/2017 1:09:07 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 1:09:07 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 1:07:50 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/28/2017 1:07:42 PM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Warning	6/28/2017 1:07:36 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/28/2017 1:07:36 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/28/2017 12:54:08 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 12:38:58 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 12:23:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 12:21:33 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2017 12:21:31 PM	Outlook	63	None	Outlook detected a change notification for your apps and will attempt to update them.
Information	6/28/2017 12:21:01 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/28/2017 12:08:37 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:53:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:38:16 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:26:26 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 11:26:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-07-05T05:50:26Z. Reason: GVLK.
Information	6/28/2017 11:23:06 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 11:21:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 11:21:25 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 259200)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 11:21:25 AM	Microsoft-Windows-Security-SPP	12289	None	"The client has processed an activation response from the key management service machine.
Info:
0x00000000, 0x00000000, 1, 0, 50, 120, 10080, 2017/06/28 05:51"
Information	6/28/2017 11:21:24 AM	Microsoft-Windows-Security-SPP	12288	None	"The client has sent an activation request to the key management service machine.
Info:
0x00000000, 0x00000000, kms.windows7.ge.com:1688, e37f4acc-ac2f-4e8b-8ecd-763bcd6ec3e2, 2017/06/28 05:51, 0, 1, 249120, b92e9980-b9d5-4821-9c94-140f632f6312, 25"
Information	6/28/2017 11:16:22 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2017 11:16:22 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249180)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 11:16:22 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 11:16:21 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 11:07:55 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:52:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:37:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:22:29 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 10:14:26 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24946)(?)])(1 )(2 )]

"
Information	6/28/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 24946)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 10:09:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 10:09:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 10:09:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 10:07:18 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:52:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:36:35 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:21:24 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Installation complete
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Installation complete with an exit code of: 
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Passed the Operating System Check.  Version: 6.1.7601 OS Name: Windows 7 64-Bit
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++ Windows OS Product Type is: WinNT
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++No Install Check was performed.
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Passed the Permissions Check
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Started the installation of GE Office 73692139 Fix 1.0 V01 with the following commandline: /Q /IC
Information	6/28/2017 9:14:08 AM	GE Software	0	(1)	++Installation Check - The following User is currently logged into the system: 212558710. The installation is currently running in the following context: SYSTEM.
Information	6/28/2017 9:14:07 AM	GE Software	0	(1)	++ Session ID: 2. Session ID Return Code: 203.
Information	6/28/2017 9:06:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 9:04:52 AM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.734. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/28/2017 9:04:52 AM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/28/2017 9:03:33 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T03:28:08.475198900Z.
Information	6/28/2017 9:03:33 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{5D625CC5-773A-4A81-B464-72B77A364552}\4SightV2.msi. Client Process Id: 4204.
Information	6/28/2017 8:58:08 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T03:28:08.475198900Z.
Information	6/28/2017 8:58:00 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{5D625CC5-773A-4A81-B464-72B77A364552}\4SightV2.msi. Client Process Id: 4204.
Information	6/28/2017 8:55:29 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8573.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Error	6/28/2017 8:55:05 AM	McLogEvent	5051	None	"A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request.
 The process will be terminated. Thread id : 6732 (0x1a4c)
 Thread address : 0x0000000076F6CE9A
 Thread message : 

 Build VSCORE.15.4.0.657 / 5900.7806
 Object being scanned = \Device\HarddiskVolume2\installs\SetUpFile_2017_06_28_We_ 0_55_42_734\DISK1\ISSetupPrerequisites\{7E4BD306-FC5C-4706-91E0-21DEB7567637}\postgresql-9.5.3-1-windows.exe
 by C:\Windows\explorer.exe
 4(0)(0)
 4(0)(0)
 7200(0)(0)
 7595(0)(0)
 7005(0)(0)
 7004(0)(0)
 5006(0)(0)
 5004(0)(0)
"
Information	6/28/2017 8:53:31 AM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8573.0000
 
 Number of signatures in EXTRA.DAT : 1
 Names of threats that EXTRA.DAT can detect : Ransomware-GCC (ED)
"
Information	6/28/2017 8:50:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:45:51 AM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎28T03:13:14.644485500Z.
Information	6/28/2017 8:45:51 AM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/28/2017 8:45:51 AM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2. Product Version: 1.0.0.727. Product Language: 1033. Manufacturer: Druck Limited. Removal success or error status: 0.
Information	6/28/2017 8:45:51 AM	MsiInstaller	11724	None	Product: 4SightV2 -- Removal completed successfully.
Information	6/28/2017 8:43:14 AM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎28T03:13:14.644485500Z.
Information	6/28/2017 8:39:45 AM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/28/2017 8:35:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:35:27 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 8:35:26 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-06-28T05:46:21Z. Reason: GVLK.
Information	6/28/2017 8:32:33 AM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 8024400e
P3: 00000000-0000-0000-0000-000000000000
P4: Scan
P5: 0
P6: 1
P7: 0
P8: AutomaticUpdates
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 3a6de142-5bae-11e7-a409-80000bd6758f
Report Status: 0"
Information	6/28/2017 8:29:37 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/28/2017 8:29:37 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 249300)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 8:29:37 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 8:29:33 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/28/2017 8:26:05 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/28/2017 8:25:51 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4111	None	Successful auto update of third-party root list with effective date: Wednesday, June 14, 2017 12:32:04 AM.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Certum Trusted Network CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL> Sha1 thumbprint: <07E032E020B72C3F192F0628A2593A19A70F069E>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=QuoVadis Root CA 3, O=QuoVadis Limited, C=BM> Sha1 thumbprint: <1F4914F7D874951DDDAE02C0BEFD3A2D82755185>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GlobalSign, O=GlobalSign, OU=GlobalSign ECC Root CA - R4> Sha1 thumbprint: <6969562E4080F424A1E7199F14BAF3EE58AB6ABB>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=GlobalSign, O=GlobalSign, OU=GlobalSign Root CA - R2> Sha1 thumbprint: <75E0ABB6138512271C04F85FDDDE38E4B7242EFE>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Signet Root CA, OU=Signet Certification Authority, O=Telekomunikacja Polska S.A., C=PL> Sha1 thumbprint: <B2BD9031AA6D0E14F4C57FD548258F37B1FB39E4>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=Common Policy, OU=FBCA, O=U.S. Government, C=us> Sha1 thumbprint: <CB44A097857C45FA187ED952086CB9841F2D51B5>.
Information	6/28/2017 8:25:09 AM	Microsoft-Windows-CAPI2	4109	None	Successful auto property update of third-party root certificate:: Subject: <CN=QuoVadis Root Certification Authority, OU=Root Certification Authority, O=QuoVadis Limited, C=BM> Sha1 thumbprint: <DE3F40BD5093D39B6C60F6DABC076201008976C9>.
Error	6/28/2017 8:21:08 AM	Application Error	1000	(100)	"Faulting application name: NetworkAdapterManager.exe, version: 1.0.0.0, time stamp: 0x55a02192
Faulting module name: KERNELBASE.dll, version: 6.1.7601.23807, time stamp: 0x5915fe14
Exception code: 0xe0434352
Fault offset: 0x000000000001a06d
Faulting process id: 0xf64
Faulting application start time: 0x01d2e8b0068b1a9d
Faulting application path: C:\Windows\Options\Packages\Wireless Suppress Util\NetworkAdapterManager.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: a219f6e7-5bac-11e7-a409-80000bd6758f"
Error	6/28/2017 8:21:06 AM	Office 2016 Licensing Service	0	None	"The description for Event ID 0 from source Office 2016 Licensing Service cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Subscription licensing service failed: -2143485936
"
Error	6/28/2017 8:21:06 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {AC69CB08-57EB-4869-A43B-12875519CD49}
Error	6/28/2017 8:21:06 AM	Microsoft Office 16	2011	None	Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {AC69CB08-57EB-4869-A43B-12875519CD49}
Information	6/28/2017 8:21:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/28/2017 8:21:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25054)(?)])(1 )(2 )]

"
Information	6/28/2017 8:21:05 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 25054)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/28/2017 8:21:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/28/2017 8:21:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/28/2017 8:21:00 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Error	6/28/2017 8:20:51 AM	.NET Runtime	1026	None	Application: NetworkAdapterManager.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Management.ManagementException
   at System.Management.ManagementException.ThrowWithExtendedInfo(System.Management.ManagementStatus)
   at System.Management.ManagementObject.InvokeMethod(System.String, System.Management.ManagementBaseObject, System.Management.InvokeMethodOptions)
   at System.Management.ManagementObject.InvokeMethod(System.String, System.Object[])
   at NetworkAdapterManager.NetworkAdapterManager.EnableWireless()
   at NetworkAdapterManager.NetworkAdapterManager.CheckNics()
   at NetworkAdapterManager.NetworkAdapterManager.AddressChangedCallback(System.Object, System.EventArgs)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Net.NetworkInformation.NetworkChange+AddressChangeListener.AddressChangedCallback(System.Object, Boolean)
   at System.Threading._ThreadPoolWaitOrTimerCallback.PerformWaitOrTimerCallback(System.Object, Boolean)


Information	6/28/2017 8:20:40 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/28/2017 8:20:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/28/2017 8:20:38 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 2147954407

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/23/2017 9:33:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 9:18:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 9:02:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:47:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:33:08 PM	MsiInstaller	1033	None	Windows Installer installed the product. Product Name: 4SightV2. Product Version: 1.0.0.727. Product Language: 1033. Manufacturer: Druck Limited. Installation success or error status: 0.
Information	6/23/2017 8:33:08 PM	MsiInstaller	11707	None	Product: 4SightV2 -- Installation operation completed successfully.
Information	6/23/2017 8:33:01 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎23T15:00:02.438064100Z.
Information	6/23/2017 8:33:01 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3D3617AC-E456-408A-8E86-04CEEEB8D8F6}\4SightV2.msi. Client Process Id: 12884.
Information	6/23/2017 8:32:38 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:30:02 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎23T15:00:02.438064100Z.
Information	6/23/2017 8:30:01 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: C:\Users\212558~1\AppData\Local\Temp\{3D3617AC-E456-408A-8E86-04CEEEB8D8F6}\4SightV2.msi. Client Process Id: 12884.
Information	6/23/2017 8:17:27 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:16:55 PM	Microsoft-Windows-RestartManager	10001	None	Ending session 0 started ‎2017‎-‎06‎-‎23T14:45:07.155854200Z.
Information	6/23/2017 8:16:55 PM	MsiInstaller	1042	None	Ending a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/23/2017 8:16:55 PM	MsiInstaller	1034	None	Windows Installer removed the product. Product Name: 4SightV2.0. Product Version: 1.0.0.724. Product Language: 1033. Manufacturer: GE. Removal success or error status: 0.
Information	6/23/2017 8:16:55 PM	MsiInstaller	11724	None	Product: 4SightV2.0 -- Removal completed successfully.
Information	6/23/2017 8:15:07 PM	Microsoft-Windows-RestartManager	10000	None	Starting session 0 - ‎2017‎-‎06‎-‎23T14:45:07.155854200Z.
Information	6/23/2017 8:14:54 PM	MsiInstaller	1040	None	Beginning a Windows Installer transaction: {402B69E2-AB04-4FD3-9E09-8E6E7E58C999}. Client Process Id: 12840.
Information	6/23/2017 8:02:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:47:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:31:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:16:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:06:39 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/23/2017 7:01:34 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:46:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:31:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:25:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 35978980-5813-11e7-a409-80000bd6758f
Report Status: 0"
Information	6/23/2017 6:15:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:00:50 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:45:28 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:39:45 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/23/2017 5:39:45 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-06-28T05:46:45Z. Reason: GVLK.
Information	6/23/2017 5:34:45 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/23/2017 5:34:45 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 255960)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/23/2017 5:34:45 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/23/2017 5:34:45 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/23/2017 5:30:17 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:15:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:59:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:44:40 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:29:23 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:14:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:59:02 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:43:52 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:28:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:13:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:06:35 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/23/2017 2:58:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:43:10 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:27:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:12:48 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:57:43 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:42:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:27:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:25:19 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: 4c7bbce3-57e9-11e7-a409-80000bd6758f
Report Status: 0"
Information	6/23/2017 1:12:12 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 1:02:50 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 1:02:50 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Error	6/23/2017 1:00:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Error	6/23/2017 1:00:08 PM	SideBySide	35	None	"Activation context generation failed for ""C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest"".Error in manifest or policy file ""C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL"" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture=""AMD64"",type=""win32"",version=""16.0.0.0"". Definition is UccApi,processorArchitecture=""x86"",type=""win32"",version=""16.0.0.0"". Please use sxstrace.exe for detailed diagnosis."
Information	6/23/2017 12:57:00 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 12:46:13 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 12:41:54 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:29:16 PM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/23/2017 12:29:16 PM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-06-28T05:47:16Z. Reason: GVLK.
Information	6/23/2017 12:26:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:24:15 PM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/23/2017 12:24:15 PM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256260)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/23/2017 12:24:14 PM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/23/2017 12:24:13 PM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/23/2017 12:19:26 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/23/2017 12:18:55 PM	McLogEvent	5000	None	"McShield service started.
 Engine version : 5900.7806
 DAT version : 8568.0000
 
 Number of signatures in EXTRA.DAT : None
 Names of threats that EXTRA.DAT can detect : None"
Information	6/23/2017 12:11:29 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 11:56:17 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 11:41:35 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 11:41:35 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/23/2017 11:41:07 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 11:39:34 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 11:39:34 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Warning	6/23/2017 11:39:17 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 11:39:17 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/23/2017 11:25:56 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 11:22:49 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 11:22:49 AM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/23/2017 11:11:14 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/23/2017 11:10:45 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/23/2017 11:06:29 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\Documents\Outlook Files\archive.pst (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	6/23/2017 11:06:29 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	6/23/2017 11:06:28 AM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/23/2017 11:06:17 AM	Outlook	63	None	The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005
Information	6/23/2017 11:06:16 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst has detected a catalog checkpoint.
Information	6/23/2017 11:06:14 AM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/23/2017 11:06:13 AM	Outlook	32	None	The store C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost has detected a catalog checkpoint.
Information	6/23/2017 11:06:13 AM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 94

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 93

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 78

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 78

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 0

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 31

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 141

Information	6/23/2017 11:06:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/23/2017 11:06:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32089)(?)])(1 )(2 )]

"
Information	6/23/2017 11:06:06 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32089)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/23/2017 11:06:05 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/23/2017 11:06:05 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/23/2017 11:06:05 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/23/2017 10:55:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 10:40:27 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 10:25:21 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 10:14:23 AM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/23/2017 10:10:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/23/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32146)(?)])(1 )(2 )]

"
Information	6/23/2017 10:09:23 AM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32146)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/23/2017 10:09:23 AM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/23/2017 10:09:23 AM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/23/2017 10:09:22 AM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/23/2017 10:00:07 AM	Microsoft-Windows-Security-SPP	903	None	"The Software Protection service has stopped.
"
Information	6/23/2017 10:00:07 AM	Microsoft-Windows-Security-SPP	16384	None	Successfully scheduled Software Protection service for re-start at 2017-06-28T05:47:06Z. Reason: GVLK.
Information	6/23/2017 9:57:14 AM	SceCli	1704	None	Security policy in the Group policy objects has been applied successfully.
Information	6/23/2017 9:55:06 AM	Microsoft-Windows-Security-SPP	902	None	"The Software Protection service has started.
6.1.7601.17514"
Information	6/23/2017 9:55:06 AM	Microsoft-Windows-Security-SPP	1003	None	"The Software Protection service has completed licensing status check.
Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
Licensing Status=
1: 4de78642-0f7f-4b61-9392-8add86d70ae8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 50e329f7-a5fa-46b2-85fd-f224e5da7764, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 5a79ecd8-d33f-406c-a619-7785899b5d59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 770bc271-8dc1-467d-b574-73cbacbeccd1, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 90a61a0d-0b76-4bf1-a8b8-89061855a4c9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 92f9d22a-65f5-49a7-90fe-06491b4fc379, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: 9ccffaf9-86a2-414e-b031-b2f777720e90, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: b92e9980-b9d5-4821-9c94-140f632f6312, 1, 1 [(0 [0x00000000, 1, 0], [( 2 0xC004F005)(?)( 1 0x00000000 30 0 msft:rm/algorithm/volume/1.0 0x00000000 256440)(?)(?)(?)])(1 )(2 )]
10: c1027486-8ae8-4633-9cf9-9658ed80504d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: c1e88de3-96c4-4563-ad7d-775f65b1e670, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: c33001fc-5e9c-4f27-8c05-e0154adb0db4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
13: cf3c5b35-35ff-4c95-9bbd-a188e47ad14c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
14: cff07cac-7534-4cc3-b3f3-99e1a0aa3c20, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
15: d188820a-cb63-4bad-a9a2-40b843ee23b7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
16: d8e04254-f9a5-4729-ae86-886de6aa907c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
17: da22eadd-46dc-4056-a287-f5041c852470, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
18: e120e868-3df2-464a-95a0-b52fa5ada4bf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
19: e838d943-63ed-4a0b-9fb1-47152908acc9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
20: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
21: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/23/2017 9:55:06 AM	Microsoft-Windows-Security-SPP	1066	None	"Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/23/2017 9:55:05 AM	Microsoft-Windows-Security-SPP	900	None	"The Software Protection service is starting.
"
Information	6/23/2017 9:54:54 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 9:54:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Received Post Shell Event 2

"
Information	6/23/2017 9:54:48 AM	Microsoft-Windows-Winlogon	4101	None	Windows license validated.
Information	6/23/2017 9:54:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Logon: 2

"
Information	6/23/2017 9:54:48 AM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

Log on event received User1

"
Information	6/23/2017 9:39:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 9:24:36 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 9:09:25 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:54:09 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:39:02 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:23:51 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 8:08:40 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:53:33 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:38:22 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:23:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 7:07:59 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:52:38 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:37:26 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:22:15 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 6:07:08 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:51:57 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:36:46 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:21:39 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 5:06:28 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:51:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:36:05 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:20:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 4:05:37 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:50:31 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:35:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:19:58 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 3:04:52 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:49:20 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:34:04 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:18:48 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 2:03:41 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:48:30 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:33:19 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:18:12 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 1:03:01 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:47:49 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:32:43 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:17:32 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/23/2017 12:03:01 AM	VSS	8224	None	The VSS service is shutting down due to idle timeout. 
Information	6/23/2017 12:02:10 AM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 11:47:04 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 11:31:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 11:16:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 11:01:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 10:45:53 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 10:30:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 10:15:31 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 10:00:24 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 9:45:13 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 9:30:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 9:14:55 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 8:59:44 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 8:47:27 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/22/2017 8:44:32 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/22/2017 8:42:38 PM	Microsoft-Windows-User Profiles Service	1530	None	"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 28 user registry handles leaked from \Registry\User\S-1-5-21-3672398596-3227583511-885490141-1389459:
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\security
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\requiredICs
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\profiles
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\MY
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networks
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\CA
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\adapters
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\ics
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Policies\Microsoft\SystemCertificates
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Disallowed
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\trust
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icGroups
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\networkLists
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\fips
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\icControl
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\Root
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Microsoft\SystemCertificates\trust
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\general
Process 1532 (\Device\HarddiskVolume1\Program Files (x86)\Juniper Networks\Odyssey Access Client\odClientService.exe) has opened key \REGISTRY\USER\S-1-5-21-3672398596-3227583511-885490141-1389459\Software\Funk Software, Inc.\Odyssey\client\control
"
Information	6/22/2017 8:42:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: 1

"
Information	6/22/2017 8:42:37 PM	igfxCUIService1.0.0.0	0	None	"The description for Event ID 0 from source igfxCUIService1.0.0.0 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event: 

 Logoff: Test

"
Information	6/22/2017 8:42:37 PM	Desktop Window Manager	9009	None	The Desktop Window Manager has exited with code (0x40010004)
Information	6/22/2017 8:31:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/22/2017 8:31:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32964)(?)])(1 )(2 )]

"
Information	6/22/2017 8:31:07 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 32964)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/22/2017 8:29:26 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 8:14:16 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 7:59:06 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 7:43:56 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 7:28:45 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 7:23:50 PM	Outlook	63	None	The Exchange web service request GetAppManifests succeeded. 
Information	6/22/2017 7:13:35 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 6:58:25 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 6:43:20 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 6:28:09 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 6:12:59 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 5:57:49 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 5:42:39 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 5:27:33 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 5:25:18 PM	Windows Error Reporting	1001	None	"Fault bucket , type 0
Event Name: WindowsUpdateFailure3
Response: Not available
Cab Id: 0

Problem signature:
P1: 7.6.7601.23806
P2: 80244019
P3: D67661EB-2423-451D-BF5D-13199E37DF28
P4: Scan
P5: 1
P6: 0
P7: 0
P8: SelfUpdate
P9: {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
P10: 0

Attached files:

These files may be available here:


Analysis symbol: 
Rechecking for solution: 0
Report Id: a8cfa6a8-5741-11e7-a409-80000bd6758f
Report Status: 0"
Information	6/22/2017 5:20:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]

"
Information	6/22/2017 5:20:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33154)(?)])(1 )(2 )]

"
Information	6/22/2017 5:20:36 PM	Office Software Protection Platform Service	1003	None	"The Software Protection service has completed licensing status check.
Application Id=0ff1ce15-a989-479d-af46-f275c6370663
Licensing Status=
1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 8 0x00000000 46 33154)(?)])(1 )(2 )]
2: 26b6a7ce-b174-40aa-a114-316aa56ba9fc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 35ec6e0e-2df4-4629-9ee3-d525e806b988, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 3ad61e22-e4fe-497f-bdb1-3e51bd872173, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 5 0)( 5 0xC004F009 5 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])]
5: 46d2c0bd-f912-4ddc-8e67-b90eadc3f83c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 6e5db8a5-78e6-4953-b793-7422351afe88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: a8119e32-b17c-4bd3-8950-7d1853f4b412, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: b6b47040-b38e-4be2-bf6a-dabf0c41540a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
9: dfc5a8b0-e9fd-43f7-b4ca-d63f1e749711, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: e3dacc06-3bc2-4e13-8e59-8e05f3232325, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: e538d623-c066-433d-a6b7-e0708b1fadf7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]
12: ff02e86c-fef0-4063-b39f-74275cddd7c3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]

"
Information	6/22/2017 5:20:36 PM	Office Software Protection Platform Service	902	None	"The Software Protection service has started.
15.0.169.500"
Information	6/22/2017 5:20:36 PM	Office Software Protection Platform Service	1066	None	"Initialization status for service objects.
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000
"
Information	6/22/2017 5:20:35 PM	Office Software Protection Platform Service	900	None	"The Software Protection service is starting.
"
Information	6/22/2017 5:12:22 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 4:57:11 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 4:42:01 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/22/2017 4:30:00 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/22/2017 4:30:00 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/22/2017 4:26:51 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 4:11:41 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Information	6/22/2017 3:56:30 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/22/2017 3:42:16 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/22/2017 3:42:16 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/22/2017 3:41:14 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/22/2017 3:40:14 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/22/2017 3:40:14 PM	Outlook	37	None	Search indexing is being re-enabled for the 'C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost' Outlook data file.
Information	6/22/2017 3:28:48 PM	Office Software Protection Platform Service	903	None	"The Software Protection service has stopped.
"
Information	6/22/2017 3:25:42 PM	MSSQL$SQLEXPRESS	17137	Server	Starting up database 'mydb'.
Warning	6/22/2017 3:23:49 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.nst (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	6/22/2017 3:23:47 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\AppData\Local\Microsoft\Outlook\GE E2K - Default Outlook Profile.ost (error=0x81404005). If this error continues, contact Microsoft Support.
Warning	6/22/2017 3:23:47 PM	Outlook	36	None	Search cannot complete the indexing of your Outlook data. Indexing cannot continue for C:\Users\212558710\Documents\Outlook Files\archive.pst (error=0x81404005). If this error continues, contact Microsoft Support.
Information	6/22/2017 3:23:47 PM	Outlook	32	None	The store C:\Users\212558710\Documents\Outlook Files\archive.pst has detected a catalog checkpoint.
Information	6/22/2017 3:23:46 PM	Outlook	45	None	Outlook loaded the following add-in(s):


Name: Microsoft Exchange Add-in
Description: Exchange support for Unified Messaging, e-mail permission rules, and calendar availability.
ProgID: UmOutlookAddin.FormRegionAddin
GUID: {F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
Boot Time (Milliseconds): 46

Name: Skype Meeting Add-in for Microsoft Office 2016
Description: Skype Meeting Add-in for Microsoft Office 2016
ProgID: UCAddin.LyncAddin.1
GUID: {A6A2383F-AD50-4D52-8110-3508275E77F7}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\UCAddin.dll
Boot Time (Milliseconds): 172

Name: PhishMe Reporter
Description: PhishMe Outlook Reporter
ProgID: PhishMeOutlookReporter.AddinModule
GUID: {601FF7BC-A576-4AE3-BE9B-D820FBCD83A6}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\PhishMe\PhishMe Reporter\adxloader.PhishMeOutlookReporter.dll
Boot Time (Milliseconds): 94

Name: Outlook Social Connector 2016
Description: Connects to social networking sites and provides people, activity, and status information.
ProgID: OscAddin.Connect
GUID: {2163EB1F-3FD9-4212-A41F-81D1F933597F}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\SOCIALCONNECTOR.DLL
Boot Time (Milliseconds): 187

Name: Microsoft MAPI S/MIME AME processor
Description: Microsoft MAPI S/MIME AME processor
ProgID: MAPISMIMEAMEProcessor.EventCallbacks
GUID: {E6439FB3-A806-4180-B8D8-FA4F11CF9521}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files\DGAgent\plugins\09D849B6-32D3-4A40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
Boot Time (Milliseconds): 15

Name: Microsoft SharePoint Server Colleague Import Add-in
Description: The Add-in allows Microsoft SharePoint Server to import colleague suggestions based on your Outlook content
ProgID: ColleagueImport.ColleagueImportAddin
GUID: {EFEF7FDB-0CED-4FB6-B3BB-3C50D39F4120}
Load Behavior: 3
HKLM: 0
Location: C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\ColleagueImport.dll
Boot Time (Milliseconds): 16

Name: Send to Bluetooth
Description: BTM Office connection
ProgID: btmoffice.Connect
GUID: {494CF5AE-7A7B-4C5E-9A09-54312FCAA6B3}
Load Behavior: 3
HKLM: 1
Location: C:\Program Files (x86)\Intel\Bluetooth\btmoffice.dll
Boot Time (Milliseconds): 47

